> For the complete documentation index, see [llms.txt](https://riteshs4hu.gitbook.io/infosec-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://riteshs4hu.gitbook.io/infosec-notes/configuration-review/cisco-meraki-firewall.md).

# Cisco Meraki Firewall

Cisco Meraki firewalls provide cloud-managed network security. A configuration review should focus on administrative security, firewall rules, VPN configuration, logging, and network segmentation.

The review is aligned with:

* CIS Controls
* Cisco Meraki Best Practices

***

### Review Categories

#### Firewall Rules

Review

* Default deny inbound
* Remove unused rules
* Review Any-Any rules
* Verify outbound restrictions
* Rule ordering reviewed

***

#### VPN Security

Review

* Strong encryption
* AES-256
* Modern IKE versions
* Certificate authentication
* Disable legacy protocols

***

#### Network Segmentation

Review

* Separate management VLAN
* Isolate guest network
* Restrict lateral movement
* Review inter-VLAN ACLs
* Secure DMZ

***

#### Content Filtering

Review

* Malware filtering
* DNS protection
* URL filtering
* Threat protection
* Geo-IP blocking (where applicable)

***

#### Logging and Monitoring

Review

* Syslog enabled
* Event logging
* Security alerts
* SNMP securely configured
* SIEM integration

***

#### Firmware

Review

* Latest stable firmware
* Automatic upgrades
* Review release notes
* Remove unsupported devices

***

#### Configuration Backup

Review

* Configuration documented
* Change history reviewed
* Backup procedures established

#### References

* CIS Benchmarks
* Cisco Meraki Documentation
* Cisco Security Best Practices
