Wildcard Domains / TLDs in Firewall-Rules (and perhaps groups)
It would be very helpful to be able to use whole Domains / TLDs (Wildcards).
A specific use-case would be, to block the new .ZIP- and .MOV-Domains for example.

For example:

set firewall name LAN-WAN rule 10 destination fqdn '*.zip'
set firewall name LAN-WAN rule 10 action drop

Example in groups:

set firewall group domain-group Malicious-Domains address '*.zip'


This would have to be handled with DNS and not in the firewall. Hostnames work on firewall because they are resolved prior to use in rules.

dmbaturin triaged this task as Wishlist priority.Jan 11 2024, 11:29 AM
dmbaturin added a project: VyOS 1.5 Circinus.