Page MenuHomeVyOS Platform

Firewall interface group - Allow inverted matcher
Closed, ResolvedPublicFEATURE REQUEST

Description

Allow inverted matcher for interface group in firewall ruleset.
For other groups, inverted-matcher is allowed.

This doesn't work:

set firewall name X rule X [inbound-interface | outbound-interface] interface-group !IFACE-GROUP

While this works:

set firewall name X rule X source group address-group !ADDRESS-GROUP

This works:

Details

Difficulty level
Unknown (require assessment)
Version
vyos-1.4-rolling-202308060317
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Perfectly compatible
Issue type
Bug (incorrect behavior)

Event Timeline

n.fort changed the task status from Open to Confirmed.Aug 8 2023, 6:02 PM
n.fort claimed this task.
n.fort created this task.
n.fort changed Version from - to vyos-1.4-rolling-202308060317.
n.fort changed the task status from In progress to Needs testing.Aug 23 2023, 4:30 PM