Both show firewall and show firewall statistics works.
But show firewall group fails:
vyos@vyos:~$ show firewall group Traceback (most recent call last): File "/usr/libexec/vyos/op_mode/firewall.py", line 434, in <module> show_firewall_group(args.name) File "/usr/libexec/vyos/op_mode/firewall.py", line 338, in show_firewall_group references = find_references(group_type, group_name) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/libexec/vyos/op_mode/firewall.py", line 303, in find_references for rule_id, rule_conf in priority_conf['rule'].items(): ~~~~~~~~~~~~~^^^^^^^^ KeyError: 'rule'
And so do show firewall summary:
vyos@vyos:~$ show firewall summary Traceback (most recent call last): Ruleset Summary IPv6 Ruleset: Ruleset Hook Ruleset Priority Description -------------- ------------------ ------------- forward filter input filter name V6_TO_DMZ name V6_TO_LAN name V6_TO_MGMT name V6_TO_WAN output filter IPv4 Ruleset: Ruleset Hook Ruleset Priority Description -------------- ------------------ ------------- forward filter input filter name V4_TO_DMZ name V4_TO_LAN name V4_TO_MGMT name V4_TO_WAN output filter File "/usr/libexec/vyos/op_mode/firewall.py", line 438, in <module> show_summary() File "/usr/libexec/vyos/op_mode/firewall.py", line 391, in show_summary show_firewall_group() File "/usr/libexec/vyos/op_mode/firewall.py", line 338, in show_firewall_group references = find_references(group_type, group_name) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/libexec/vyos/op_mode/firewall.py", line 303, in find_references for rule_id, rule_conf in priority_conf['rule'].items(): ~~~~~~~~~~~~~^^^^^^^^ KeyError: 'rule'
Current ruleset (commits and boots without errors):
set firewall global-options all-ping 'enable' set firewall global-options broadcast-ping 'disable' set firewall global-options ip-src-route 'disable' set firewall global-options ipv6-receive-redirects 'disable' set firewall global-options ipv6-src-route 'disable' set firewall global-options log-martians 'enable' set firewall global-options receive-redirects 'disable' set firewall global-options resolver-cache set firewall global-options resolver-interval '60' set firewall global-options send-redirects 'disable' set firewall global-options source-validation 'strict' set firewall global-options syn-cookies 'enable' set firewall global-options twa-hazards-protection 'disable' set firewall group interface-group DMZ interface 'eth2' set firewall group interface-group LAN interface 'eth3' set firewall group interface-group MGMT interface 'eth0' set firewall group interface-group WAN interface 'eth1' set firewall group ipv6-network-group V6_DMZ set firewall group ipv6-network-group V6_LAN set firewall group ipv6-network-group V6_MGMT set firewall group ipv6-network-group V6_WAN network '::/0' set firewall group network-group V4_BOGONS network '0.0.0.0/8' set firewall group network-group V4_BOGONS network '10.0.0.0/8' set firewall group network-group V4_BOGONS network '100.64.0.0/10' set firewall group network-group V4_BOGONS network '127.0.0.0/8' set firewall group network-group V4_BOGONS network '169.254.0.0/16' set firewall group network-group V4_BOGONS network '172.16.0.0/12' set firewall group network-group V4_BOGONS network '192.0.0.0/24' set firewall group network-group V4_BOGONS network '192.0.2.0/24' set firewall group network-group V4_BOGONS network '192.168.0.0/16' set firewall group network-group V4_BOGONS network '198.18.0.0/15' set firewall group network-group V4_BOGONS network '198.51.100.0/24' set firewall group network-group V4_BOGONS network '203.0.113.0/24' set firewall group network-group V4_BOGONS network '224.0.0.0/4' set firewall group network-group V4_BOGONS network '240.0.0.0/4' set firewall group network-group V4_DMZ network '192.168.2.0/24' set firewall group network-group V4_LAN network '192.168.3.0/24' set firewall group network-group V4_MGMT network '192.168.56.0/24' set firewall group network-group V4_RFC1918 network '10.0.0.0/8' set firewall group network-group V4_RFC1918 network '172.16.0.0/12' set firewall group network-group V4_RFC1918 network '192.168.0.0/16' set firewall group network-group V4_WAN network '192.168.1.0/24' set firewall group network-group V4_WAN network '0.0.0.0/0' set firewall ipv4 forward filter default-action 'drop' set firewall ipv4 forward filter rule 10 action 'accept' set firewall ipv4 forward filter rule 10 state established 'enable' set firewall ipv4 forward filter rule 20 action 'accept' set firewall ipv4 forward filter rule 20 state related 'enable' set firewall ipv4 forward filter rule 30 action 'drop' set firewall ipv4 forward filter rule 30 state invalid 'enable' set firewall ipv4 forward filter rule 40 action 'jump' set firewall ipv4 forward filter rule 40 jump-target 'V4_TO_WAN' set firewall ipv4 forward filter rule 40 outbound-interface interface-group 'WAN' set firewall ipv4 forward filter rule 50 action 'jump' set firewall ipv4 forward filter rule 50 jump-target 'V4_TO_DMZ' set firewall ipv4 forward filter rule 50 outbound-interface interface-group 'DMZ' set firewall ipv4 forward filter rule 60 action 'jump' set firewall ipv4 forward filter rule 60 jump-target 'V4_TO_LAN' set firewall ipv4 forward filter rule 60 outbound-interface interface-group 'LAN' set firewall ipv4 input filter default-action 'accept' set firewall ipv4 input filter rule 10 action 'accept' set firewall ipv4 input filter rule 10 state established 'enable' set firewall ipv4 input filter rule 20 action 'accept' set firewall ipv4 input filter rule 20 state related 'enable' set firewall ipv4 input filter rule 30 action 'drop' set firewall ipv4 input filter rule 30 state invalid 'enable' set firewall ipv4 input filter rule 999999 action 'accept' set firewall ipv4 input filter rule 999999 inbound-interface interface-name 'lo' set firewall ipv4 input filter rule 999999 source address '127.0.0.0/8' set firewall ipv4 name V4_TO_DMZ default-action 'drop' set firewall ipv4 name V4_TO_LAN default-action 'drop' set firewall ipv4 name V4_TO_MGMT default-action 'drop' set firewall ipv4 name V4_TO_WAN default-action 'drop' set firewall ipv4 output filter default-action 'accept' set firewall ipv4 output filter rule 10 action 'accept' set firewall ipv4 output filter rule 10 state established 'enable' set firewall ipv4 output filter rule 20 action 'accept' set firewall ipv4 output filter rule 20 state related 'enable' set firewall ipv4 output filter rule 30 action 'drop' set firewall ipv4 output filter rule 30 state invalid 'enable' set firewall ipv4 output filter rule 999999 action 'accept' set firewall ipv4 output filter rule 999999 destination address '127.0.0.0/8' set firewall ipv4 output filter rule 999999 outbound-interface interface-name 'lo' set firewall ipv6 forward filter default-action 'drop' set firewall ipv6 forward filter rule 10 action 'accept' set firewall ipv6 forward filter rule 10 state established 'enable' set firewall ipv6 forward filter rule 20 action 'accept' set firewall ipv6 forward filter rule 20 state related 'enable' set firewall ipv6 forward filter rule 30 action 'drop' set firewall ipv6 forward filter rule 30 state invalid 'enable' set firewall ipv6 forward filter rule 40 action 'jump' set firewall ipv6 forward filter rule 40 jump-target 'V6_TO_WAN' set firewall ipv6 forward filter rule 40 outbound-interface interface-group 'WAN' set firewall ipv6 forward filter rule 50 action 'jump' set firewall ipv6 forward filter rule 50 jump-target 'V6_TO_DMZ' set firewall ipv6 forward filter rule 50 outbound-interface interface-group 'DMZ' set firewall ipv6 forward filter rule 60 action 'jump' set firewall ipv6 forward filter rule 60 jump-target 'V6_TO_LAN' set firewall ipv6 forward filter rule 60 outbound-interface interface-group 'LAN' set firewall ipv6 input filter default-action 'accept' set firewall ipv6 input filter rule 10 action 'accept' set firewall ipv6 input filter rule 10 state established 'enable' set firewall ipv6 input filter rule 20 action 'accept' set firewall ipv6 input filter rule 20 state related 'enable' set firewall ipv6 input filter rule 30 action 'drop' set firewall ipv6 input filter rule 30 state invalid 'enable' set firewall ipv6 input filter rule 999999 action 'accept' set firewall ipv6 input filter rule 999999 inbound-interface interface-name 'lo' set firewall ipv6 input filter rule 999999 source address '::1/128' set firewall ipv6 name V6_TO_DMZ default-action 'drop' set firewall ipv6 name V6_TO_LAN default-action 'drop' set firewall ipv6 name V6_TO_MGMT default-action 'drop' set firewall ipv6 name V6_TO_WAN default-action 'drop' set firewall ipv6 output filter default-action 'accept' set firewall ipv6 output filter rule 10 action 'accept' set firewall ipv6 output filter rule 10 state established 'enable' set firewall ipv6 output filter rule 20 action 'accept' set firewall ipv6 output filter rule 20 state related 'enable' set firewall ipv6 output filter rule 30 action 'drop' set firewall ipv6 output filter rule 30 state invalid 'enable' set firewall ipv6 output filter rule 999999 action 'accept' set firewall ipv6 output filter rule 999999 destination address '::1/128' set firewall ipv6 output filter rule 999999 outbound-interface interface-name 'lo'