Page MenuHomeVyOS Platform

Delete firewall description not possible
Needs reporter action, NormalPublicBUG

Description

Currently, it's not possible to delete the description of a firewall description:

On a testing VyOS:

configure
delete firewall
set firewall name test description test
commit

I expect the description to be deleted when I run this Ansible task:

- name: Delete description
  vyos.vyos.vyos_firewall_global:
    config:
      group:
        address_group:
        - name: test
      state: replaced

But nothing happens.

I already have part of the code ready, which I'll upload to GitHub and create a PR later today.

Details

Version
6.0.0
Is it a breaking change?
Behavior change
Issue type
Bug (incorrect behavior)

Event Timeline

RubenNL changed the task status from Open to In progress.
RubenNL claimed this task.
RubenNL triaged this task as Normal priority.

Hello @RubenNL !

Are you able to update the status of this Mafifest, add a link to PR or other doc please?
Thank you

Hi @RubenNL
Do you plan to work on this one or you are OK to delegate / re-assign?
You mentioned a PR - can you please advise the number

Thank you

@RubenNL thanks for looking into this
I believe the module is misused, that is why the result is not as expected.

"description" is controlled by vyos.vyos.vyos_firewall_rules. Here is the simple test:

  1. Provision the device
vyos@vyos:~$ configure
[edit]
vyos@vyos# set firewall ipv4 name test description "new firewall"
[edit]
vyos@vyos# commit 
d[edit]
vyos@vyos# save
[edit]
vyos@vyos# exit
exit
vyos@vyos:~$ show configuration commands | match firewall
set firewall group address-group test
set firewall ipv4 name test description 'new firewall'
  1. Playbook
---
- name: Testing FW global
  hosts: vyos_lab
  gather_facts: false
  tasks:
    - name: Delete ruleset description
      vyos.vyos.vyos_firewall_rules:
        config:
          - afi: ipv4
            rule_sets:
              - name: test
        state: replaced
  1. Running the playbook
$ ansible-playbook -i hosts -l vyos150 fwg_06.yaml

PLAY [Testing FW global] *********************************************************************************************************************************************************************

TASK [Delete ruleset description] ************************************************************************************************************************************************************
[WARNING]: Deprecation warnings can be disabled by setting `deprecation_warnings=False` in ansible.cfg.
[DEPRECATION WARNING]: Passing `warnings` to `exit_json` or `fail_json` is deprecated. This feature will be removed from ansible-core version 2.23. Use `AnsibleModule.warn` instead.
changed: [vyos150]

PLAY RECAP ***********************************************************************************************************************************************************************************
vyos150                    : ok=1    changed=1    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0   
  1. Result
vyos@vyos:~$ show configuration commands | match firewall
set firewall group address-group test
set firewall ipv4 name test

As such, everything works as intended.

evgmol changed the task status from In progress to Needs reporter action.Jul 27 2026, 9:59 AM