Page MenuHomeVyOS Platform

Improve firewall remote-group op-mode output with details from nftables
Closed, ResolvedPublicFEATURE REQUEST

Description

Summary

During the initial deployment of remote groups, only the configured URL for the group is displayed, rather than the actual implemented networks, IPs, or ranges added to nftables. It would be very beneficial to view the installed elements for remote groups directly from op-mode without needing to issue manual nft commands.

Additional information

As of rolling release 2025.04.01. Only URL is displayed in both summary and detail view.

vyos@vyos:~$ show firewall group remote-bogon-list
Firewall Groups

Name               Type          References    Members
-----------------  ------------  ------------  -------------------------------------------------------
remote-bogon-list  remote_group  N/D           https://team-cymru.org/Services/Bogons/bogon-bn-agg.txt
vyos@vyos:~$
vyos@vyos:~$ show firewall group remote-bogon-list detail
Firewall Groups

 Name        | remote-bogon-list
 Description | v4 bogon list
 Type        | remote_group
 References  | N/D
 Members     | https://team-cymru.org/Services/Bogons/bogon-bn-agg.txt

With patch. URL is shown in summary, but all nftable entries are showed in detail view. If not entries are found, it defaults to showing the URL in the detail view as well.

vyos@vyos:~$ show firewall group remote-bogon-list
Firewall Groups

Name               Type          References    Members
-----------------  ------------  ------------  -------------------------------------------------------
remote-bogon-list  remote_group  N/D           https://team-cymru.org/Services/Bogons/bogon-bn-agg.txt
vyos@vyos:~$
vyos@vyos:~$ show firewall group remote-bogon-list detail
Firewall Groups

 Name        | remote-bogon-list
 Description | v4 bogon list
 Type        | remote_group
 References  | N/D
 Members     | 0.0.0.0/8 10.0.0.0/8 100.64.0.0/10 127.0.0.0/8 169.254.0.0/16
             | 172.16.0.0/12 192.0.0.0/24 192.0.2.0/24 192.168.0.0/16
             | 198.18.0.0/15 198.51.100.0/24 203.0.113.0/24 224.0.0.0/3

Details

Version
-
Is it a breaking change?
Perfectly compatible
Issue type
Feature (new functionality)