Page MenuHomeVyOS Platform

Include rulseset in firewall
Closed, ResolvedPublicFEATURE REQUEST

Description

It would be nice to be able to include another rule set in the firewall.

For example, I have a lot of zones that have the basic allow established/related, drop invalid, allow a few icmp types, and allow dns, plus 1 or 2 other rules. It would remove a ton of duplication in the config if it was possible to have an include directive.

Details

Version
-
Is it a breaking change?
Unspecified (possibly destroys the router)

Event Timeline

syncer triaged this task as Wishlist priority.Sep 1 2018, 3:00 PM
dmbaturin subscribed.

This would be best done along with firewall scripts rewrite.

I'm very interested in this as well. Especially when you do lots of filtering based on ipsets that contain adresses from multiple zones, inclusion can save you a lot of redundancy.

zsdc set Is it a breaking change? to Unspecified (possibly destroys the router).
zsdc subscribed.

Most likely this should be done (after firewall rewrite) as jump statements.

n.fort claimed this task.
n.fort subscribed.

Jump action is available in 1.4
Then, I'm setting this task as resolved