Page MenuHomePhabricator

Allow wan load-balancing rules to match against groups
Open, NormalPublicENHANCEMENT

Description

Can we extend the source/destination matching options to allow us to use groups?

Details

Difficulty level
Normal (likely a few hours)

Event Timeline

jhendryUK created this task.Aug 5 2016, 1:42 PM
jhendryUK changed Difficulty level from Easy (less than an hour) to Normal (likely a few hours).

I wonder if we can even extend groups even further into the NAT rules as well.

Further, I think it'd be good if we can specify multiple inbound-interfaces in wan load-balancing - for example, for exclude lines where we'd like to exclude addresses from wan load-balancing for multiple VLANs.

Multiple inbound-interfaces was going to be the next task I raised for wan load-balancing :). We should probably change the name of the option to something more descriptive of what it does. exclude-traffic-from-interfaces or similar.

Another interesting option is glob matches, iptables allows you to specify a + at the end of the interface name. Lets also allow for that so w can exclude ipsec/openvpn etc etc... tunnels in a single command

syncer triaged this task as Normal priority.Aug 21 2016, 5:06 PM
syncer added subscribers: VyOS 1.1.x, VyOS 2.0.x.
syncer edited subscribers, added: VyOS 1.2 Crux; removed: VyOS 2.0.x, VyOS 1.1.x.
pasik added a subscriber: pasik.Oct 1 2018, 9:55 AM
syncer changed the subtype of this task from "Task" to "Enhancement".Oct 20 2018, 7:00 AM