Page MenuHomeVyOS Platform

support for ip groups in nat
Open, Requires assessmentPublicFEATURE REQUEST



Would it be possible to add support for address groups in nat, so I could do something like this:

set nat source rule 10 destination address-group 'some-group'

It would be a great feature.


Difficulty level
Unknown (require assessment)
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Unspecified (possibly destroys the router)

Event Timeline

danielpo created this task.Jan 30 2020, 6:02 AM
jjakob added a subscriber: jjakob.Mar 31 2020, 9:32 AM

I vote for this as well. I have a lot of addresses I need to add to a nat source address so I need to create one rule per IP. Because I have a specific rule numbering scheme, I'm running out of space in it so I had to break the scheme. The ability to use groups in nat source and destination addresses would greatly help.

pasik added a subscriber: pasik.Mar 31 2020, 3:48 PM
Dmitry added a subscriber: Dmitry.May 20 2020, 10:55 AM

Note: When we migrate NAT to nftables, we need to use nftables sets instead of ipset