Page MenuHomeVyOS Platform

support for ip groups in nat
Open, Requires assessmentPublicFEATURE REQUEST

Description

Hi,

Would it be possible to add support for address groups in nat, so I could do something like this:

set nat source rule 10 destination address-group 'some-group'

It would be a great feature.

Details

Difficulty level
Unknown (require assessment)
Version
-
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Unspecified (possibly destroys the router)

Event Timeline

I vote for this as well. I have a lot of addresses I need to add to a nat source address so I need to create one rule per IP. Because I have a specific rule numbering scheme, I'm running out of space in it so I had to break the scheme. The ability to use groups in nat source and destination addresses would greatly help.

Note: When we migrate NAT to nftables, we need to use nftables sets instead of ipset