Page MenuHomeVyOS Platform

Dynamic ipv4 interface list
Open, Requires assessmentPublicFEATURE REQUEST


Ability to have a list (ipset) of dynamic IP addresses assigned via DHCP/PPPoE etc.
With this list, we will be able to improve the ability of flexible configurations.

It will be useful for firewall/PBR/NAT/port_forwarding features.

As one example:

Router main receives a DHCP address on eth4 from ISP.
This address is associated with the DynDNS site record.
Clients from the "internal network" should go to the external address/port 80 of the main router and redirect to the site located on the service device (

[email protected]# set nat destination rule 200 destination 
Possible completions:
   address      Destination IP address, subnet, or range
   port         Destination port

We can't use the IP address because it's a dynamic address that we don't know in advance.
We can't use only port 80 because all packets will be forwarded.


Difficulty level
Unknown (require assessment)
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Feature (new functionality)

Event Timeline

One question, I don't understand why we can't use only port 80 without this dynamic WAN IP address. In any case, you have inbound interface and port, I think this will be enough.


set nat destination rule 102 destination port '80'
set nat destination rule 102 inbound-interface 'eth2'
set nat destination rule 102 protocol 'tcp'
set nat destination rule 102 translation address ''
set nat destination rule 102 translation port '80'

How will internal clients gain access to external sites if we forward all packets with dst port 80?
This is just one example.

Ok, as a workaround you can you.

set nat destination rule 102 source address !
erkin renamed this task from Dynamic ipv4 interface list. to Dynamic ipv4 interface list.Aug 30 2021, 7:48 AM
erkin set Issue type to Feature (new functionality).
erkin removed a subscriber: Active contributors.

This feature would be very helpfull for hairpin nat as we can see from the mentions.
Might also be helpfull for ipv6 as well.
I am aware its a different product but edgeos from ubiquiti does something like this (looks to be a managed address group that populates dynamically) for nat and fw:

destination {
    group {
        address-group ADDRv4_eth0
aderouineau added a subscriber: aderouineau.

Any update on this, since it's been more than 2 years since the initial request? This would indeed be very useful for hairpin NAT. It it complicated to implement?