Page MenuHomeVyOS Platform

Firewall - Implement global option to use one single general chian
In progress, Requires assessmentPublicFEATURE REQUEST


So far, firewall ruleset need to be applied to an interface.
With T4699 and T4700, and this new option, one general firewall ruleset may be configured to do all the filtering needed.

Something similar to:

set firewall global-filtering name ABCD
set firewall name ABCD default-action drop
set firewall name ABCD rule 10 in-interface eth0
set firewall name ABCD rule 10 source address
set firewall name ABCD rule 10 action accept

Command set firewall global-filtering will add a jump action in chain ip vyos_filter VYOS_FW_FORWARD to specified destination, in the example, chain ABCD


Difficulty level
Unknown (require assessment)
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Perfectly compatible
Issue type
Feature (new functionality)

Event Timeline

n.fort changed the task status from Open to In progress.Fri, Sep 16, 10:50 AM
n.fort claimed this task.
n.fort created this task.
n.fort changed Version from - to vyos-1.4-rolling-202209160217.