Page MenuHomeVyOS Platform

Include rulseset in firewall
Closed, ResolvedPublicFEATURE REQUEST

Description

It would be nice to be able to include another rule set in the firewall.

For example, I have a lot of zones that have the basic allow established/related, drop invalid, allow a few icmp types, and allow dns, plus 1 or 2 other rules. It would remove a ton of duplication in the config if it was possible to have an include directive.

Details

Difficulty level
Hard (possibly days)
Version
-
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Unspecified (possibly destroys the router)

Event Timeline

syncer triaged this task as Wishlist priority.Sep 1 2018, 3:00 PM
dmbaturin added a subscriber: dmbaturin.

This would be best done along with firewall scripts rewrite.

I'm very interested in this as well. Especially when you do lots of filtering based on ipsets that contain adresses from multiple zones, inclusion can save you a lot of redundancy.

zsdc changed Difficulty level from Unknown (require assessment) to Hard (possibly days).Mar 11 2021, 5:22 PM
zsdc set Is it a breaking change? to Unspecified (possibly destroys the router).
zsdc added a subscriber: zsdc.

Most likely this should be done (after firewall rewrite) as jump statements.

n.fort claimed this task.
n.fort added a subscriber: n.fort.

Jump action is available in 1.4
Then, I'm setting this task as resolved