Suggestion for adding functionality global group
Event Timeline
I can support this idea. It's quite usual on other routers or firewalls to have global objects, you define once and use it in firewall, nat, policy routing...
@syncer I think the problem is that many fields (eg. within the NAT, WLB, PBR facilities) don't allow to use groups you can use in the firewall stanzas. I think there's no need to poll on this, seems to me like a no-brainer, everyone wants this. Many modern products also add auto variables such as eth0_ipaddresses or eth0_networks. Juniper has an implementation that also allows for hierarchical grouping.
If you want to next-step it and go beyond most vendors: allow for eg. interfaces eth0 address group name. as long the requested type matches the list it should be possible.
Often times the lists are an abstraction that allows for an integrator to keep control over the overall vyos config, but the client would have control over (certain) lists for their day-to-day network operations.
Still i suggest to do poll on possible syntax and implementation
it could be that is not easy because of many existing problems