mirror of
https://github.com/vyos/vyos-documentation.git
synced 2025-12-13 09:02:02 +01:00
firewall: T7739: Default ruleset for firewall zones (#1714)
Adds new syntax documentation for https://github.com/vyos/vyos-1x/pull/4672
This commit is contained in:
parent
2355b54255
commit
279d3d4edc
@ -139,7 +139,7 @@ Applying a Rule-Set to a Zone
|
||||
|
||||
Once a rule-set has been defined, it can then be applied to the source and
|
||||
destination zones. The configuration syntax is anchored on the destination
|
||||
zone, with each of the source zone rulesets listed against the destination.
|
||||
zone, with each of the source zone rule-sets listed against the destination.
|
||||
|
||||
.. cfgcmd:: set firewall zone <Destination Zone> from <Source Zone>
|
||||
firewall name <ipv4-rule-set-name>
|
||||
@ -154,6 +154,21 @@ It is recommended to create two rule-sets for each source-destination zone pair.
|
||||
set firewall zone DMZ from LAN firewall name LAN-DMZ-v4
|
||||
set firewall zone LAN from DMZ firewall name DMZ-LAN-v4
|
||||
|
||||
Applying a Default Rule-Set to a Zone
|
||||
=====================================
|
||||
|
||||
When a destination zone shares a common rule-set for multiple source zones or
|
||||
a complex set of default policies are required, an optional default rule-set
|
||||
can be applied. The default rule-set applies to all zones that do not have a
|
||||
rule-set configured as defined in
|
||||
:ref:`IPv4<configuration/firewall/zone:Applying a Rule-Set to a Zone>`
|
||||
|
||||
.. cfgcmd:: set firewall zone <Destination Zone> default-firewall name
|
||||
<ipv4-rule-set-name>
|
||||
|
||||
.. cfgcmd:: set firewall zone <Destination Zone> default-firewall ipv6-name
|
||||
<ipv6-rule-set-name>
|
||||
|
||||
**************
|
||||
Operation-mode
|
||||
**************
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user