Merge pull request #1634 from markh0338/remote-group-docs

T7386: firewall: update remote-group docs to support IPv6
This commit is contained in:
Christian Breunig 2025-05-12 20:49:41 +02:00 committed by GitHub
commit 835a750a72
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -41,14 +41,14 @@ Remote Groups
==============
A **remote-group** takes an argument of a URL hosting a linebreak-deliminated
list of IPv4s addresses, CIDRs and ranges. VyOS will pull this list periodicity
list of IPv4 and/or IPv6 addresses, CIDRs and ranges. VyOS will pull this list periodicity
according to the frequency defined in the firewall **resolver-interval** and load
matching entries into the group for use in rules. The list will be cached in
persistent storage, so in cases of update failure rules will still function.
.. cfgcmd:: set firewall group remote-group <name> url <http(s) url>
Define remote list of IPv4 addresses/ranges/CIDRs to fetch
Define remote list of IPv4 and/or IPv6 addresses/ranges/CIDRs to fetch
.. cfgcmd:: set firewall group remote-group <name> description <text>
@ -56,13 +56,18 @@ persistent storage, so in cases of update failure rules will still function.
The format of the remote list is very flexible. VyOS will attempt to parse the
first word of each line as an entry, and will skip if it cannot find a valid
match. Below is a list of acceptable matches that would be parsed correctly:
match. Lines that begin with an alphanumeric character but do not match valid IPv4
or IPv6 addresses, ranges, or CIDRs will be logged to the system log. Below is a
list of acceptable matches that would be parsed correctly:
.. code-block:: none
127.0.0.1
127.0.0.0/24
127.0.0.1-127.0.0.254
2001:db8::1
2001:db8:cafe::/48
2001:db8:cafe::1-2001:db8:cafe::ffff
Network Groups
==============