mirror of
https://github.com/vyos/vyos-documentation.git
synced 2025-10-26 08:41:46 +01:00
Merge pull request #895 from nicolas-fort/fwall_update
Firewall update: add groups and note to firewall interface section
This commit is contained in:
commit
c7c838ffa5
@ -148,11 +148,11 @@ Some firewall settings are global and have an affect on the whole system.
|
|||||||
Groups
|
Groups
|
||||||
******
|
******
|
||||||
|
|
||||||
Firewall groups represent collections of IP addresses, networks, or
|
Firewall groups represent collections of IP addresses, networks, ports,
|
||||||
ports. Once created, a group can be referenced by firewall rules as
|
mac addresses or domains. Once created, a group can be referenced by
|
||||||
either a source or destination. Members can be added or removed from a
|
firewall, nat and policy route rules as either a source or destination
|
||||||
group without changes to, or the need to reload, individual firewall
|
matcher. Members can be added or removed from a group without changes to,
|
||||||
rules.
|
or the need to reload, individual firewall rules.
|
||||||
|
|
||||||
Groups need to have unique names. Even though some contain IPv4
|
Groups need to have unique names. Even though some contain IPv4
|
||||||
addresses and others contain IPv6 addresses, they still need to have
|
addresses and others contain IPv6 addresses, they still need to have
|
||||||
@ -183,7 +183,6 @@ defined.
|
|||||||
|
|
||||||
Provide a IPv4 or IPv6 address group description
|
Provide a IPv4 or IPv6 address group description
|
||||||
|
|
||||||
|
|
||||||
Network Groups
|
Network Groups
|
||||||
==============
|
==============
|
||||||
|
|
||||||
@ -208,7 +207,6 @@ recommended.
|
|||||||
|
|
||||||
Provide a IPv4 or IPv6 network group description.
|
Provide a IPv4 or IPv6 network group description.
|
||||||
|
|
||||||
|
|
||||||
Port Groups
|
Port Groups
|
||||||
===========
|
===========
|
||||||
|
|
||||||
@ -234,6 +232,34 @@ filtering unnecessary ports. Ranges of ports can be specified by using
|
|||||||
|
|
||||||
Provide a port group description.
|
Provide a port group description.
|
||||||
|
|
||||||
|
MAC Groups
|
||||||
|
==========
|
||||||
|
|
||||||
|
A **mac group** represents a collection of mac addresses.
|
||||||
|
|
||||||
|
.. cfgcmd:: set firewall group mac-group <name> mac-address <mac-address>
|
||||||
|
|
||||||
|
Define a mac group.
|
||||||
|
|
||||||
|
.. code-block:: none
|
||||||
|
|
||||||
|
set firewall group mac-group MAC-G01 mac-address 88:a4:c2:15:b6:4f
|
||||||
|
set firewall group mac-group MAC-G01 mac-address 4c:d5:77:c0:19:81
|
||||||
|
|
||||||
|
|
||||||
|
Domain Groups
|
||||||
|
=============
|
||||||
|
|
||||||
|
A **domain group** represents a collection of domains.
|
||||||
|
|
||||||
|
.. cfgcmd:: set firewall group domain-group <name> address <domain>
|
||||||
|
|
||||||
|
Define a domain group.
|
||||||
|
|
||||||
|
.. code-block:: none
|
||||||
|
|
||||||
|
set firewall group domain-group DOM address example.com
|
||||||
|
|
||||||
|
|
||||||
*********
|
*********
|
||||||
Rule-Sets
|
Rule-Sets
|
||||||
@ -634,11 +660,15 @@ A Rule-Set can be applied to every interface:
|
|||||||
set firewall interface eth1.100 out name LANv4-OUT
|
set firewall interface eth1.100 out name LANv4-OUT
|
||||||
set firewall interface bond0 in name LANv4-IN
|
set firewall interface bond0 in name LANv4-IN
|
||||||
set firewall interface vtun1 in name LANv4-IN
|
set firewall interface vtun1 in name LANv4-IN
|
||||||
|
set firewall interface eth2* in name LANv4-IN
|
||||||
|
|
||||||
.. note::
|
.. note::
|
||||||
As you can see in the example here, you can assign the same rule-set to
|
As you can see in the example here, you can assign the same rule-set to
|
||||||
several interfaces. An interface can only have one rule-set per chain.
|
several interfaces. An interface can only have one rule-set per chain.
|
||||||
|
|
||||||
|
.. note::
|
||||||
|
You can use wildcard ``*`` to match a group of interfaces.
|
||||||
|
|
||||||
***********************
|
***********************
|
||||||
Operation-mode Firewall
|
Operation-mode Firewall
|
||||||
***********************
|
***********************
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user