diff options
author | Christian Breunig <christian@breunig.cc> | 2024-05-10 14:24:22 +0200 |
---|---|---|
committer | GitHub <noreply@github.com> | 2024-05-10 14:24:22 +0200 |
commit | 42fe1f06e79c69f04d80f988ca331badcd954cb0 (patch) | |
tree | 2dd3e98f82d0ff280f293a9449ff1d6dd37409b8 /docs/configuration/firewall/ipv4.rst | |
parent | fd4b7ff7fcddf8da651d767cb150c5f7d9091ae8 (diff) | |
parent | 734c3d98f30f83ee50698cd3d5c69cb6006a8588 (diff) | |
download | vyos-documentation-42fe1f06e79c69f04d80f988ca331badcd954cb0.tar.gz vyos-documentation-42fe1f06e79c69f04d80f988ca331badcd954cb0.zip |
Merge pull request #1435 from vyos/mergify/bp/sagitta/pr-1434
Firewall: add documentation for dynamic firewall groups. (backport #1434)
Diffstat (limited to 'docs/configuration/firewall/ipv4.rst')
-rw-r--r-- | docs/configuration/firewall/ipv4.rst | 21 |
1 files changed, 21 insertions, 0 deletions
diff --git a/docs/configuration/firewall/ipv4.rst b/docs/configuration/firewall/ipv4.rst index b5a087a7..2fe877bb 100644 --- a/docs/configuration/firewall/ipv4.rst +++ b/docs/configuration/firewall/ipv4.rst @@ -516,6 +516,27 @@ geoip) to keep database and rules updated. criteria. .. cfgcmd:: set firewall ipv4 forward filter rule <1-999999> + source group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv4 input filter rule <1-999999> + source group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv4 output filter rule <1-999999> + source group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv4 name <name> rule <1-999999> + source group dynamic-address-group <name | !name> + +.. cfgcmd:: set firewall ipv4 forward filter rule <1-999999> + destination group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv4 input filter rule <1-999999> + destination group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv4 output filter rule <1-999999> + destination group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv4 name <name> rule <1-999999> + destination group dynamic-address-group <name | !name> + + Use a specific dynamic-address-group. Prepend character ``!`` for inverted + matching criteria. + +.. cfgcmd:: set firewall ipv4 forward filter rule <1-999999> source group network-group <name | !name> .. cfgcmd:: set firewall ipv4 input filter rule <1-999999> source group network-group <name | !name> |