diff options
author | Nicolas Fort <nicolasfort1988@gmail.com> | 2024-05-09 15:27:20 -0300 |
---|---|---|
committer | Mergify <37929162+mergify[bot]@users.noreply.github.com> | 2024-05-10 09:56:40 +0000 |
commit | 734c3d98f30f83ee50698cd3d5c69cb6006a8588 (patch) | |
tree | 0bd245c8ec8351097653c718b9529e321fdf0830 /docs/configuration/firewall/ipv6.rst | |
parent | f9eb141c1564f051bc6659ff695fa4bdad6f53ce (diff) | |
download | vyos-documentation-734c3d98f30f83ee50698cd3d5c69cb6006a8588.tar.gz vyos-documentation-734c3d98f30f83ee50698cd3d5c69cb6006a8588.zip |
Firewall: add documentation for dynamic firewall groups.
(cherry picked from commit 245e133042b160ca9f28b4be13d2b5c8e0edba70)
Diffstat (limited to 'docs/configuration/firewall/ipv6.rst')
-rw-r--r-- | docs/configuration/firewall/ipv6.rst | 21 |
1 files changed, 21 insertions, 0 deletions
diff --git a/docs/configuration/firewall/ipv6.rst b/docs/configuration/firewall/ipv6.rst index c679ffd5..b0249124 100644 --- a/docs/configuration/firewall/ipv6.rst +++ b/docs/configuration/firewall/ipv6.rst @@ -526,6 +526,27 @@ geoip) to keep database and rules updated. criteria. .. cfgcmd:: set firewall ipv6 forward filter rule <1-999999> + source group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv6 input filter rule <1-999999> + source group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv6 output filter rule <1-999999> + source group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv6 name <name> rule <1-999999> + source group dynamic-address-group <name | !name> + +.. cfgcmd:: set firewall ipv6 forward filter rule <1-999999> + destination group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv6 input filter rule <1-999999> + destination group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv6 output filter rule <1-999999> + destination group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv6 name <name> rule <1-999999> + destination group dynamic-address-group <name | !name> + + Use a specific dynamic-address-group. Prepend character ``!`` for inverted + matching criteria. + +.. cfgcmd:: set firewall ipv6 forward filter rule <1-999999> source group network-group <name | !name> .. cfgcmd:: set firewall ipv6 input filter rule <1-999999> source group network-group <name | !name> |