.. _vyos.rest.vyos_firewall_rules_module: ***************************** vyos.rest.vyos_firewall_rules ***************************** **Manage firewall rule sets on VyOS devices using REST API** Version added: 1.0.0 .. contents:: :local: :depth: 1 Synopsis -------- - Manages named firewall rule sets on VyOS devices via the REST API. - Supports both IPv4 (``ipv4``) and IPv6 (``ipv6``) rule sets. - Uses REST API (``connection=httpapi``) instead of CLI. - In VyOS 1.5+, firewall uses named rule sets under ``firewall.ipv4.name`` and ``firewall.ipv6.name``. Parameters ---------- .. raw:: html
Parameter Choices/Defaults Comments
config
list / elements=dictionary
Firewall rule set configuration.
afi
string / required
    Choices:
  • ipv4
  • ipv6
Address family.
rule_sets
list / elements=dictionary
Named rule sets for this address family.
default_action
string
    Choices:
  • accept
  • drop
  • reject
Default action when no rule matches.
description
string
Rule set description.
name
string / required
Rule set name.
rules
list / elements=dictionary
Firewall rules in this rule set.
action
string
    Choices:
  • accept
  • drop
  • reject
  • return
  • queue
  • continue
Rule action.
description
string
Rule description.
destination
dictionary
Destination match criteria.
address
string
Destination IP address or prefix.
group
string
Destination group name.
port
string
Destination port or range.
disable
boolean
    Choices:
  • no
  • yes
Disable this rule.
icmp
dictionary
ICMP type/code to match.
code
integer
ICMP code.
type
integer
ICMP type.
log
boolean
    Choices:
  • no
  • yes
Enable logging for this rule.
number
integer / required
Rule number.
protocol
string
Protocol to match.
source
dictionary
Source match criteria.
address
string
Source IP address or prefix.
group
string
Source group name.
port
string
Source port or range.
state
string
    Choices:
  • established
  • invalid
  • new
  • related
Connection state to match.
state
string
    Choices:
  • merged ←
  • replaced
  • overridden
  • deleted
  • gathered
Desired state of the firewall rules configuration.
merged adds or updates without removing existing config.
replaced replaces rule sets for named rule sets in config.
overridden replaces all firewall rule sets.
deleted removes firewall rule sets.
gathered returns current configuration as structured data.

Notes ----- .. note:: - Requires ``ansible_connection=httpapi`` with the VyOS httpapi plugin. - ``ansible_network_os`` must be set to ``vyos.rest.vyos``. - Rule sets are identified by AFI and name. Deleting a rule set removes all its rules. Examples -------- .. code-block:: yaml - name: Merge firewall rules vyos.rest.vyos_firewall_rules: config: - afi: ipv4 rule_sets: - name: RULE-SET1 default_action: drop rules: - number: 10 action: accept protocol: tcp source: address: 192.168.1.0/24 destination: port: "80" - number: 20 action: drop state: invalid - afi: ipv6 rule_sets: - name: RULE-SET6 default_action: accept rules: - number: 10 action: accept state: merged - name: Delete all firewall rules vyos.rest.vyos_firewall_rules: state: deleted - name: Gather firewall rules vyos.rest.vyos_firewall_rules: state: gathered Return Values ------------- Common return values are documented `here `_, the following are the fields unique to this module: .. raw:: html
Key Returned Description
after
list
when changed
Firewall rules configuration after this module ran.

before
list
always
Firewall rules configuration before this module ran.

commands
list
always
List of API command tuples sent to the device.

gathered
list
when state is gathered
Current firewall rules configuration as structured data.

response
dictionary
when changes are applied
Raw API response.

saved
boolean
when changes are applied
Whether the config was saved after changes.



Status ------ Authors ~~~~~~~ - VyOS Community (@vyos)