From cc5895fe61f938189e229dffb7746fc93aac0f3b Mon Sep 17 00:00:00 2001 From: Adam Schultz Date: Sat, 16 Aug 2025 22:29:11 -0400 Subject: firewall: T7739: Default ruleset for firewall zones In large networks with many zones where simple allow/deny rules are not sufficient, zones become tedious to manage. Many use cases can be simplified by providing an ability to define a default ruleset for traffic from other zones. This change proposes adding the follwing syntax: set firewall zone default_firewall name set firewall zone default_firewall ipv6_name The proposed behavior is the following: local in: The default firewall ruleset for the local zone will be appended after all from configurations. local out: If a non-local zone does not have a from local ruleset but does have a default_firewall ruleset, the default_firewall ruleset will be appended using oifname forward: The default firewall ruleset for the zone will be appended after all from configurations To keep the behavior consistent with from ruleset configurations, a return is appended after the default_firewall ruleset. The proposed behavior differs slightly from the default_policy configuration for the local out chains. The default_policy applied in the out templates comes from the local zone, not the actual outbound zone. The proposed change does not amend this, but does make default_firewall logically consistent with the intent of the out rules. --- interface-definitions/firewall.xml.in | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) (limited to 'interface-definitions') diff --git a/interface-definitions/firewall.xml.in b/interface-definitions/firewall.xml.in index 7538c3cc5..d5ddbe2cd 100644 --- a/interface-definitions/firewall.xml.in +++ b/interface-definitions/firewall.xml.in @@ -428,6 +428,29 @@ drop + + + Default firewall rules for traffic coming into this zone + + + + + IPv6 firewall ruleset + + firewall ipv6 name + + + + + + IPv4 firewall ruleset + + firewall ipv4 name + + + + + Zone from which to filter traffic -- cgit v1.2.3