diff options
author | Daniil Baturin <daniil@vyos.io> | 2024-05-10 11:55:52 +0200 |
---|---|---|
committer | GitHub <noreply@github.com> | 2024-05-10 11:55:52 +0200 |
commit | 5950dac4b59bfa02bb2b63b15036992fac6ff916 (patch) | |
tree | 3cab48e78ef2805d58ec20d948e054c51fbe07d4 /docs/configuration/firewall/ipv6.rst | |
parent | 63b9255ba6f29375d85086d912f156389c21b4f2 (diff) | |
parent | 245e133042b160ca9f28b4be13d2b5c8e0edba70 (diff) | |
download | vyos-documentation-5950dac4b59bfa02bb2b63b15036992fac6ff916.tar.gz vyos-documentation-5950dac4b59bfa02bb2b63b15036992fac6ff916.zip |
Merge pull request #1434 from nicolas-fort/fwall_dyn_groups
Firewall: add documentation for dynamic firewall groups.
Diffstat (limited to 'docs/configuration/firewall/ipv6.rst')
-rw-r--r-- | docs/configuration/firewall/ipv6.rst | 21 |
1 files changed, 21 insertions, 0 deletions
diff --git a/docs/configuration/firewall/ipv6.rst b/docs/configuration/firewall/ipv6.rst index 4b695f74..28b57e72 100644 --- a/docs/configuration/firewall/ipv6.rst +++ b/docs/configuration/firewall/ipv6.rst @@ -526,6 +526,27 @@ geoip) to keep database and rules updated. criteria. .. cfgcmd:: set firewall ipv6 forward filter rule <1-999999> + source group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv6 input filter rule <1-999999> + source group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv6 output filter rule <1-999999> + source group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv6 name <name> rule <1-999999> + source group dynamic-address-group <name | !name> + +.. cfgcmd:: set firewall ipv6 forward filter rule <1-999999> + destination group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv6 input filter rule <1-999999> + destination group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv6 output filter rule <1-999999> + destination group dynamic-address-group <name | !name> +.. cfgcmd:: set firewall ipv6 name <name> rule <1-999999> + destination group dynamic-address-group <name | !name> + + Use a specific dynamic-address-group. Prepend character ``!`` for inverted + matching criteria. + +.. cfgcmd:: set firewall ipv6 forward filter rule <1-999999> source group network-group <name | !name> .. cfgcmd:: set firewall ipv6 input filter rule <1-999999> source group network-group <name | !name> |