summaryrefslogtreecommitdiff
path: root/docs/configuration/firewall
diff options
context:
space:
mode:
authorYuriy Andamasov <yuriy@vyos.io>2026-05-02 17:54:19 +0300
committerYuriy Andamasov <yuriy@vyos.io>2026-05-06 16:18:03 +0300
commitf7bab3007a9e0d0fef3ec551a677380a00b12d6a (patch)
treef46b904bd00ad186308fbd3c9bedcdadf3b2aa05 /docs/configuration/firewall
parentfa54a080fac977157454beb0853daf0ac0e6af66 (diff)
downloadvyos-documentation-f7bab3007a9e0d0fef3ec551a677380a00b12d6a.tar.gz
vyos-documentation-f7bab3007a9e0d0fef3ec551a677380a00b12d6a.zip
chore(swap): remove canary md-*.md files and docs/superpowers
- Remove 115 canary md-*.md files (incremental swap helpers no longer needed) - Remove 8 files under docs/superpowers (project planning/design docs that shouldn't ship in the documentation tree) 🤖 Generated by [robots](https://vyos.io)
Diffstat (limited to 'docs/configuration/firewall')
-rw-r--r--docs/configuration/firewall/md-bridge.md673
-rw-r--r--docs/configuration/firewall/md-global-options.md214
-rw-r--r--docs/configuration/firewall/md-groups.md419
-rw-r--r--docs/configuration/firewall/md-ipv6.md1624
4 files changed, 0 insertions, 2930 deletions
diff --git a/docs/configuration/firewall/md-bridge.md b/docs/configuration/firewall/md-bridge.md
deleted file mode 100644
index 42442ee7..00000000
--- a/docs/configuration/firewall/md-bridge.md
+++ /dev/null
@@ -1,673 +0,0 @@
----
-lastproofread: '2026-03-28'
----
-
-(firewall-configuration)=
-
-# Bridge Firewall Configuration
-
-## Overview
-
-Learn more about bridge firewall configuration
-and related op-mode commands.
-
-The following commands are covered in this section:
-
-```{cfgcmd} set firewall bridge \<options\>
-```
-From the main structure defined in
-{doc}`Firewall Overview</configuration/firewall/index>`
-in this section you can find detailed information only for the next part
-of the general structure:
-```none
-- set firewall
- * bridge
- - forward
- + filter
- - input
- + filter
- - output
- + filter
- - prerouting
- + filter
- - name
- + custom_name
-```
-Traffic that is received by the router on an interface that is a member of a
-bridge is processed on the **Bridge Layer**. Before the bridge decision is
-made, all packets are analyzed at **Prerouting**. First filters can be applied
-here, and also rules for ignoring connection tracking system can be configured.
-The relevant configuration that acts in **prerouting** is:
-
-
-- `set firewall bridge prerouting filter ...`.
-
-
-For traffic that needs to be switched internally by the bridge, the base
-chain is **forward**, and its base command for filtering is `set firewall
-bridge forward filter ...`, which happens in stage 4, highlighted with red
-color.
-
-
-:::{figure} /_static/images/firewall-bridge-forward.png
-:::
-
-
-For traffic destined to the router itself or that needs to be routed
-(assuming a layer3 bridge is configured), the base chain is **input**, and the
-base command is `set firewall bridge input filter ...` and the path is:
-
-
-:::{figure} /_static/images/firewall-bridge-input.png
-:::
-
-
-If it's not dropped, then the packet is sent to **IP Layer**, and will be
-processed by the **IP Layer** firewall: IPv4 or IPv6 ruleset. Check once again
-the {doc}`general packet flow diagram</configuration/firewall/index>` if
-needed.
-
-
-For traffic that originates from the bridge itself, the base chain is
-**output**, and the base command is `set firewall bridge output filter
-...`, and the path is:
-
-
-:::{figure} /_static/images/firewall-bridge-output.png
-:::
-
-
-Custom bridge firewall chains can be created with the command `set firewall
-bridge name <name> ...`. To use such a custom chain, a rule with action jump
-and the appropriate target must be defined in a base chain.
-
-
-## Bridge Rules
-
-
-For firewall filtering, firewall rules need to be created. Each rule is
-numbered, has an action to apply if the rule is matched, and the ability
-to specify multiple matching criteria. Data packets go through the rules
-from 1 - 999999, so order is crucial. At the first match the action of the
-rule will be executed.
-
-
-### Actions
-
-
-If a rule is defined, an action must also be defined for it. This tells the
-firewall what to do if all matching criteria in the rule are met.
-
-
-In firewall bridge rules, the action can be:
-
-
-- `accept`: accept the packet.
-- `continue`: continue parsing next rule.
-- `drop`: drop the packet.
-- `jump`: jump to another custom chain.
-- `return`: Return from the current chain and continue at the next rule
- of the last chain.
-- `queue`: Enqueue packet to userspace.
-- `notrack`: ignore connection tracking system. This action is only
- available in prerouting chain.
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> action [accept | continue | drop | jump | queue | return]
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> action [accept | continue | drop | jump | queue | return]
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> action [accept | continue | drop | jump | queue | return]
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> action [accept | continue | drop | jump | notrack | queue | return]
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> action [accept | continue | drop | jump | queue | return]
-
-
-This required setting defines the action of the current rule. If action is
-set to jump, then jump-target is also needed.
-```
-
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> jump-target \<text\>
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> jump-target \<text\>
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> jump-target \<text\>
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> jump-target \<text\>
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> jump-target \<text\>
-
-
-If action is set to ``queue``, use next command to specify the queue
-target. Range is also supported:
-```
-
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> queue \<0-65535\>
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> queue \<0-65535\>
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> queue \<0-65535\>
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> queue \<0-65535\>
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> queue \<0-65535\>
-
-
-Also, if action is set to ``queue``, use next command to specify the queue
-options. Possible options are ``bypass`` and ``fanout``:
-```
-
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> queue-options bypass
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> queue-options bypass
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> queue-options bypass
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> queue-options bypass
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> queue-options bypass
-```
-
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> queue-options fanout
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> queue-options fanout
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> queue-options fanout
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> queue-options fanout
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> queue-options fanout
-```
-Also, **default-action** is an action that takes place whenever a packet does
-not match any rule in its chain. For base chains, possible options for
-**default-action** are **accept** or **drop**.
-```{cfgcmd} set firewall bridge forward filter default-action [accept | drop]
-```
-
-```{cfgcmd} set firewall bridge input filter default-action [accept | drop]
-```
-
-```{cfgcmd} set firewall bridge output filter default-action [accept | drop]
-```
-
-```{cfgcmd} set firewall bridge prerouting filter default-action [accept | drop]
-```
-
-```{cfgcmd} set firewall bridge name \<name\> default-action [accept | continue | drop | jump | reject | return]
-
-
-This sets the default action of the rule-set if a packet does not match
-any of the rules in that chain. If default-action is set to ``jump``, then
-``default-jump-target`` is also needed. Note that for base chains, default
-action can only be set to ``accept`` or ``drop``, while on custom chains
-more actions are available.
-```
-
-```{cfgcmd} set firewall bridge name \<name\> default-jump-target \<text\>
-
-To be used only when ``default-action`` is set to ``jump``. Use this
-command to specify jump target for default rule.
-```
-:::{note}
-**Important note about default-actions:**
-If the default action for any base chain is not defined, then the default
-action is set to **accept** for that chain. For custom chains, if the
-default action is not defined, then the default-action is set to **drop**.
-:::
-
-
-### Firewall Logs
-
-
-You can enable logging for every firewall rule. If enabled, other log options
-can be configured.
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> log
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> log
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> log
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> log
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> log
-
-Enable logging for the matched packet. If this configuration command is not
-present, then the log is not enabled.
-```
-
-```{cfgcmd} set firewall bridge forward filter default-log
-```
-
-```{cfgcmd} set firewall bridge input filter default-log
-```
-
-```{cfgcmd} set firewall bridge output filter default-log
-```
-
-```{cfgcmd} set firewall bridge prerouting filter default-log
-```
-
-```{cfgcmd} set firewall bridge name \<name\> default-log
-
-Use this command to enable the logging of the default action on
-the specified chain.
-```
-
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> log-options level [emerg | alert | crit | err | warn | notice | info | debug]
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> log-options level [emerg | alert | crit | err | warn | notice | info | debug]
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> log-options level [emerg | alert | crit | err | warn | notice | info | debug]
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> log-options level [emerg | alert | crit | err | warn | notice | info | debug]
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> log-options level [emerg | alert | crit | err | warn | notice | info | debug]
-
-
-Define log-level. Only applicable if rule log is enabled.
-```
-
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> log-options group \<0-65535\>
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> log-options group \<0-65535\>
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> log-options group \<0-65535\>
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> log-options group \<0-65535\>
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> log-options group \<0-65535\>
-
-
-Define the log group to send messages to. Only applicable if rule log is
-enabled.
-```
-
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> log-options snapshot-length \<0-9000\>
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> log-options snapshot-length \<0-9000\>
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> log-options snapshot-length \<0-9000\>
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> log-options snapshot-length \<0-9000\>
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> log-options snapshot-length \<0-9000\>
-
-
-Define length of packet payload to include in netlink message. Only
-applicable if rule log is enabled and the log group is defined.
-```
-
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> log-options queue-threshold \<0-65535\>
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> log-options queue-threshold \<0-65535\>
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> log-options queue-threshold \<0-65535\>
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> log-options queue-threshold \<0-65535\>
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> log-options queue-threshold \<0-65535\>
-
-
-Define the number of packets to queue inside the kernel before sending them
-to userspace. Only applicable if rule log is enabled and the log group is
-defined.
-```
-### Firewall Description
-
-
-You can define a description for reference for every custom chain.
-```{cfgcmd} set firewall bridge name \<name\> description \<text\>
-
-Provide a rule-set description to a custom firewall chain.
-```
-
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> description \<text\>
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> description \<text\>
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> description \<text\>
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> description \<text\>
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> description \<text\>
-
-
-Provide a description for each rule.
-```
-### Rule Status
-
-
-By default, when you define a rule, it is enabled. In some cases, it is
-useful to disable the rule instead of removing it.
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> disable
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> disable
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> disable
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> disable
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> disable
-
-Command for disabling a rule but keep it in the configuration.
-```
-### Matching criteria
-
-
-There are many matching criteria against which a packet can be tested. Refer
-to {doc}`IPv4</configuration/firewall/ipv4>` and
-{doc}`IPv6</configuration/firewall/ipv6>` matching criteria for more details.
-
-
-Since bridges operate at layer 2, both matchers for IPv4 and IPv6 are
-supported in bridge firewall configuration. Same applies to firewall groups.
-
-
-Same specific matching criteria that can be used in bridge firewall are
-described in this section:
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> ethernet-type [802.1q | 802.1ad | arp | ipv4 | ipv6]
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> ethernet-type [802.1q | 802.1ad | arp | ipv4 | ipv6]
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> ethernet-type [802.1q | 802.1ad | arp | ipv4 | ipv6]
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> ethernet-type [802.1q | 802.1ad | arp | ipv4 | ipv6]
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> ethernet-type [802.1q | 802.1ad | arp | ipv4 | ipv6]
-
-
-Match based on the Ethernet type of the packet.
-```
-
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> vlan ethernet-type [802.1q | 802.1ad | arp | ipv4 | ipv6]
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> vlan ethernet-type [802.1q | 802.1ad | arp | ipv4 | ipv6]
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> vlan ethernet-type [802.1q | 802.1ad | arp | ipv4 | ipv6]
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> vlan ethernet-type [802.1q | 802.1ad | arp | ipv4 | ipv6]
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> vlan ethernet-type [802.1q | 802.1ad | arp | ipv4 | ipv6]
-
-
-Match based on the Ethernet type of the packet when it is VLAN tagged.
-```
-
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> vlan id \<0-4096\>
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> vlan id \<0-4096\>
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> vlan id \<0-4096\>
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> vlan id \<0-4096\>
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> vlan id \<0-4096\>
-
-
-Match based on VLAN identifier. Range is also supported.
-```
-
-```{cfgcmd} set firewall bridge forward filter rule \<1-999999\> vlan priority \<0-7\>
-```
-
-```{cfgcmd} set firewall bridge input filter rule \<1-999999\> vlan priority \<0-7\>
-```
-
-```{cfgcmd} set firewall bridge output filter rule \<1-999999\> vlan priority \<0-7\>
-```
-
-```{cfgcmd} set firewall bridge prerouting filter rule \<1-999999\> vlan priority \<0-7\>
-```
-
-```{cfgcmd} set firewall bridge name \<name\> rule \<1-999999\> vlan priority \<0-7\>
-
-
-Match based on VLAN priority (Priority Code Point - PCP). Range is also
-supported.
-```
-### Packet Modifications
-
-
-Starting from **VyOS-1.5-rolling-202410060007**, the firewall can modify
-packets before they are sent out. This feaure provides more flexibility in
-packet handling.
-```{cfgcmd} set firewall bridge [prerouting | forward | output] filter rule \<1-999999\> set dscp \<0-63\>
-
-
-Set a specific value of Differentiated Services Codepoint (DSCP).
-```
-
-```{cfgcmd} set firewall bridge [prerouting | forward | output] filter rule \<1-999999\> set mark \<1-2147483647\>
-
-
-Set a specific packet mark value.
-```
-
-```{cfgcmd} set firewall bridge [prerouting | forward | output] filter rule \<1-999999\> set tcp-mss \<500-1460\>
-
-
-Set the TCP-MSS (TCP maximum segment size) for the connection.
-```
-
-```{cfgcmd} set firewall bridge [prerouting | forward | output] filter rule \<1-999999\> set ttl \<0-255\>
-
-
-Set the TTL (Time to Live) value.
-```
-
-```{cfgcmd} set firewall bridge [prerouting | forward | output] filter rule \<1-999999\> set hop-limit \<0-255\>
-
-
-Set hop limit value.
-```
-
-```{cfgcmd} set firewall bridge [forward | output] filter rule \<1-999999\> set connection-mark \<0-2147483647\>
-
-
-Set connection mark value.
-```
-### Use IP firewall
-
-By default, for switched traffic, only the rules defined under `set firewall
-bridge` are applied. There are two global-options that can be configured in
-order to force deeper analysis of the packet on the IP layer. These options
-are:
-```{cfgcmd} set firewall global-options apply-to-bridged-traffic ipv4
-
-This command enables the IPv4 firewall for bridged traffic. If this option
-is used, packets are also parsed by rules defined in ``set firewall ipv4
-...``
-```
-
-```{cfgcmd} set firewall global-options apply-to-bridged-traffic ipv6
-
-This command enables the IPv6 firewall for bridged traffic. If this option
-is used, packets are also parsed by rules defined in ``set firewall ipv6
-...``
-```
-## Operation-mode Firewall
-### Rule-set overview
-In this section you can find all useful firewall op-mode commands.
-General commands for firewall configuration, counter and statistics:
-```{opcmd} show firewall
-```
-
-```{opcmd} show firewall summary
-```
-
-```{opcmd} show firewall statistics
-```
-And, to print only bridge firewall information:
-```{opcmd} show firewall bridge
-```
-
-```{opcmd} show firewall bridge forward filter
-```
-
-```{opcmd} show firewall bridge forward filter rule \<rule\>
-```
-
-```{opcmd} show firewall bridge name \<name\>
-```
-
-```{opcmd} show firewall bridge name \<name\> rule \<rule\>
-```
-### Show Firewall log
-```{opcmd} show log firewall
-```
-
-```{opcmd} show log firewall bridge
-```
-
-```{opcmd} show log firewall bridge forward
-```
-
-```{opcmd} show log firewall bridge forward filter
-```
-
-```{opcmd} show log firewall bridge name \<name\>
-```
-
-```{opcmd} show log firewall bridge forward filter rule \<rule\>
-```
-
-```{opcmd} show log firewall bridge name \<name\> rule \<rule\>
-
-Show the logs of all firewall; show all bridge firewall logs; show all logs
-for forward hook; show all logs for forward hook and priority filter; show
-all logs for particular custom chain; show logs for specific Rule-Set.
-```
-### Example
-Configuration example:
-```none
-set firewall bridge forward filter default-action 'drop'
-set firewall bridge forward filter default-log
-set firewall bridge forward filter rule 10 action 'continue'
-set firewall bridge forward filter rule 10 inbound-interface name 'eth2'
-set firewall bridge forward filter rule 10 vlan id '22'
-set firewall bridge forward filter rule 20 action 'drop'
-set firewall bridge forward filter rule 20 inbound-interface group 'TRUNK-RIGHT'
-set firewall bridge forward filter rule 20 vlan id '60'
-set firewall bridge forward filter rule 30 action 'jump'
-set firewall bridge forward filter rule 30 jump-target 'TEST'
-set firewall bridge forward filter rule 30 outbound-interface name '!eth1'
-set firewall bridge forward filter rule 35 action 'accept'
-set firewall bridge forward filter rule 35 vlan id '11'
-set firewall bridge forward filter rule 40 action 'continue'
-set firewall bridge forward filter rule 40 destination mac-address '66:55:44:33:22:11'
-set firewall bridge forward filter rule 40 source mac-address '11:22:33:44:55:66'
-set firewall bridge name TEST default-action 'accept'
-set firewall bridge name TEST default-log
-set firewall bridge name TEST rule 10 action 'continue'
-set firewall bridge name TEST rule 10 log
-set firewall bridge name TEST rule 10 vlan priority '0'
-```
-And op-mode commands:
-```none
-vyos@BRI:~$ show firewall bridge
-Rulesets bridge Information
-
----------------------------------
-bridge Firewall "forward filter"
-
-Rule Action Protocol Packets Bytes Conditions
-------- -------- ---------- --------- ------- ---------------------------------------------------------------------
-10 continue all 0 0 iifname "eth2" vlan id 22 continue
-20 drop all 0 0 iifname @I_TRUNK-RIGHT vlan id 60
-30 jump all 2130 170688 oifname != "eth1" jump NAME_TEST
-35 accept all 2080 168616 vlan id 11 accept
-40 continue all 0 0 ether daddr 66:55:44:33:22:11 ether saddr 11:22:33:44:55:66 continue
-default drop all 0 0
-
----------------------------------
-bridge Firewall "name TEST"
-
-Rule Action Protocol Packets Bytes Conditions
-------- -------- ---------- --------- ------- --------------------------------------------------
-10 continue all 2130 170688 vlan pcp 0 prefix "[bri-NAM-TEST-10-C]" continue
-default accept all 2130 170688
-
-vyos@BRI:~$
-vyos@BRI:~$ show firewall bridge name TEST
-Ruleset Information
-
----------------------------------
-bridge Firewall "name TEST"
-
-Rule Action Protocol Packets Bytes Conditions
-------- -------- ---------- --------- ------- --------------------------------------------------
-10 continue all 2130 170688 vlan pcp 0 prefix "[bri-NAM-TEST-10-C]" continue
-default accept all 2130 170688
-
-vyos@BRI:~$
-```
-Inspect logs:
-```none
-vyos@BRI:~$ show log firewall bridge
-Dec 05 14:37:47 kernel: [bri-NAM-TEST-10-C]IN=eth1 OUT=eth2 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=50:00:00:04:00:00 IPSRC=10.11.11.101 MACDST=00:00:00:00:00:00 IPDST=10.11.11.102
-Dec 05 14:37:48 kernel: [bri-NAM-TEST-10-C]IN=eth1 OUT=eth2 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=50:00:00:04:00:00 IPSRC=10.11.11.101 MACDST=00:00:00:00:00:00 IPDST=10.11.11.102
-Dec 05 14:37:49 kernel: [bri-NAM-TEST-10-C]IN=eth1 OUT=eth2 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=50:00:00:04:00:00 IPSRC=10.11.11.101 MACDST=00:00:00:00:00:00 IPDST=10.11.11.102
-...
-vyos@BRI:~$ show log firewall bridge forward filter
-Dec 05 14:42:22 kernel: [bri-FWD-filter-default-D]IN=eth2 OUT=eth1 MAC=33:33:00:00:00:16:50:00:00:06:00:00:86:dd SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0
-Dec 05 14:42:22 kernel: [bri-FWD-filter-default-D]IN=eth2 OUT=eth1 MAC=33:33:00:00:00:16:50:00:00:06:00:00:86:dd SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0
-```
diff --git a/docs/configuration/firewall/md-global-options.md b/docs/configuration/firewall/md-global-options.md
deleted file mode 100644
index 3a480472..00000000
--- a/docs/configuration/firewall/md-global-options.md
+++ /dev/null
@@ -1,214 +0,0 @@
----
-lastproofread: '2026-03-30'
----
-
-(firewall-global-options-configuration)=
-
-# Global Options Firewall Configuration
-
-## Overview
-
-Some firewall settings are global and affect the entire system. This section
-provides information about these global options that you can configure using
-the VyOS CLI.
-
-Configuration commands covered in this section:
-
-```{cfgcmd} set firewall global-options ...
-```
-## Configuration
-```{cfgcmd} set firewall global-options all-ping [enable | disable]
-
-By default, when VyOS receives an ICMP echo request packet destined for
-itself, it answers with an ICMP echo reply, unless your firewall prevents
-it.
-
-You can set firewall rules to accept, drop, or reject ICMP in, out, or
-local traffic. You can also use the **firewall global-options all-ping**
-command. This command affects only LOCAL traffic (packets destined for your
-VyOS system), not IN or OUT traffic.
-
-:::{note}
-**firewall global-options all-ping** affects only LOCAL traffic
-and always behaves in the most restrictive way
-:::
-:::{code-block} none
-set firewall global-options all-ping enable
-:::
-When you set this command, VyOS answers every ICMP echo request addressed
-to itself, but that response occurs only if no other rule drops or rejects
-local echo requests. In case of conflict, VyOS does not answer ICMP echo
-requests.
-
-:::{code-block} none
-set firewall global-options all-ping disable
-:::
-When you set this command, VyOS answers no ICMP echo requests addressed to
-itself, regardless of where they come from or what specific rules accept
-them.
-```
-
-```{cfgcmd} set firewall global-options apply-to-bridged-traffic [ipv4 | ipv6]
-
-Apply IPv4 or IPv6 firewall rules to bridged traffic.
-```
-
-```{cfgcmd} set firewall global-options broadcast-ping [enable | disable]
-
-Enable or disable the response to ICMP broadcast messages. The system
-alters the following parameter:
-* ``net.ipv4.icmp_echo_ignore_broadcasts``
-```
-
-```{cfgcmd} set firewall global-options ip-src-route [enable | disable]
-```
-
-```{cfgcmd} set firewall global-options ipv6-src-route [enable | disable]
-
-Set whether VyOS accepts packets with a source route option.
-The following sysctl parameters will be changed:
-* ``net.ipv4.conf.all.accept_source_route``
-* ``net.ipv6.conf.all.accept_source_route``
-```
-
-```{cfgcmd} set firewall global-options receive-redirects [enable | disable]
-```
-
-```{cfgcmd} set firewall global-options ipv6-receive-redirects [enable | disable]
-
-Allow VyOS to accept ICMPv4 and ICMPv6 redirect messages.
-The following sysctl parameters will be changed:
-* ``net.ipv4.conf.all.accept_redirects``
-* ``net.ipv6.conf.all.accept_redirects``
-```
-
-```{cfgcmd} set firewall global-options send-redirects [enable | disable]
-
-Allow VyOS to send ICMPv4 redirect messages.
-The following sysctl parameter will be changed:
-* ``net.ipv4.conf.all.send_redirects``
-```
-
-```{cfgcmd} set firewall global-options log-martians [enable | disable]
-
-Allow VyOS to log martian IPv4 packets.
-The following sysctl parameter will be changed:
-* ``net.ipv4.conf.all.log_martians``
-```
-
-```{cfgcmd} set firewall global-options source-validation [strict | loose | disable]
-
-Set the IPv4 source validation mode.
-The following sysctl parameter will be changed:
-* ``net.ipv4.conf.all.rp_filter``
-```
-
-```{cfgcmd} set firewall global-options syn-cookies [enable | disable]
-
-Allow VyOS to use IPv4 TCP SYN Cookies.
-The following sysctl parameter will be changed:
-* ``net.ipv4.tcp_syncookies``
-```
-
-```{cfgcmd} set firewall global-options twa-hazards-protection [enable | disable]
-
-Enable or disable VyOS {rfc}`1337` conformance.
-The following sysctl parameter will be changed:
-* ``net.ipv4.tcp_rfc1337``
-```
-
-```{cfgcmd} set firewall global-options state-policy established action [accept | drop | reject]
-```
-
-```{cfgcmd} set firewall global-options state-policy established log
-```
-
-```{cfgcmd} set firewall global-options state-policy established log-level [emerg | alert | crit | err | warn | notice | info | debug]
-
-Set the global setting for an established connection.
-```
-
-```{cfgcmd} set firewall global-options state-policy invalid action [accept | drop | reject]
-```
-
-```{cfgcmd} set firewall global-options state-policy invalid log
-```
-
-```{cfgcmd} set firewall global-options state-policy invalid log-level [emerg | alert | crit | err | warn | notice | info | debug]
-
-Set the global setting for invalid packets.
-```
-
-```{cfgcmd} set firewall global-options state-policy related action [accept | drop | reject]
-```
-
-```{cfgcmd} set firewall global-options state-policy related log
-```
-
-```{cfgcmd} set firewall global-options state-policy related log-level [emerg | alert | crit | err | warn | notice | info | debug]
-
-Set the global setting for related connections.
-```
-VyOS supports setting timeouts for connections by connection type. You can
-set timeout values for generic connections, ICMP connections, UDP
-connections, or TCP connections in various states.
-```{cfgcmd} set firewall global-options timeout icmp \<1-21474836\>
-
-:defaultvalue:
-```
-
-```{cfgcmd} set firewall global-options timeout other \<1-21474836\>
-
-:defaultvalue:
-```
-
-```{cfgcmd} set firewall global-options timeout tcp close \<1-21474836\>
-
-:defaultvalue:
-```
-
-```{cfgcmd} set firewall global-options timeout tcp close-wait \<1-21474836\>
-
-:defaultvalue:
-```
-
-```{cfgcmd} set firewall global-options timeout tcp established \<1-21474836\>
-
-:defaultvalue:
-```
-
-```{cfgcmd} set firewall global-options timeout tcp fin-wait \<1-21474836\>
-
-:defaultvalue:
-```
-
-```{cfgcmd} set firewall global-options timeout tcp last-ack \<1-21474836\>
-
-:defaultvalue:
-```
-
-```{cfgcmd} set firewall global-options timeout tcp syn-recv \<1-21474836\>
-
-:defaultvalue:
-```
-
-```{cfgcmd} set firewall global-options timeout tcp syn-sent \<1-21474836\>
-
-:defaultvalue:
-```
-
-```{cfgcmd} set firewall global-options timeout tcp time-wait \<1-21474836\>
-
-:defaultvalue:
-```
-
-```{cfgcmd} set firewall global-options timeout udp other \<1-21474836\>
-
-:defaultvalue:
-```
-
-```{cfgcmd} set firewall global-options timeout udp stream \<1-21474836\>
-:defaultvalue:
-
-Set the timeout in seconds for a protocol or state.
-``` \ No newline at end of file
diff --git a/docs/configuration/firewall/md-groups.md b/docs/configuration/firewall/md-groups.md
deleted file mode 100644
index 2e4bdec1..00000000
--- a/docs/configuration/firewall/md-groups.md
+++ /dev/null
@@ -1,419 +0,0 @@
----
-lastproofread: '2026-03-30'
----
-
-(firewall-groups-configuration)=
-
-# Firewall groups
-
-## Configuration
-
-Firewall groups represent collections of IP addresses, networks, ports,
-MAC addresses, domains, or interfaces. You can reference a group in firewall,
-NAT, and policy route rules as either a source or destination matcher, and/or
-as inbound or outbound in the case of interface groups.
-
-### Address Groups
-
-An **address group** contains a single IP address or IP address range.
-
-```{cfgcmd} set firewall group address-group \<name\> address [address | address range]
-
-```
-```{cfgcmd} set firewall group ipv6-address-group \<name\> address \<address\>
-
-Define an IPv4 or IPv6 address group.
-
-:::{code-block} none
-set firewall group address-group ADR-INSIDE-v4 address 192.168.0.1
-set firewall group address-group ADR-INSIDE-v4 address 10.0.0.1-10.0.0.8
-set firewall group ipv6-address-group ADR-INSIDE-v6 address 2001:db8::1
-:::
-```
-
-```{cfgcmd} set firewall group address-group \<name\> description \<text\>
-```
-
-```{cfgcmd} set firewall group ipv6-address-group \<name\> description \<text\>
-
-Provide an IPv4 or IPv6 address group description.
-```
-### Remote Groups
-A **remote-group** uses a URL that hosts a newline-delimited list of IPv4
-and/or IPv6 addresses, CIDRs, and ranges. VyOS pulls this list periodically
-according to the frequency you define in the firewall **resolver-interval**
-and loads matching entries into the group for use in rules. The list is cached
-in persistent storage, so rules continue to function if updates fail.
-```{cfgcmd} set firewall group remote-group \<name\> url \<http(s) url\>
-
-Specify a remote list of IPv4 and/or IPv6 addresses, ranges, and CIDRs
-to fetch.
-```
-
-```{cfgcmd} set firewall group remote-group \<name\> description \<text\>
-
-Set a description for a remote group.
-```
-The remote list format is flexible. VyOS attempts to parse the first word of
-each line as an entry and skips lines it cannot match. Lines that begin with
-an alphanumeric character but do not match valid IPv4 or IPv6 addresses,
-ranges, or CIDRs are logged to the system log. The following examples show
-acceptable formats that VyOS parses correctly:
-```none
-127.0.0.1
-127.0.0.0/24
-127.0.0.1-127.0.0.254
-2001:db8::1
-2001:db8:cafe::/48
-2001:db8:cafe::1-2001:db8:cafe::ffff
-```
-### Network Groups
-**Network groups** accept IP networks in CIDR notation. You can add specific
-IP addresses as a 32-bit prefix. If you need to add a mix of addresses and
-networks, use a network group.
-```{cfgcmd} set firewall group network-group \<name\> network \<CIDR\>
-```
-
-```{cfgcmd} set firewall group ipv6-network-group \<name\> network \<CIDR\>
-
-Define an IPv4 or IPv6 network group.
-
-:::{code-block} none
-set firewall group network-group NET-INSIDE-v4 network 192.168.0.0/24
-set firewall group network-group NET-INSIDE-v4 network 192.168.1.0/24
-set firewall group ipv6-network-group NET-INSIDE-v6 network 2001:db8::/64
-:::
-```
-
-```{cfgcmd} set firewall group network-group \<name\> description \<text\>
-```
-
-```{cfgcmd} set firewall group ipv6-network-group \<name\> description \<text\>
-
-Provide an IPv4 or IPv6 network group description.
-```
-### Interface Groups
-An **interface group** represents a collection of interfaces.
-```{cfgcmd} set firewall group interface-group \<name\> interface \<text\>
-
-Define an interface group.
-Wildcard ``*`` is supported. For example: ``eth3*``.
-Prepend the character ``!`` to invert the criteria. For example: ``!eth2``.
-```
-
-```none
-set firewall group interface-group LAN interface bond1001
-set firewall group interface-group LAN interface eth3*
-```
-
-```{cfgcmd} set firewall group interface-group \<name\> description \<text\>
-
-Provide an interface group description.
-```
-### Port Groups
-A **port group** represents only port numbers, not the protocol. You can
-reference port groups for either TCP or UDP. Create TCP and UDP groups
-separately to avoid accidentally filtering unnecessary ports. Specify port
-ranges by using `-`.
-```{cfgcmd} set firewall group port-group \<name\> port [portname | portnumber | startport-endport]
-
-Define a port group. A port name can be any name defined in
-/etc/services. For example, ``http``.
-
-:::{code-block} none
-set firewall group port-group PORT-TCP-SERVER1 port http
-set firewall group port-group PORT-TCP-SERVER1 port 443
-set firewall group port-group PORT-TCP-SERVER1 port 5000-5010
-:::
-```
-
-```{cfgcmd} set firewall group port-group \<name\> description \<text\>
-
-Provide a port group description.
-```
-### MAC Groups
-A **mac group** represents a collection of mac addresses.
-```{cfgcmd} set firewall group mac-group \<name\> mac-address \<mac-address\>
-
-Define a mac group.
-```
-
-```none
-set firewall group mac-group MAC-G01 mac-address 88:a4:c2:15:b6:4f
-set firewall group mac-group MAC-G01 mac-address 4c:d5:77:c0:19:81
-```
-
-```{cfgcmd} set firewall group mac-group \<name\> description \<text\>
-
-Provide a MAC group description.
-```
-### Domain Groups
-A **domain group** represents a collection of domains.
-```{cfgcmd} set firewall group domain-group \<name\> address \<domain\>
-
-Define a domain group.
-```
-
-```none
-set firewall group domain-group DOM address example.com
-```
-
-```{cfgcmd} set firewall group domain-group \<name\> description \<text\>
-
-Provide a domain group description.
-```
-### Dynamic Groups
-Firewall dynamic groups differ from other groups because you can use them as
-source/destination in firewall rules, and members are not defined statically
-in VyOS configuration. Instead, firewall rules dynamically add members to
-these groups.
-
-#### Defining Dynamic Address Groups
-Dynamic address groups support both IPv4 and IPv6 families. Use these
-commands to define dynamic IPv4 and IPv6 address groups:
-```{cfgcmd} set firewall group dynamic-group address-group \<name\>
-```
-
-```{cfgcmd} set firewall group dynamic-group ipv6-address-group \<name\>
-```
-Add description to firewall groups:
-```{cfgcmd} set firewall group dynamic-group address-group \<name\> description <text>
-```
-
-```{cfgcmd} set firewall group dynamic-group ipv6-address-group \<name\> description <text>
-```
-#### Adding elements to Dynamic Firewall Groups
-After you define dynamic firewall groups, use them in firewall rules to
-dynamically add elements to them.
-
-Commands used for this task are:
-- Add destination IP address of the connection to a dynamic address group:
-```{cfgcmd} set firewall ipv4 [forward | input | output] filter rule \<1-999999\> add-address-to-group destination-address address-group \<name\>
-```
-
-```{cfgcmd} set firewall ipv4 name \<name\> rule \<1-999999\> add-address-to-group destination-address address-group <name>
-```
-
-```{cfgcmd} set firewall ipv6 [forward | input | output] filter rule \<1-999999\> add-address-to-group destination-address address-group \<name\>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> add-address-to-group destination-address address-group <name>
-```
-- Add source IP address of the connection to a dynamic address group:
-```{cfgcmd} set firewall ipv4 [forward | input | output] filter rule \<1-999999\> add-address-to-group source-address address-group \<name\>
-```
-
-```{cfgcmd} set firewall ipv4 name \<name\> rule \<1-999999\> add-address-to-group source-address address-group <name>
-```
-
-```{cfgcmd} set firewall ipv6 [forward | input | output] filter rule \<1-999999\> add-address-to-group source-address address-group \<name\>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> add-address-to-group source-address address-group <name>
-```
-You can define specific timeouts per rule. When a rule matches, the source or
-destination address is added to the group, and the element remains in the group
-until the timeout expires. If you do not define a timeout, the element remains
-in the group until the next reboot or until you commit firewall configuration
-changes.
-```{cfgcmd} set firewall ipv4 [forward | input | output] filter rule \<1-999999\> add-address-to-group [destination-address | source-address] timeout <timeout>
-```
-
-```{cfgcmd} set firewall ipv4 name \<name\> rule \<1-999999\> add-address-to-group [destination-address | source-address] timeout \<timeout\>
-```
-
-```{cfgcmd} set firewall ipv6 [forward | input | output] filter rule \<1-999999\> add-address-to-group [destination-address | source-address] timeout <timeout>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> add-address-to-group [destination-address | source-address] timeout \<timeout\>
-```
-Timeout can be defined using seconds, minutes, hours or days:
-```none
-set firewall ipv6 name FOO rule 10 add-address-to-group source-address timeout
-Possible completions:
-<number>s Timeout value in seconds
-<number>m Timeout value in minutes
-<number>h Timeout value in hours
-<number>d Timeout value in days
-```
-#### Using Dynamic Firewall Groups
-Like other firewall groups, you can use dynamic firewall groups in firewall
-rules as matching options. For example:
-```none
-set firewall ipv4 input filter rule 10 source group dynamic-address-group FOO
-set firewall ipv4 input filter rule 10 destination group dynamic-address-group BAR
-```
-## Examples
-
-### General example
-After you create firewall groups, you can reference them in firewall, NAT,
-NAT66, and/or policy-route rules. The following example creates multiple
-groups:
-```none
-set firewall group address-group SERVERS address 198.51.100.101
-set firewall group address-group SERVERS address 198.51.100.102
-set firewall group network-group TRUSTEDv4 network 192.0.2.0/30
-set firewall group network-group TRUSTEDv4 network 203.0.113.128/25
-set firewall group ipv6-network-group TRUSTEDv6 network 2001:db8::/64
-set firewall group interface-group LAN interface eth2.2001
-set firewall group interface-group LAN interface bon0
-set firewall group port-group PORT-SERVERS port http
-set firewall group port-group PORT-SERVERS port 443
-set firewall group port-group PORT-SERVERS port 5000-5010
-```
-And next, some configuration example where groups are used:
-```none
-set firewall ipv4 output filter rule 10 action accept
-set firewall ipv4 output filter rule 10 outbound-interface group !LAN
-set firewall ipv4 forward filter rule 20 action accept
-set firewall ipv4 forward filter rule 20 source group network-group TRUSTEDv4
-set firewall ipv6 input filter rule 10 action accept
-set firewall ipv6 input filter rule 10 source group network-group TRUSTEDv6
-set nat destination rule 101 inbound-interface group LAN
-set nat destination rule 101 destination group address-group SERVERS
-set nat destination rule 101 protocol tcp
-set nat destination rule 101 destination group port-group PORT-SERVERS
-set nat destination rule 101 translation address 203.0.113.250
-set policy route PBR rule 201 destination group port-group PORT-SERVERS
-set policy route PBR rule 201 protocol tcp
-set policy route PBR rule 201 set table 15
-```
-### Port knocking example
-You can use dynamic firewall groups with port knocking to secure access to
-the router or any other device. The following example shows a 4-step port
-knocking configuration:
-```none
-set firewall global-options state-policy established action 'accept'
-set firewall global-options state-policy invalid action 'drop'
-set firewall global-options state-policy related action 'accept'
-set firewall group dynamic-group address-group ALLOWED
-set firewall group dynamic-group address-group PN_01
-set firewall group dynamic-group address-group PN_02
-set firewall ipv4 input filter default-action 'drop'
-set firewall ipv4 input filter rule 5 action 'accept'
-set firewall ipv4 input filter rule 5 protocol 'icmp'
-set firewall ipv4 input filter rule 10 action 'drop'
-set firewall ipv4 input filter rule 10 add-address-to-group source-address address-group 'PN_01'
-set firewall ipv4 input filter rule 10 add-address-to-group source-address timeout '2m'
-set firewall ipv4 input filter rule 10 description 'Port_nock 01'
-set firewall ipv4 input filter rule 10 destination port '9990'
-set firewall ipv4 input filter rule 10 protocol 'tcp'
-set firewall ipv4 input filter rule 20 action 'drop'
-set firewall ipv4 input filter rule 20 add-address-to-group source-address address-group 'PN_02'
-set firewall ipv4 input filter rule 20 add-address-to-group source-address timeout '3m'
-set firewall ipv4 input filter rule 20 description 'Port_nock 02'
-set firewall ipv4 input filter rule 20 destination port '9991'
-set firewall ipv4 input filter rule 20 protocol 'tcp'
-set firewall ipv4 input filter rule 20 source group dynamic-address-group 'PN_01'
-set firewall ipv4 input filter rule 30 action 'drop'
-set firewall ipv4 input filter rule 30 add-address-to-group source-address address-group 'ALLOWED'
-set firewall ipv4 input filter rule 30 add-address-to-group source-address timeout '2h'
-set firewall ipv4 input filter rule 30 description 'Port_nock 03'
-set firewall ipv4 input filter rule 30 destination port '9992'
-set firewall ipv4 input filter rule 30 protocol 'tcp'
-set firewall ipv4 input filter rule 30 source group dynamic-address-group 'PN_02'
-set firewall ipv4 input filter rule 99 action 'accept'
-set firewall ipv4 input filter rule 99 description 'Port_nock 04 - Allow ssh'
-set firewall ipv4 input filter rule 99 destination port '22'
-set firewall ipv4 input filter rule 99 protocol 'tcp'
-set firewall ipv4 input filter rule 99 source group dynamic-address-group 'ALLOWED'
-```
-Before testing, we can check the members of firewall groups:
-```none
-vyos@vyos# run show firewall group
-Firewall Groups
-
-Name Type References Members Timeout Expires
-------- ---------------------- -------------------- ------------- --------- ---------
-ALLOWED address_group(dynamic) ipv4-input-filter-30 N/D N/D N/D
-PN_01 address_group(dynamic) ipv4-input-filter-10 N/D N/D N/D
-PN_02 address_group(dynamic) ipv4-input-filter-20 N/D N/D N/D
-[edit]
-vyos@vyos#
-```
-With this configuration, to gain SSH access to the router, the user must:
-
-1. Create a new TCP connection to destination port 9990. A new entry is added
- to dynamic firewall group `PN_01`.
-
- ```none
- vyos@vyos# run show firewall group
- Firewall Groups
-
- Name Type References Members Timeout Expires
- ------- ---------------------- -------------------- ------------- --------- ---------
- ALLOWED address_group(dynamic) ipv4-input-filter-30 N/D N/D N/D
- PN_01 address_group(dynamic) ipv4-input-filter-10 192.168.89.31 120 119
- PN_02 address_group(dynamic) ipv4-input-filter-20 N/D N/D N/D
- [edit]
- vyos@vyos#
- ```
-
-2. Create a new TCP connection to destination port 9991. A new entry is added
- to dynamic firewall group `PN_02`.
-
- ```none
- vyos@vyos# run show firewall group
- Firewall Groups
-
- Name Type References Members Timeout Expires
- ------- ---------------------- -------------------- ------------- --------- ---------
- ALLOWED address_group(dynamic) ipv4-input-filter-30 N/D N/D N/D
- PN_01 address_group(dynamic) ipv4-input-filter-10 192.168.89.31 120 106
- PN_02 address_group(dynamic) ipv4-input-filter-20 192.168.89.31 180 179
- [edit]
- vyos@vyos#
- ```
-
-3. Create a new TCP connection to destination port 9992. A new entry is added
- to dynamic firewall group `ALLOWED`.
-
- ```none
- vyos@vyos# run show firewall group
- Firewall Groups
-
- Name Type References Members Timeout Expires
- ------- ---------------------- -------------------- ------------- --------- ---------
- ALLOWED address_group(dynamic) ipv4-input-filter-30 192.168.89.31 7200 7199
- PN_01 address_group(dynamic) ipv4-input-filter-10 192.168.89.31 120 89
- PN_02 address_group(dynamic) ipv4-input-filter-20 192.168.89.31 180 170
- [edit]
- vyos@vyos#
- ```
-
-4. Now you can connect via SSH to the router (assuming SSH is
- configured).
-
-## Operation-mode
-```{opcmd} show firewall group
-```
-
-```{opcmd} show firewall group \<name\>
-
-Display an overview of defined groups, including the firewall group name,
-type, references (where the group is used), members, timeout, and
-expiration (the last two only apply to dynamic firewall groups).
-```
-Here is an example of such command:
-```none
-vyos@vyos:~$ show firewall group
-Firewall Groups
-
-Name Type References Members Timeout Expires
------------- ---------------------- ---------------------- ---------------- --------- ---------
-SERVERS address_group nat-destination-101 198.51.100.101
- 198.51.100.102
-ALLOWED address_group(dynamic) ipv4-input-filter-30 192.168.77.39 7200 7174
-PN_01 address_group(dynamic) ipv4-input-filter-10 192.168.0.245 120 112
- 192.168.77.39 120 85
-PN_02 address_group(dynamic) ipv4-input-filter-20 192.168.77.39 180 151
-LAN interface_group ipv4-output-filter-10 bon0
- nat-destination-101 eth2.2001
-TRUSTEDv6 ipv6_network_group ipv6-input-filter-10 2001:db8::/64
-TRUSTEDv4 network_group ipv4-forward-filter-20 192.0.2.0/30
- 203.0.113.128/25
-PORT-SERVERS port_group route-PBR-201 443
- route-PBR-201 5000-5010
- nat-destination-101 http
-vyos@vyos:~$
-```
diff --git a/docs/configuration/firewall/md-ipv6.md b/docs/configuration/firewall/md-ipv6.md
deleted file mode 100644
index bbbaec16..00000000
--- a/docs/configuration/firewall/md-ipv6.md
+++ /dev/null
@@ -1,1624 +0,0 @@
----
-lastproofread: '2026-04-01'
----
-
-(firewall-ipv6-configuration)=
-
-# IPv6 Firewall Configuration
-
-## Overview
-
-This section covers useful information about IPv6 firewall configuration and
-appropriate operation-mode commands.
-
-This section describes the following configuration commands:
-
-```{cfgcmd} set firewall ipv6 ...
-```
-To learn about the general traffic flow in VyOS firewalls, see {doc}`Firewall </configuration/firewall/index>`.
-```none
-- set firewall
- * ipv6
- - forward
- + filter
- - input
- + filter
- - output
- + filter
- + raw
- - prerouting
- + raw
- - name
- + custom_name
-```
-The router first receives all traffic and processes it in the **prerouting**
-section.
-
-
-This stage includes:
-
-
-- **Firewall Prerouting**: commands found under `set firewall ipv6
- prerouting raw ...`
-- {doc}`Conntrack Ignore</configuration/system/conntrack>`: `set system
- conntrack ignore ipv6...`
-- {doc}`Policy Route</configuration/policy/route>`: commands found under
- `set policy route6 ...`
-- {doc}`Destination NAT</configuration/nat/nat44>`: commands found under
- `set nat66 destination ...`
-
-
-For transit traffic that the router receives and forwards, the base chain is
-**forward**. The following diagram shows a simplified packet flow for transit
-traffic:
-
-
-:::{figure} /_static/images/firewall-fwd-packet-flow.png
-:::
-
-
-Use `set firewall ipv6 forward filter ...` to configure filtering rules for
-transit traffic. This command corresponds to stage 5 and is highlighted in red
-in the diagram.
-
-
-For traffic destined to the router, use the **input** chain. For traffic the
-router generates, use the **output** chain. The following diagram shows the
-packet flow for traffic destined to the router and traffic generated by the
-router (starting from circle number 6):
-
-
-:::{figure} /_static/images/firewall-input-packet-flow.png
-:::
-
-
-Use `set firewall ipv6 input filter ...` to configure traffic destined to
-the router.
-
-
-Use `set firewall ipv6 output ...` to configure traffic the router generates.
-Two sub-chains are available: **filter** and **raw**:
-
-
-- **Output Prerouting**: `set firewall ipv6 output raw ...`.
- As described in **Prerouting**, the firewall processes rules in this
- section before the connection tracking subsystem.
-- **Output Filter**: `set firewall ipv6 output filter ...`. The firewall
- processes rules in this section after the connection tracking subsystem.
-
-
-:::{note}
-**Important note about default-actions:**
-If you do not define a default action for a base chain, the system sets
-the default action to **accept** for that chain. For custom chains, if you
-do not define a default action, the system sets the default-action to
-**drop**
-:::
-
-
-Create custom firewall chains using the commands
-`set firewall ipv6 name <name> ...`. To use the custom chain, define a
-rule with **action jump** and the appropriate **target** in a base chain.
-
-
-## Firewall - IPv6 Rules
-
-
-Create firewall rules for firewall filtering. Each rule is numbered and has
-an action to apply when the rule is matched. You can specify multiple matching
-criteria. Packets go through rules from 1 - 999999, so order is crucial. The
-firewall executes the action of the first matching rule.
-
-
-### Actions
-
-
-If you define a rule, you must define an action for it. The action tells the
-firewall what to do when all criteria for that rule are met.
-
-
-The action can be :
-
-
-- `accept`: accept the packet.
-- `continue`: continue parsing next rule.
-- `drop`: drop the packet.
-- `reject`: reject the packet.
-- `jump`: jump to another custom chain.
-- `return`: Return from the current chain and continue at the next rule
- of the last chain.
-- `queue`: Enqueue packet to userspace.
-- `synproxy`: synproxy the packet.
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> action [accept | continue | drop | jump | queue | reject | return | synproxy]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> action [accept | continue | drop | jump | queue | reject | return | synproxy]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> action [accept | continue | drop | jump | queue | reject | return]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> action [accept | continue | drop | jump | queue | reject | return]
-
-
-This required setting defines the action of the current rule. If you set
-the action to jump, you must also define a jump-target.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> jump-target <text>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> jump-target <text>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> jump-target <text>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> jump-target <text>
-
-
-Use this command only when action is set to ``jump``. Specify the jump
-target.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> queue <0-65535>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> queue <0-65535>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> queue <0-65535>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> queue <0-65535>
-
-
-Use this command only when action is set to ``queue``. Specify the queue
-target. Queue ranges are also supported.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> queue-options bypass
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> queue-options bypass
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> queue-options bypass
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> queue-options bypass
-
-
-Use this command only when action is set to ``queue``. This command allows
-the packet to go through the firewall when no userspace software is connected
-to the queue.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> queue-options fanout
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> queue-options fanout
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> queue-options fanout
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> queue-options fanout
-
-
-Use this command only when action is set to ``queue``. This command
-distributes packets among multiple queues.
-```
-Also, **default-action** is an action that takes place whenever a packet does
-not match any rule in its chain. For base chains, possible options for
-**default-action** are **accept** or **drop**.
-```{cfgcmd} set firewall ipv6 forward filter default-action [accept | drop]
-```
-
-```{cfgcmd} set firewall ipv6 input filter default-action [accept | drop]
-```
-
-```{cfgcmd} set firewall ipv6 output filter default-action [accept | drop]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> default-action [accept | drop | jump | queue | reject | return]
-
-
-Set the default action of the rule-set if a packet does not match any rule
-criteria. If you set default-action to ``jump``, you must also define
-``default-jump-target``. For base chains, you can only set the default
-action to ``accept`` or ``drop``. For custom chains, more actions are
-available.
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> default-jump-target \<text\>
-
-To be used only when ``default-action`` is set to ``jump``. Use this
-command to specify the jump target for the default rule.
-```
-:::{note}
-**Important note about default-actions:**
-If you do not define the default action for a base chain, the system sets
-the default action to **accept** for that chain. For custom chains, if you
-do not define a default action, the system sets the default-action to
-**drop**.
-:::
-
-
-### Firewall Logs
-
-
-You can enable logging for each firewall rule. When enabled, you can also
-define other log options.
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> log
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> log
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> log
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> log
-
-Enable logging for matched packets. If this configuration command is not
-present, logging is disabled.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter default-log
-```
-
-```{cfgcmd} set firewall ipv6 input filter default-log
-```
-
-```{cfgcmd} set firewall ipv6 output filter default-log
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> default-log
-
-Use this command to enable the logging of the default action on
-the specified chain.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> log-options level [emerg | alert | crit | err | warn | notice | info | debug]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> log-options level [emerg | alert | crit | err | warn | notice | info | debug]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> log-options level [emerg | alert | crit | err | warn | notice | info | debug]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> log-options level [emerg | alert | crit | err | warn | notice | info | debug]
-
-
-Define log-level. Only applicable if rule log is enabled.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> log-options group <0-65535>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> log-options group <0-65535>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> log-options group <0-65535>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> log-options group <0-65535>
-
-
-Define the log group to send messages to. Only applicable if rule log is
-enabled.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> log-options snapshot-length <0-9000>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> log-options snapshot-length <0-9000>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> log-options snapshot-length <0-9000>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> log-options snapshot-length <0-9000>
-
-
-Define the length of packet payload to include in a netlink message. Only
-applicable when rule logging is enabled and log group is defined.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> log-options queue-threshold <0-65535>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> log-options queue-threshold <0-65535>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> log-options queue-threshold <0-65535>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> log-options queue-threshold <0-65535>
-
-
-Define the number of packets to queue inside the kernel before sending them
-to userspace. Only applicable when rule logging is enabled and log group is
-defined.
-```
-### Firewall Description
-
-
-For reference, you can define descriptions on every rule and custom chain.
-```{cfgcmd} set firewall ipv6 name \<name\> description \<text\>
-
-Provide a rule-set description to a custom firewall chain.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> description <text>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> description <text>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> description <text>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> description \<text\>
-
-Provide a description for each rule.
-```
-### Rule Status
-
-
-New rules are enabled by default. In some cases, you may want to disable a
-rule rather than remove it.
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> disable
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> disable
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> disable
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> disable
-
-Command for disabling a rule but keep it in the configuration.
-```
-### Matching criteria
-
-
-There are a lot of matching criteria against which the packet can be tested.
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> connection-status nat [destination | source]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> connection-status nat [destination | source]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> connection-status nat [destination | source]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> connection-status nat [destination | source]
-
-
-Match packets based on NAT connection status.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> connection-mark <1-2147483647>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> connection-mark <1-2147483647>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> connection-mark <1-2147483647>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> connection-mark <1-2147483647>
-
-
-Match packets based on connection mark.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source address [address | addressrange | CIDR]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> source address [address | addressrange | CIDR]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> source address [address | addressrange | CIDR]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> source address [address | addressrange | CIDR]
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> destination address [address | addressrange | CIDR]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> destination address [address | addressrange | CIDR]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> destination address [address | addressrange | CIDR]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> destination address [address | addressrange | CIDR]
-
-
-Match based on source or destination address. This is similar to network
-groups, but you can negate the matching addresses here.
-
-
-:::{code-block} none
-set firewall ipv6 name FOO rule 100 source address 2001:db8::202
-:::
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source address-mask [address]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> source address-mask [address]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> source address-mask [address]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> source address-mask [address]
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> destination address-mask [address]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> destination address-mask [address]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> destination address-mask [address]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> destination address-mask [address]
-
-
-Apply an arbitrary netmask to mask addresses and match only a specific
-portion. This is useful for IPv6 because rules remain valid when the IPv6
-prefix changes if the host portion of the system's IPv6 address is static.
-Examples include SLAAC and [tokenised IPv6 addresses](https://datatracker.ietf.org/doc/id/draft-chown-6man-tokenised-ipv6-identifiers-02.txt)
-
-
-This function works for both individual addresses and address groups.
-
-
-% stop_vyoslinter
-
-:::{code-block} none
-# Match any IPv6 address with the suffix ::0000:0000:0000:beef
-set firewall ipv6 forward filter rule 100 destination address ::beef
-set firewall ipv6 forward filter rule 100 destination address-mask ::ffff:ffff:ffff:ffff
-# Address groups
-set firewall group ipv6-address-group WEBSERVERS address ::1000
-set firewall group ipv6-address-group WEBSERVERS address ::2000
-set firewall ipv6 forward filter rule 200 source group address-group WEBSERVERS
-set firewall ipv6 forward filter rule 200 source address-mask ::ffff:ffff:ffff:ffff
-:::
-% start_vyoslinter
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source fqdn <fqdn>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> source fqdn <fqdn>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> source fqdn <fqdn>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> source fqdn <fqdn>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> destination fqdn <fqdn>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> destination fqdn <fqdn>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> destination fqdn <fqdn>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> destination fqdn <fqdn>
-
-
-Specify a Fully Qualified Domain Name as source or destination to match.
-Ensure that the router can resolve the DNS query.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source geoip country-code <country>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> source geoip country-code <country>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> source geoip country-code <country>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> source geoip country-code <country>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> destination geoip country-code <country>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> destination geoip country-code <country>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> destination geoip country-code <country>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> destination geoip country-code <country>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source geoip inverse-match
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> source geoip inverse-match
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> source geoip inverse-match
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> source geoip inverse-match
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> destination geoip inverse-match
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> destination geoip inverse-match
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> destination geoip inverse-match
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> destination geoip inverse-match
-
-
-Match IP addresses based on their geolocation. For more information, see
-[GeoIP matching](https://wiki.nftables.org/wiki-nftables/index.php/GeoIP_matching).
-Use inverse-match to match anything except the specified country codes.
-```
-DB-IP.com provides data under CC-BY-4.0 license. Attribution is required and
-redistribution is permitted, allowing VyOS to include a database in images
-(approximately 3 MB compressed). The package includes a cron script that you
-can manually call through op-mode update geoip to keep the database and rules
-updated.
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source mac-address <mac-address>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> source mac-address <mac-address>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> source mac-address <mac-address>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> source mac-address <mac-address>
-
-
-You can specify only a source MAC address to match.
-
-
-:::{code-block} none
-set firewall ipv6 input filter rule 100 source mac-address 00:53:00:11:22:33
-set firewall ipv6 input filter rule 101 source mac-address !00:53:00:aa:12:34
-:::
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source port [1-65535 | portname | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> source port [1-65535 | portname | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> source port [1-65535 | portname | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> source port [1-65535 | portname | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> destination port [1-65535 | portname | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> destination port [1-65535 | portname | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> destination port [1-65535 | portname | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> destination port [1-65535 | portname | start-end]
-
-
-Specify a port by number or by name as defined in ``/etc/services``.
-
-
-:::{code-block} none
-set firewall ipv6 forward filter rule 10 source port '22'
-set firewall ipv6 forward filter rule 11 source port '!http'
-set firewall ipv6 forward filter rule 12 source port 'https'
-:::
-Multiple source ports can be specified as a comma-separated list.
-The whole list can also be "negated" using ``!``. For example:
-
-
-:::{code-block} none
-set firewall ipv6 forward filter rule 10 source port '!22,https,3333-3338'
-:::
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source group address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> source group address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> source group address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> source group address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> destination group address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> destination group address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> destination group address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> destination group address-group <name | !name>
-
-
-Specify an address group. You can prepend the character ``!`` to invert the
-matching criteria.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source group dynamic-address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> source group dynamic-address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> source group dynamic-address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> source group dynamic-address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> destination group dynamic-address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> destination group dynamic-address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> destination group dynamic-address-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> destination group dynamic-address-group <name | !name>
-
-
-Specify a dynamic address group. You can prepend the character ``!`` to
-invert the matching criteria.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source group network-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> source group network-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> source group network-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> source group network-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> destination group network-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> destination group network-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> destination group network-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> destination group network-group <name | !name>
-
-
-Specify a network group. You can prepend the character ``!`` to invert the
-matching criteria.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source group port-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> source group port-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> source group port-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> source group port-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> destination group port-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> destination group port-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> destination group port-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> destination group port-group <name | !name>
-
-
-Specify a port group. You can prepend the character ``!`` to invert the
-matching criteria.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source group domain-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> source group domain-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> source group domain-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> source group domain-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> destination group domain-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> destination group domain-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> destination group domain-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> destination group domain-group <name | !name>
-
-
-Specify a domain group. You can prepend the character ``!`` to invert the
-matching criteria.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source group mac-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> source group mac-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> source group mac-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> source group mac-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> destination group mac-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> destination group mac-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> destination group mac-group <name | !name>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> destination group mac-group <name | !name>
-
-
-Specify a MAC group. You can prepend the character ``!`` to invert the
-matching criteria.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> dscp [0-63 | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> dscp [0-63 | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> dscp [0-63 | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> dscp [0-63 | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> dscp-exclude [0-63 | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> dscp-exclude [0-63 | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> dscp-exclude [0-63 | start-end]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> dscp-exclude [0-63 | start-end]
-
-
-Match based on dscp value.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> fragment [match-frag | match-non-frag]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> fragment [match-frag | match-non-frag]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> fragment [match-frag | match-non-frag]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> fragment [match-frag | match-non-frag]
-
-
-Match packets based on fragmentation.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> icmpv6 [code | type] <0-255>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> icmpv6 [code | type] <0-255>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> icmpv6 [code | type] <0-255>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> icmpv6 [code | type] <0-255>
-
-
-Match packets based on ICMP or ICMPv6 code and type.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> icmpv6 type-name <text>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> icmpv6 type-name <text>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> icmpv6 type-name <text>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> icmpv6 type-name <text>
-
-
-Match based on ICMPv6 type-name. Press **Tab** for information about
-supported **type-name** criteria.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> inbound-interface name <iface>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> inbound-interface name <iface>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> inbound-interface name <iface>
-
-
-Match based on inbound interface. You can use the wildcard ``*``. For
-example: ``eth2*``. You can prepend the character ``!`` to invert the
-matching criteria. For example ``!eth2``
-```
-:::{note}
-If an interface is attached to a non-default VRF, when using
-**inbound-interface**, use the VRF name. For example:
-`set firewall ipv6 forward filter rule 10 inbound-interface name MGMT`
-:::
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> inbound-interface group <iface_group>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> inbound-interface group <iface_group>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> inbound-interface group <iface_group>
-
-
-Match based on the inbound interface group. You can prepend the character
-``!`` to invert the matching criteria. For example ``!IFACE_GROUP``
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> outbound-interface name <iface>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> outbound-interface name <iface>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> outbound-interface name <iface>
-
-
-Match based on outbound interface. You can use the wildcard ``*``. For
-example: ``eth2*``. You can prepend the character ``!`` to invert the
-matching criteria. For example ``!eth2``
-```
-:::{note}
-If an interface is attached to a non-default VRF, when using
-**outbound-interface**, use the physical interface name. For example:
-`set firewall ipv6 forward filter rule 10 outbound-interface name eth0`
-:::
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> outbound-interface group <iface_group>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> outbound-interface group <iface_group>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> outbound-interface group <iface_group>
-
-
-Match based on outbound interface group. You can prepend the character ``!``
-to invert the matching criteria. For example ``!IFACE_GROUP``
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> ipsec [match-ipsec-in | match-ipsec-out | match-none-in | match-none-out]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> ipsec [match-ipsec-in | match-none-in]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> ipsec [match-ipsec-out | match-none-out]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> ipsec [match-ipsec-in | match-ipsec-out | match-none-in | match-none-out]
-
-
-Match packets based on IPsec.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> limit burst <0-4294967295>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> limit burst <0-4294967295>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> limit burst <0-4294967295>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> limit burst <0-4294967295>
-
-
-Match based on the maximum number of packets allowed to exceed the rate
-limit.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> limit rate <text>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> limit rate <text>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> limit rate <text>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> limit rate <text>
-
-
-Match based on the maximum average rate, specified as ``integer/unit``.
-For example, specify ``5/minutes``.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> packet-length <text>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> packet-length <text>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> packet-length <text>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> packet-length <text>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> packet-length-exclude <text>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> packet-length-exclude <text>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> packet-length-exclude <text>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> packet-length-exclude <text>
-
-
-Match based on packet length. You can specify multiple values from 1 to
-65535 and ranges.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> packet-type [broadcast | host | multicast | other]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> packet-type [broadcast | host | multicast | other]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> packet-type [broadcast | host | multicast | other]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> packet-type [broadcast | host | multicast | other]
-
-
-Match based on packet type.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> protocol [<text> | <0-255> | all | tcp_udp]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> protocol [<text> | <0-255> | all | tcp_udp]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> protocol [<text> | <0-255> | all | tcp_udp]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> protocol [<text> | <0-255> | all | tcp_udp]
-
-
-Match based on protocol number or name as defined in ``/etc/protocols``.
-Specify ``all`` for all protocols and ``tcp_udp`` for TCP and UDP packets.
-Prepend ``!`` to negate the protocol selection.
-
-
-:::{code-block} none
-set firewall ipv6 input filter rule 10 protocol tcp
-:::
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> recent count <1-255>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> recent count <1-255>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> recent count <1-255>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> recent count <1-255>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> recent time [second | minute | hour]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> recent time [second | minute | hour]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> recent time [second | minute | hour]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> recent time [second | minute | hour]
-
-
-Match packets based on recently seen sources.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> tcp flags [not] <text>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> tcp flags [not] <text>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> tcp flags [not] <text>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> tcp flags [not] <text>
-
-
-Allowed values for TCP flags: ``ack``, ``cwr``, ``ecn``, ``fin``, ``psh``,
-``rst``, ``syn``, and ``urg``. You can specify multiple values. To invert
-the selection, use ``not``, as shown in the following example.
-
-
-:::{code-block} none
-set firewall ipv6 input filter rule 10 tcp flags 'ack'
-set firewall ipv6 input filter rule 12 tcp flags 'syn'
-set firewall ipv6 input filter rule 13 tcp flags not 'fin'
-:::
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> state [established | invalid | new | related]
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> state [established | invalid | new | related]
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> state [established | invalid | new | related]
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> state [established | invalid | new | related]
-
-
-Match based on packet state.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> time startdate <text>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> time startdate <text>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> time startdate <text>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> time startdate <text>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> time starttime <text>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> time starttime <text>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> time starttime <text>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> time starttime <text>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> time stopdate <text>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> time stopdate <text>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> time stopdate <text>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> time stopdate <text>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> time stoptime <text>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> time stoptime <text>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> time stoptime <text>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> time stoptime <text>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> time weekdays <text>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> time weekdays <text>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> time weekdays <text>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> time weekdays <text>
-
-
-Match packets based on time criteria.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> hop-limit <eq | gt | lt> <0-255>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> hop-limit <eq | gt | lt> <0-255>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> hop-limit <eq | gt | lt> <0-255>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> hop-limit <eq | gt | lt> <0-255>
-
-
-Match the hop-limit parameter. Use ``eq`` for equal, ``gt`` for greater than,
-and ``lt`` for less than.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> recent count <1-255>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> recent count <1-255>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> recent count <1-255>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> recent count <1-255>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> recent time <second | minute | hour>
-```
-
-```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> recent time <second | minute | hour>
-```
-
-```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> recent time <second | minute | hour>
-```
-
-```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> recent time <second | minute | hour>
-
-
-Match when the specified number of connections occur within the specified
-time period. Use these criteria to block brute-force attempts.
-```
-### Packet Modifications
-
-
-The firewall can modify packets before sending them.
-This feature provides more flexibility for packet handling.
-```{cfgcmd} set firewall ipv6 prerouting raw rule \<1-999999\> set dscp <0-63>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> set dscp <0-63>
-```
-
-```{cfgcmd} set firewall ipv6 output [filter | raw] rule \<1-999999\> set dscp <0-63>
-
-
-Set a specific value of Differentiated Services Codepoint (DSCP).
-```
-
-```{cfgcmd} set firewall ipv6 prerouting raw rule \<1-999999\> set mark <1-2147483647>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> set mark <1-2147483647>
-```
-
-```{cfgcmd} set firewall ipv6 output [filter | raw] rule \<1-999999\> set mark <1-2147483647>
-
-
-Set a specific packet mark value.
-```
-
-```{cfgcmd} set firewall ipv6 prerouting raw rule \<1-999999\> set tcp-mss <500-1460>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> set tcp-mss <500-1460>
-```
-
-```{cfgcmd} set firewall ipv6 output [filter | raw] rule \<1-999999\> set tcp-mss <500-1460>
-
-
-Set the TCP-MSS (TCP maximum segment size) for the connection.
-```
-
-```{cfgcmd} set firewall ipv6 prerouting raw rule \<1-999999\> set hop-limit <0-255>
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> set hop-limit <0-255>
-```
-
-```{cfgcmd} set firewall ipv6 output [filter | raw] rule \<1-999999\> set hop-limit <0-255>
-
-
-Set hop limit value.
-```
-
-```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> set connection-mark <0-2147483647>
-```
-
-```{cfgcmd} set firewall ipv4 output [filter | raw] rule \<1-999999\> set connection-mark <0-2147483647>
-
-
-Set connection mark value.
-```
-## Synproxy
-
-
-Synproxy connections
-```{cfgcmd} set firewall ipv6 [input | forward] filter rule \<1-999999\> action synproxy
-```
-
-```{cfgcmd} set firewall ipv6 [input | forward] filter rule \<1-999999\> protocol tcp
-```
-
-```{cfgcmd} set firewall ipv6 [input | forward] filter rule \<1-999999\> synproxy tcp mss <501-65535>
-
-
- Set the TCP MSS (maximum segment size) for the connection.
-```
-
-```{cfgcmd} set firewall ipv6 [input | forward] filter rule \<1-999999\> synproxy tcp window-scale <1-14>
-
-
- Set the window scale factor for TCP window scaling.
-```
-### Example synproxy
-
-
-Requirements to enable synproxy:
-
-
-- Traffic must be symmetric
-- Synproxy relies on syncookies and TCP timestamps, ensure these are enabled
-- Disable conntrack loose track option
-```none
-
-set system sysctl parameter net.ipv4.tcp_timestamps value '1'
-
-
-set system conntrack tcp loose disable
-
-set system conntrack ignore ipv6 rule 10 destination port '8080'
-
-set system conntrack ignore ipv6 rule 10 protocol 'tcp'
-
-set system conntrack ignore ipv6 rule 10 tcp flags syn
-
-
-set firewall global-options syn-cookies 'enable'
-
-set firewall ipv6 input filter rule 10 action 'synproxy'
-
-set firewall ipv6 input filter rule 10 destination port '8080'
-
-set firewall ipv6 input filter rule 10 inbound-interface name 'eth1'
-
-set firewall ipv6 input filter rule 10 protocol 'tcp'
-
-set firewall ipv6 input filter rule 10 synproxy tcp mss '1460'
-
-set firewall ipv6 input filter rule 10 synproxy tcp window-scale '7'
-
-set firewall ipv6 input filter rule 1000 action 'drop'
-
-set firewall ipv6 input filter rule 1000 state invalid
-
-```
-## Operation-mode Firewall
-
-
-### Rule-set overview
-```{opcmd} show firewall
-
-Show a basic firewall overview for all rule-sets, not only for IPv6:
-
-
-:::{code-block} none
-vyos@vyos:~$ show firewall
-Rulesets Information
-
-
----------------------------------
-IPv4 Firewall "forward filter"
-
-
-Rule Action Protocol Packets Bytes Conditions
-------- -------- ---------- --------- ------- -----------------------------------------
-5 jump all 0 0 iifname "eth1" jump NAME_VyOS_MANAGEMENT
-10 jump all 0 0 oifname "eth1" jump NAME_WAN_IN
-15 jump all 0 0 iifname "eth3" jump NAME_WAN_IN
-default accept all
-
-
----------------------------------
-IPv4 Firewall "name VyOS_MANAGEMENT"
-
-
-Rule Action Protocol Packets Bytes Conditions
-------- -------- ---------- --------- ------- --------------------------------
-5 accept all 0 0 ct state established accept
-10 drop all 0 0 ct state invalid
-20 accept all 0 0 ip saddr @A_GOOD_GUYS accept
-30 accept all 0 0 ip saddr @N_ENTIRE_RANGE accept
-40 accept all 0 0 ip saddr @A_VyOS_SERVERS accept
-50 accept icmp 0 0 meta l4proto icmp accept
-default drop all 0 0
-
-
----------------------------------
-IPv6 Firewall "forward filter"
-
-
-Rule Action Protocol
-------- -------- ----------
-5 jump all
-10 jump all
-15 jump all
-default accept all
-
-
----------------------------------
-IPv6 Firewall "input filter"
-
-
-Rule Action Protocol
-------- -------- ----------
-5 jump all
-default accept all
-
-
----------------------------------
-IPv6 Firewall "ipv6_name IPV6-VyOS_MANAGEMENT"
-
-
-Rule Action Protocol
-------- -------- ----------
-5 accept all
-10 drop all
-20 accept all
-30 accept all
-40 accept all
-50 accept ipv6-icmp
-default drop all
-:::
-```
-
-```{opcmd} show firewall summary
-
-This will show you a summary of rule-sets and groups
-
-
-:::{code-block} none
-vyos@vyos:~$ show firewall summary
-Ruleset Summary
-
-
-IPv6 Ruleset:
-
-
-Ruleset Hook Ruleset Priority Description
--------------- -------------------- -------------------------
-forward filter
-input filter
-ipv6_name IPV6-VyOS_MANAGEMENT
-ipv6_name IPV6-WAN_IN PUBLIC_INTERNET
-
-
-IPv4 Ruleset:
-
-
-Ruleset Hook Ruleset Priority Description
--------------- ------------------ -------------------------
-forward filter
-input filter
-name VyOS_MANAGEMENT
-name WAN_IN PUBLIC_INTERNET
-
-
-Firewall Groups
-
-
-Name Type References Members
------------------------ ------------------ ----------------------- ----------------
-PBX address_group WAN_IN-100 198.51.100.77
-SERVERS address_group WAN_IN-110 192.0.2.10
-WAN_IN-111 192.0.2.11
-WAN_IN-112 192.0.2.12
-WAN_IN-120
-WAN_IN-121
-WAN_IN-122
-SUPPORT address_group VyOS_MANAGEMENT-20 192.168.1.2
-WAN_IN-20
-PHONE_VPN_SERVERS address_group WAN_IN-160 10.6.32.2
-PINGABLE_ADRESSES address_group WAN_IN-170 192.168.5.2
-WAN_IN-171
-PBX ipv6_address_group IPV6-WAN_IN-100 2001:db8::1
-SERVERS ipv6_address_group IPV6-WAN_IN-110 2001:db8::2
-IPV6-WAN_IN-111 2001:db8::3
-IPV6-WAN_IN-112 2001:db8::4
-IPV6-WAN_IN-120
-IPV6-WAN_IN-121
-IPV6-WAN_IN-122
-SUPPORT ipv6_address_group IPV6-VyOS_MANAGEMENT-20 2001:db8::5
-IPV6-WAN_IN-20
-:::
-```
-
-```{opcmd} show firewall ipv6 [forward | input | output] filter
-```
-
-```{opcmd} show firewall ipv6 ipv6-name \<name\>
-
-This command will give an overview of a single rule-set.
-
-
-:::{code-block} none
-vyos@vyos:~$ show firewall ipv6 input filter
-Ruleset Information
-
-
----------------------------------
-ipv6 Firewall "input filter"
-
-
-Rule Action Protocol Packets Bytes Conditions
-------- -------- ---------- --------- ------- ------------------------------------------------------------------------------
-10 jump all 13 1456 iifname "eth1" jump NAME6_INP-ETH1
-20 accept ipv6-icmp 10 1112 meta l4proto ipv6-icmp iifname "eth0" prefix "[ipv6-INP-filter-20-A]" accept
-default accept all 14 1584
-
-
-vyos@vyos:~$
-:::
-```
-
-```{opcmd} show firewall ipv6 [forward | input | output] filter rule <1-999999>
-```
-
-```{opcmd} show firewall ipv6 name \<name\> rule \<1-999999\>
-```
-
-```{opcmd} show firewall ipv6 ipv6-name \<name\> rule \<1-999999\>
-
-This command will give an overview of a rule in a single rule-set
-```
-
-```{opcmd} show firewall group \<name\>
-
-Show an overview of defined groups, including the type, members, and where
-the group is used.
-
-
-:::{code-block} none
-vyos@vyos:~$ show firewall group LAN
-Firewall Groups
-
-
-Name Type References Members
------------- ------------------ ----------------------- ----------------
-LAN ipv6_network_group IPV6-VyOS_MANAGEMENT-30 2001:db8::0/64
-IPV6-WAN_IN-30
-LAN network_group VyOS_MANAGEMENT-30 192.168.200.0/24
-WAN_IN-30
-:::
-```
-
-```{opcmd} show firewall statistics
-
-Show statistics of all rule-sets since the last boot.
-```
-### Show Firewall log
-```{opcmd} show log firewall
-```
-
-```{opcmd} show log firewall ipv6
-```
-
-```{opcmd} show log firewall ipv6 [forward | input | output | name]
-```
-
-```{opcmd} show log firewall ipv6 [forward | input | output] filter
-```
-
-```{opcmd} show log firewall ipv6 name \<name\>
-```
-
-```{opcmd} show log firewall ipv6 [forward | input | output] filter rule \<rule\>
-```
-
-```{opcmd} show log firewall ipv6 name \<name\> rule \<rule\>
-
-Show firewall logs for all firewalls, all IPv6 firewalls, specific hooks,
-specific priorities, specific custom chains, or specific rule-sets.
-```
-### Example Partial Config
-```none
-firewall {
- ipv6 {
- input {
- filter {
- rule 10 {
- action jump
- inbound-interface {
- name eth1
- }
- jump-target INP-ETH1
- }
- rule 20 {
- action accept
- inbound-interface {
- name eth0
- }
- log
- protocol ipv6-icmp
- }
- }
- }
- name INP-ETH1 {
- default-action drop
- default-log
- rule 10 {
- action accept
- protocol tcp_udp
- }
- }
- }
-}
-```
-### Update geoip database
-```{opcmd} update geoip
-
-Command used to update GeoIP database and firewall sets.
-``` \ No newline at end of file