How to load networks from a file to add them into the firewall group in vyos 1.4 with ntf command to replace removed ipset

There are several similar/same tasks:
https://vyos.dev/T5278
https://vyos.dev/T6040
https://vyos.dev/T4797

1 Like

Yeah, I agree with the multiple path options. And a refresh interval makes sense.

I was going to create a feature request, but I saw there’s already numerous requests already (like Viacheslav mentioned). I wasn’t sure if they stalled because they stalled, or because there’s zero interest of adding the feature.

The fact that there’s 3 feature requests shows how popular/useful this is. ⚓ T4797 External address/network lists for firewall (Local and remote) seems close to the finish line.

There’s certainly user/community interest. I was more talking about interest for the product owners.

That task you listed did seem very far along, but the last tangible update was late 2022.

1 Like

There are several nuances how file can be present
Formats:
host/network/range, splitter by newline/comma or something else

And how periodically update the groups

The request changes were never done by author of the PR T4797: Add support for external lists by TheSin- · Pull Request #1648 · vyos/vyos-1x · GitHub

Based on c-po’s comments in that PR, the feature is desired all around. Looks like it just needs to be implemented in a way that integrates with a consistent schema.

1 Like

I really need this feature. If not i can’t upgrade vyos from 1.3 to 1.4. the solution is very good for me. with shell script to
check and, run it if the list lost .

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.