a bit easier to understand
This, I started with zones on juniper and when i started using vyos that came much easier than interface rulesets. In fact, i still haven’t wrapped my mind around just how those work.
a helper function in vyos to insert the stubs would be appreciated.
+1 to this. this is my biggest gripe with doing the initial setup on zones, there is so much additional config. Once set up though i do think it’s easier to manage.
Another thing, if you’re using this for a homelab and start messing around with interfaces and wireing it’s much easier to just slap the correct interface to the correct zone and let the zone’s firewall settings take care of the rest than going around to each interface and making sure the correct firewall names are asigned to the correct directions on each interface.