Firewall Rule: Choose Interface Group
-
I created an interface group called "RiskyBusiness" which contains 3 network interfaces.
- IoT
- Guest Wi-Fi
- Public LAN
I would like to choose this interface group as a "Source" or "Destination" when creating a Firewall Rule. Is this currently possible? If not, does this sound like a good feature request? Or could it possibly cause more harm/problems that helpful solutions?
-
They are generally used for applying the same rules to multiple interfaces in one place.
Just make sure you understand the rule processing order.
https://docs.netgate.com/pfsense/en/latest/book/interfaces/interfacetypes-groups.html#group-rule-processing-order
-
@NogBadTheBad Thank you for sending this documentation my way!
As it turns out, what I (originally) wanted to do can be accomplished using an "Alias".
https://docs.netgate.com/pfsense/en/latest/firewall/aliases.html?highlight=aliasYou were right. Interface Groups serve an entirely different purpose.