Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Nested alias for hosts vs networks

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lightningbit
      last edited by

      Hi,

      Question about nesting alias objects.
      according the manual, we can have nested aliases, as long as we stay within the same type.
      With, type, Pfsense probably mean IP, PORT, URL, ....
      can we mix nested aliases of the type "host" and "network" as elements of an alias ?
      if so, should that "parent" alias then be the host or network type?

      Thanks

      L 1 Reply Last reply Reply Quote 0
      • L
        lightningbit @lightningbit
        last edited by

        anyone?

        KOMK 1 Reply Last reply Reply Quote 0
        • KOMK
          KOM @lightningbit
          last edited by

          @lightningbit I don't believe that you can mix types like that. I think of it in the context of how the alias will be used. In every field I can think of that uses aliases, they are always for one specific type of data. Having an alias that holds a port and network, or host and network, would mean including invalid data.

          What are you trying to do?

          L 1 Reply Last reply Reply Quote 0
          • L
            lightningbit @KOM
            last edited by

            @kom ok thanks for the info.
            I was hoping to be able to treat aliases or "objects" similar to how commercial firewalls do
            I'm used to work with Checkpoint, Fortinet, ....
            They can mix objects for hosts and networks.

            But I think I found the solution by simulating host objects by creating network objects with ip/32 (obvious of course... that I didn't think of that before

            JeGrJ 1 Reply Last reply Reply Quote 0
            • JeGrJ
              JeGr LAYER 8 Moderator @lightningbit
              last edited by

              @lightningbit Nesting can only happen in type "Host" Aliases. But the Aliases you put in there can be of another Type (Network for example). Single IPs can be Network type aliases, too - just use /32 as netmask or /128 for IP6.

              Don't forget to upvote ๐Ÿ‘ those who kindly offered their time and brainpower to help you!

              If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

              L 1 Reply Last reply Reply Quote 2
              • L
                lightningbit @JeGr
                last edited by

                @jegr so if I understand you correctly, I could create an alias of type HOST, and inside add aliases of type host and network

                JeGrJ 1 Reply Last reply Reply Quote 0
                • JeGrJ
                  JeGr LAYER 8 Moderator @lightningbit
                  last edited by

                  @lightningbit Indeed :)

                  Don't forget to upvote ๐Ÿ‘ those who kindly offered their time and brainpower to help you!

                  If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.