Restoring firewall rules on individual interfaces
-
Good morning,
I would like to avoid retyping the rules on certain interfaces.
It is a new 2.7.0 build, the existing hardware is live and running 2.6.0. Not all the interfaces are on the new hardware so restoring all interface rules is not an option?
I did explore manipulating the exported XML file to see if I could extract just the interface with the rules I want to import - is this the right approach or would a restore all be the only way?
-
You can't restore only firewall rules from some interfaces like that.
If you restore the config and reassign the interfaces you will get the rules from the interfaces you assign but only consecutive interfaces. So if the interfaces you are removing are between the remaining interfaces the ruleset will not be what you expect.You can do this manually editing the config to remove the interfaces you don't want and changing the NIC assignments of those you do to match the new hardware.
Anytime you edit the config though the scope for making a typo is there!Steve
-
J jimp moved this topic from Problems Installing or Upgrading pfSense Software on
-
Thanks Steve - to eliminate typos I have recreated all the interfaces and will delete them post restore of rules.
-
Just to clear you should restore the complete modified config. The rules section will reference a different set of interfaces so will not line up otherwise.