<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Aliases and Groups]]></title><description><![CDATA[<p dir="auto">Hello,<br />
We are searching for a firewall to replace an old VPN-1 of CheckPoint, so I'm testing some software solutions.<br />
I really appreciate the pfSense, it is a great product. Unfortunately, there are some negative points I saw. I would like to know if there are any plans to change them.</p>
<p dir="auto">The most important thing pfSense cannot do is grouping the objects. For example, I would like to create some aliases and add them to a group usable in the firewall rules. So I would like to know if this functionality is supposed to be added in the future versions or can be added as a patch by modifying Web GUI files (maybe the problem is deeper than GUI, I don't know).</p>
<p dir="auto">Another question - why there is no list of aliases when I add a firewall rule? I can use an alias but I should enter it manually. The same question - could it be changed?</p>
<p dir="auto">And the third question, the most interesting - can I disable the firewall management by Web GUI and use another tool to manage it (I think about fwbuilder). Sure, I would like to use Web GUI to manage all another parameters (VPN, CARP etc.)</p>
<p dir="auto">Best regards,<br />
Peter</p>
]]></description><link>https://forum.netgate.com/topic/38126/aliases-and-groups</link><generator>RSS for Node</generator><lastBuildDate>Sun, 19 Jul 2026 00:32:56 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/38126.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 11 Oct 2011 14:39:56 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Aliases and Groups on Wed, 05 Dec 2012 12:56:36 GMT]]></title><description><![CDATA[<p dir="auto">This is a very old topic…</p>
<p dir="auto">Since 2.0 it's possible to use aliases inside aliases (groups of groups).</p>
]]></description><link>https://forum.netgate.com/post/367260</link><guid isPermaLink="true">https://forum.netgate.com/post/367260</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Wed, 05 Dec 2012 12:56:36 GMT</pubDate></item><item><title><![CDATA[Reply to Aliases and Groups on Wed, 05 Dec 2012 10:57:20 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peter2121">@<bdi>Peter2121</bdi></a>:</p>
<blockquote>
<blockquote>
<p dir="auto">Alias is a group of ips/ports/nets, do you need group of groups?<br />
why?</p>
</blockquote>
<p dir="auto">Yes, I need to group some groups. Our rulebase is complex, the logic is the same as in MS Active Directory - we group the stations and networks due to the location and logical functions and then we put these groups in another groups, used in rules. So we have some logical groups used in different rules together with other logical groups.<br />
For example, there are logical groups <em>Account</em>, <em>Comm</em>, <em>R_and_D</em>. And we have the rules <em>Grp_Web to Any service HTTP</em> and <em>Grp_Mail_In to Any service IMAP</em>. We put <em>R_and_D</em> and <em>Comm</em> in <em>Grp_Web</em>, we put <em>Account</em> and <em>R_and_D</em> in <em>Grp_Mail_In</em>. When I need to give some rights to a new station - I just add this station to the group <em>Account</em> for example, I should not think about rules.</p>
</blockquote>
<p dir="auto">+1. Grouping aliases would be a productivity and administrative boost.</p>
]]></description><link>https://forum.netgate.com/post/367221</link><guid isPermaLink="true">https://forum.netgate.com/post/367221</guid><dc:creator><![CDATA[mmerlone]]></dc:creator><pubDate>Wed, 05 Dec 2012 10:57:20 GMT</pubDate></item><item><title><![CDATA[Reply to Aliases and Groups on Wed, 12 Oct 2011 09:08:15 GMT]]></title><description><![CDATA[<p dir="auto">…as about <em>fwbuilder</em> - the software knows to manage OpenBSD <em>pf</em> using OS scripts. It seems that <em>pfSense</em> uses <em>pf</em> as the firewall backend, so it should work. The problem - possible conflicts between the configuration imported from <em>fwbuilber</em> and WebGUI de <em>pfsense</em>. I still need WebGUI to manage the rest of <em>pfsense</em>.</p>
]]></description><link>https://forum.netgate.com/post/299772</link><guid isPermaLink="true">https://forum.netgate.com/post/299772</guid><dc:creator><![CDATA[Peter2121]]></dc:creator><pubDate>Wed, 12 Oct 2011 09:08:15 GMT</pubDate></item><item><title><![CDATA[Reply to Aliases and Groups on Tue, 11 Oct 2011 21:00:26 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for your answer, marcelloc.</p>
<blockquote>
<p dir="auto">Alias is a group of ips/ports/nets, do you need group of groups?<br />
why?</p>
</blockquote>
<p dir="auto">Yes, I need to group some groups. Our rulebase is complex, the logic is the same as in MS Active Directory - we group the stations and networks due to the location and logical functions and then we put these groups in another groups, used in rules. So we have some logical groups used in different rules together with other logical groups.<br />
For example, there are logical groups <em>Account</em>, <em>Comm</em>, <em>R_and_D</em>. And we have the rules <em>Grp_Web to Any service HTTP</em> and <em>Grp_Mail_In to Any service IMAP</em>. We put <em>R_and_D</em> and <em>Comm</em> in <em>Grp_Web</em>, we put <em>Account</em> and <em>R_and_D</em> in <em>Grp_Mail_In</em>. When I need to give some rights to a new station - I just add this station to the group <em>Account</em> for example, I should not think about rules.</p>
<blockquote>
<p dir="auto">when you start to type the alias you will see a list of aliases that matches your type.</p>
</blockquote>
<p dir="auto">Yes, I saw the names appeared when I begin to type. It's better then nothing but I would prefer a listbox or drop-down box.</p>
<blockquote>
<p dir="auto">until 2.0 most features are in gui.</p>
</blockquote>
<p dir="auto">Sorry, I don't understand you.</p>
]]></description><link>https://forum.netgate.com/post/299695</link><guid isPermaLink="true">https://forum.netgate.com/post/299695</guid><dc:creator><![CDATA[Peter2121]]></dc:creator><pubDate>Tue, 11 Oct 2011 21:00:26 GMT</pubDate></item><item><title><![CDATA[Reply to Aliases and Groups on Tue, 11 Oct 2011 18:48:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peter2121">@<bdi>Peter2121</bdi></a>:</p>
<blockquote>
<p dir="auto">The most important thing pfSense cannot do is grouping the objects. For example, I would like to create some aliases and add them to a group usable in the firewall rules. So I would like to know if this functionality is supposed to be added in the future versions or can be added as a patch by modifying Web GUI files (maybe the problem is deeper than GUI, I don't know).</p>
</blockquote>
<p dir="auto">Alias is a group of ips/ports/nets, do you need group of groups?<br />
why?</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peter2121">@<bdi>Peter2121</bdi></a>:</p>
<blockquote>
<p dir="auto">Another question - why there is no list of aliases when I add a firewall rule? I can use an alias but I should enter it manually. The same question - could it be changed?</p>
</blockquote>
<p dir="auto">when you start to type the alias you will see a list of aliases that matches your type.<br />
Use only firefox or chrome to access gui.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peter2121">@<bdi>Peter2121</bdi></a>:</p>
<blockquote>
<p dir="auto">And the third question, the most interesting - can I disable the firewall management by Web GUI and use another tool to manage it (I think about fwbuilder). Sure, I would like to use Web GUI to manage all another parameters (VPN, CARP etc.)</p>
</blockquote>
<p dir="auto">until 2.0 most features are in gui.</p>
]]></description><link>https://forum.netgate.com/post/299679</link><guid isPermaLink="true">https://forum.netgate.com/post/299679</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Tue, 11 Oct 2011 18:48:25 GMT</pubDate></item></channel></rss>