Since firewall rules are matched from top to bottom, how can I re-order them?
I have this questoin because I want to make a policy based routing (the host 172.16.1.73 should use a different gateway), but according to the log, the matched rule is the default one (probably because it is listed first). That is why I want to pull the last rule to the top. Screenshots attached.
Edit: I just found out how to do it,
apparenty you select the rule that you want to move, then find the other rule that should be below the selected one, and press the button in the right which looks like a back arrow.
If you hover with your mouse pointer over the small left pointing arrows at the right of each line, it will probably become evident.
In case it doesn't:
1. check the small check box at the left for the rule you want to move to the top.
2. click the left pointing arrow at the right for the first rule.
HTH,
Patrick
i agree, they have a really weird/confusing re-ordering system.
I don't think it's confusing at all. Just tried to help the OP.
QuoteI don't think it's confusing at all.
I agree ... You just have to get used to it. So pointing the OP to the right direction it the way to help.
I just realized this is really missing in the docs ...
And regarding the confusing reordering: I think it is still better then those just allowing to push lines only step by step up and down one position ...
To give a broad hint here: if you miss something from the documentation fell free to complete it and create a pull request. Those who use the opnsense firewall regularly will find things obviously and will newer miss it from the documentation. Those who just start using it now are the people who should are not yet blind by habit and fill realize some things are missing ... everyone can help ...
https://github.com/opnsense/docs/pull/402
Although it is not a real major issue. It is not as intuitive as it could be. Every other application i know just has "handles" to drag/drop rows to the right place. That said, i think this should not a high priority issue to improve.
QuoteIt is not as intuitive as it could be
... at least the docs are updated.
This is not intuitive, what was wrong with the anchor from the open source version? Anyways thanks.
What do you mean by "from the open source version"? I am referring to the open source version.
Maybe he meant pfSense? ;)
Cheers,
Franco