OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Rule Separators
« previous next »
  • Print
Pages: [1] 2 3 ... 6

Author Topic: Rule Separators  (Read 25343 times)

GreG.P.

  • Newbie
  • *
  • Posts: 16
  • Karma: 0
  • The Best of Free or nothing!
    • View Profile
Rule Separators
« on: April 18, 2016, 04:23:49 pm »
Hi, there is some indispensable options in firewall rules and NAT rules interface: Separators and object drag and drop.
Something Like this https://redmine.pfsense.org/issues/5373 but with regroup rules below each inserted separators.

One more essential option is regarding the objects (alias) database, an quick dynamic menu access to the objects (alias) in the same rules page configuration will be really appreciated and the drag&drop function to copy and paste an object (alias) from one rule to another rule.

Thanks.
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17706
  • Karma: 1618
    • View Profile
Re: Rule Separators
« Reply #1 on: April 18, 2016, 04:32:22 pm »
Hi PsykoGreG,

Are you looking for this? https://docs.opnsense.org/manual/how-tos/fwcategory.html

What do you mean by quick dynamic menu access in the same rules page?


Cheers,
Franco
Logged

GreG.P.

  • Newbie
  • *
  • Posts: 16
  • Karma: 0
  • The Best of Free or nothing!
    • View Profile
Re: Rule Separators
« Reply #2 on: April 18, 2016, 05:18:56 pm »
Hi Franco,

I see this category to filter rules, there are indexed on the description field or rule name?

I do a screen shot to exactly show you all interesting options.

Regards,
GreG
« Last Edit: April 18, 2016, 06:15:00 pm by PsykoGreG »
Logged

GreG.P.

  • Newbie
  • *
  • Posts: 16
  • Karma: 0
  • The Best of Free or nothing!
    • View Profile
Re: Rule Separators
« Reply #3 on: April 18, 2016, 06:07:48 pm »
Red : The dynamic Objects (alias) menu with the first field that's permit to sort the list of objects dynamically by typing first characters of objects (alias).
Second red circle permit to filter the category of objects (alias) to view only these in the objects menu in the left. For example: machines, network, protocols, ports, groups, .. objects.
And the last red circle permit to create directly an object (alias) or a group of objects from this menu without exit the filter rules page.
Dark Blue : Search field that permit to filter dynamically the rules view (I think like the OPNsense "Filter by category" option)
Pink circles : There are drag and drop fields object. Can be drag&drop between rules or from the objects menu in the left side.
Green : This is Separator rule (with custom colours) that permit to regroup all rules until the next separator and indicate the number of contained rules in the separator.
Logged

m2nis

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: Rule Separators
« Reply #4 on: November 30, 2018, 08:41:18 am »
Hello,

Sorry to reopen this topic, but I must admit that, when you come from Pfs, these separators are really missing in the firewall rules. They are simple but really great to explain the rules and separate them. Any chance to have it one day ?

Have a good day.
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17706
  • Karma: 1618
    • View Profile
Re: Rule Separators
« Reply #5 on: December 03, 2018, 09:36:00 am »
There are no plans to add any non-functional abstractions to the rule listing.


Cheers,
Franco
Logged

m2nis

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: Rule Separators
« Reply #6 on: December 03, 2018, 09:50:50 am »
Sad but... perfectly clear.  :)

Thank's for your reply.
Logged

RGijsen

  • Newbie
  • *
  • Posts: 24
  • Karma: 4
    • View Profile
Re: Rule Separators
« Reply #7 on: February 13, 2019, 04:22:45 pm »
+1 for me though too. 'We won't' is a bit of a sad answer honestly. We are currently migrating to OPNsense (and the reason is pure ideological), and really the rule-list look like a long mess in OPNsense. The ability to put some descriptive lines in there like 'Exchange', 'RD Servers' and such is a real addition. They are certainly not non-functional. Network wise they may be, but it's certainly functional to us.

Everyone has their own believes, but we think it's really useful. For example we used red seperators when we had rules we had to review later on.
« Last Edit: February 13, 2019, 04:28:15 pm by RGijsen »
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Rule Separators
« Reply #8 on: February 13, 2019, 04:55:07 pm »
+1...
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

Sopor

  • Newbie
  • *
  • Posts: 6
  • Karma: 0
    • View Profile
Re: Rule Separators
« Reply #9 on: November 10, 2019, 03:32:03 am »
I'm also an old pfsense user and that separator was really really nice. When you have many entries it will be so much easier if it is possible to separate them. I really hope the devs reconsidering this and add a separator or at least something similar.
Logged

ole

  • Jr. Member
  • **
  • Posts: 72
  • Karma: 1
    • View Profile
Re: Rule Separators
« Reply #10 on: May 23, 2020, 03:50:57 pm »
Quote from: Sopor on November 10, 2019, 03:32:03 am
I'm also an old pfsense user and that separator was really really nice. When you have many entries it will be so much easier if it is possible to separate them. I really hope the devs reconsidering this and add a separator or at least something similar.

+1
Logged

ninjax

  • Newbie
  • *
  • Posts: 4
  • Karma: 0
    • View Profile
Re: Rule Separators
« Reply #11 on: September 13, 2020, 05:38:08 pm »
+2
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Rule Separators
« Reply #12 on: September 13, 2020, 07:41:30 pm »
...I would chip in 50.- Euros for this feature. Anyone? 
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

Gcon

  • Newbie
  • *
  • Posts: 15
  • Karma: 2
    • View Profile
Re: Rule Separators
« Reply #13 on: February 26, 2021, 01:30:00 pm »
Quote from: franco on December 03, 2018, 09:36:00 am
There are no plans to add any non-functional abstractions to the rule listing.


Cheers,
Franco

Anything that improves the readabiity and maintainability of firewall rules is not in fact "non-functional". Rule seperators and/or groupings serve a very important function, at least from a human perspective (and the web GUI is, by its very nature created for humans to use). In my 25+ years in networking I've worked on Checkpoint, Fortinet, Netscreen and Juniper firewalls for national Internet Service Providers and guess what?! - they all have rule seperation/grouping. It's far from being a pfSense thing - it's an industry-wide thing.

pFsense's approach is OK - better than nothing - but even that could do with some improvement. Individual filter rules should be programatically linked to the categories they fall within, and ideally have the ability to toggle collapsing of groups, reorder groups (drag and drop) and toggle group rules on and off. Basically, they act as "first-class citizens" in the whole scheme of things. This is one thing that seperates the commercial enterprise firewall offerings from more hobbyist/enthusiast ones.

As a bare minimum though, there should be text seperators to visually indicate logical groupings of rules. This lack of functionality is one of the main reasons why I conitnue to favour pfSense over OPNsense.

This issue makes me think of the late 90's novel by Allan Cooper entitled, "The Inmates Are Running the Asylum", which details how programmers ruin interface design by thinking that they know what's best for the end-user (and to no-one's surprise, they don't)

+1 :)
« Last Edit: February 26, 2021, 01:31:46 pm by Gcon »
Logged

bdl

  • Newbie
  • *
  • Posts: 1
  • Karma: 0
    • View Profile
Re: Rule Separators
« Reply #14 on: September 01, 2021, 02:26:04 pm »
+1  :)
Logged

  • Print
Pages: [1] 2 3 ... 6
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Rule Separators
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2