How do predefined net aliases work?

Started by silmarine, Today at 09:32:37 AM

Previous topic - Next topic
Quote from: Monviech (Cedrik) on Today at 11:00:32 AMThere are no magic other attributes to a "Floating" rules than just the processing order.

Nice to see this explicitly stated :)

I came to the realization after studying /tmp/rules.debug, but in the past had spent a lot of time wading through misinformation in online searches and A.I. chatbots.  There are still claims out there that floating rules have special properties.
N5105 | 8/250GB | 4xi226-V | Community

Today at 05:53:22 PM #16 Last Edit: Today at 05:59:43 PM by Bob.Dig
Quote from: OPNenthu on Today at 04:13:14 PMthat floating rules have special properties.
They have, in pfSense. And you can select different interfaces, which is special too, for both. 

Btw. I don't understand, why the choice for creating a floating rule for one interface only has been taken away from users. Is there an actual, good reason? What does it solve to not allowing it. 

Today at 06:43:10 PM #17 Last Edit: Today at 06:46:40 PM by Monviech (Cedrik)
It solves that it slowly paths the way to a unified ruleset without special hardcoded prorities in which you can move rules at any spot you want.

At least thats my wish for the long run:
https://github.com/opnsense/core/issues/9652#issuecomment-4274523794

Demystifying floating plays well into that strategy.
Hardware:
DEC740

Today at 07:21:39 PM #18 Last Edit: Today at 07:24:47 PM by Bob.Dig
Thanks for pointing to that discussion. My English ain't that good, so I have the feeling, that I still might miss something. Let's say I have two WANs, for both I block RFC1918 outgoing, so I used one floating rule. But for one WAN, I have an allow rule for WAN_network before that. Now I am forced to do things differently.

Quotein which you can move rules at any spot you want
That sounds like more freedom but yet we will get less. :)
I kinda think that you could achieve that goal in the same time without that floating-decision, I can't see that benefit, yet. ;) And some people hate any friction.

Sorry it feels like we are hijacking this thread now. If this needs to be discussed further best create a new thread.
Hardware:
DEC740