Rules under version 27

Started by headbanger, Today at 12:24:47 AM

Previous topic - Next topic
I know when version 26 rolled out Rules[New] was added.  I never migrated and kept using the legacy rules.  Now I am on version 27 and I am unable to edit any rules.  Rules [New] and Rules legacy are gone and there is only Rules.  Do I now have to do a migration?  I see migration assistant.  It talks about exporting the rules, editing the rules and then importing them.  Don't know how to edit them in XML.  I already did an export of te entre configuration.  Am I safe ub assuming that is I mess this up I can import the configuration and get back to where I am?  Any help would be appreciated.

As per the release notes:

Quotefirewall: legacy rules pages move to plugin

Look for:

os-firewall-legacy

I tried this too. Unfortunately, the legacy rules will be imported showing up like automatic rules, i.e. they work but can't edited or removed. The legacy rules plugin doesn't help. While it shows the legacy rules in the usual way, it doesn't do anything to the broken import. I wrote about it here. It would be great to have the newer version of OPNsense to not import legacy rules.

You just follow the migration assistant step by step, that's all you have to do.

The legacy rules are not imported automatically to the new rules, what you see is just a preview of them while they are still in the config.xml path of the old rules.

That's so you can compare old to new rules after import, and before deleting them with the last step of the migration assistant.

Hope that makes it clearer.
Hardware:
DEC740

Quote from: Monviech (Cedrik) on Today at 01:11:07 PMHope that makes it clearer.

The confusion comes from the fact that the migration of rules must be completed before upgrading to OPNsense 26.7 or newer. If instead one takes a backup from 26.4 or earlier and just restores it, all the legacy rules show up as new rules. But they can not be selected, edited or deleted via the UI. The instance is borked. If you can't go back to a snapshot, the instance has to be installed from scratch. That's why 26.7 or later should not import the filter section of a legacy style config.xml.

Quote from: mooh on Today at 01:36:40 PMcomes from the fact that the migration of rules must be completed before upgrading to OPNsense 26.7 or newer.
You're sure? All the buttons (two) are also there in the "new" rules. To me, it looks like you can migrate any time, have not tested that though, because I already migrated them before.

Today at 02:51:46 PM #6 Last Edit: Today at 02:53:19 PM by mooh
Quote from: Bob.Dig on Today at 01:51:47 PMYou're sure?
Yes. Tried it with and without the legacy rules plugin.

And let me try to make this clear once again: This is not about migrating the rules from legacy to new. This is about restoring a complete configuration.xml from a <= 26.4 backup to a 26.7 instance. The legacy rules will be imported as new rules and that import is broken. It is however completely fine to import into 26.7 the rules that have been exported from 26.4.

The legacy rules are not imported as new rules.

The new rules just displays the legacy rules via this command:

configctl filter list non_mvc_rules
Each legacy rule will have a link button, and if you press it you either open the exact rule when the legacy firewall plugin is installed, or it opens the migration assistant if the legacy firewall plugin is missing.
Hardware:
DEC740

When it tried it, the legacy rules were visible in the new rules UI and they worked, at least as far as I could test it in a small test setup. I realised only after a while that I couldn't modify them.

Today at 05:03:57 PM #9 Last Edit: Today at 05:05:39 PM by Monviech (Cedrik)
Yes the legacy rules are visible and they work.

Thats the reason they are visible in the new Rules GUI.

They cannot be edited, but they have a command that redirects you to the migration assistant.

Even if you dont have the legacy firewall rules, you can always migrate.

Nothing is broken.

What I cannot deny though is that it might be confusing for some users. But it cannot be easily fixed. Visibility of all rules is more important, and an automatic migration too sensitive cause some rules might not be valid anymore (The migration assistant and the import validate this and warn)
Hardware:
DEC740