Feedback on Firewall — Configuring firewall rules
Selecting Invert Match will text, there should be a warning block suggesting the avoidance of negating macros. See #6799 for more details.
Updated by Marcos Mendoza 5 months ago
Invert Matchon macros such as
LAN netcan lead to undesired rule behavior when the interface also uses Virtual IPs. This is due to traffic matching against the interface network OR the VIPs. For example, given the rule
pass on $LAN from any to ! $LAN_net, traffic destined to
192.168.0.0/24, and a VIP of
10.0.0.1/32, such traffic will still match the negate rule since the destination IP does not match the VIP.
- % Done changed from 0 to 50