Skip to content

os-bind: Allow ACLs to reference firewall aliases #9565

@arichtman

Description

@arichtman

Important notices

Before you add a new report, we ask you kindly to acknowledge the following:

Is your feature request related to a problem? Please describe.

When configuring Bind ACLs, you must enter and update network addresses/ranges manually.

Describe the solution you like

If ACLs could reference Firewall aliases, we could compose existing networks and addresses, as well as have automatic adjustments like tracked interfaces, and dynamic IPs like v6 prefixes.

Describe alternatives you considered

Using a hook script to pull my LAN IPv6 prefix out and sed it into the Bind conf file.

Additional context

Specifically, I'm looking to allowlist recursive queries from my LAN's IPv6 subnet, with it surviving a prefix change since my ISP does not guarantee a static prefix.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions