A firewall group rule represents a collection of attributes like ports, IP addresses which define match criteria and action (allow, or deny) that needs to be taken on the matched data traffic.
Network v2
Create a firewall rule for a given project
openstack firewall group rule create
Set firewall rule name.
Enable firewall rule (default).
Disable firewall rule.
Make the firewall rule public, which allows it to be used in all projects (as opposed to the default, which is to restrict its use to the current project).
Restrict use of the firewall rule to the current project.
Owner’s project (name or ID)
Domain the project belongs to (name or ID). This can be used in case collisions between project names exist.
A description of the firewall rule.
Protocol for the firewall rule (‘tcp’, ‘udp’, ‘icmp’, ‘any’). Default is ‘any’.
Action for the firewall rule (‘allow’, ‘deny’, ‘reject’). Default is ‘deny’.
Set IP version 4 or 6 (default is 4).
Source port number or range (integer in [1, 65535] or range like 123:456).
Detach source port number or range.
Destination port number or range (integer in [1, 65535] or range like 123:456).
Detach destination port number or range.
Source IP address or subnet.
Detach source IP address.
Destination IP address or subnet.
Detach destination IP address.
Enable this rule (default is enabled).
Disable this rule.
Delete a given firewall rule
openstack firewall group rule delete
<firewall-rule> [<firewall-rule> ...]
Firewall rule(s) to delete (name or ID).
List all firewall rules
openstack firewall group rule list
[--long]
List additional fields in output.
Set firewall rule properties
openstack firewall group rule set
Firewall rule to set (name or ID).
Set firewall rule name.
Enable firewall rule (default).
Disable firewall rule.
Make the firewall rule public, which allows it to be used in all projects (as opposed to the default, which is to restrict its use to the current project).
Restrict use of the firewall rule to the current project.
Owner’s project (name or ID).
Domain the project belongs to (name or ID). This can be used in case collisions between project names exist.
A description of the firewall rule.
Protocol for the firewall rule (‘tcp’, ‘udp’, ‘icmp’, ‘any’).
Action for the firewall rule (‘allow’, ‘deny’, ‘reject’).
Set IP version 4 or 6 (default is 4).
Source port number or range (integer in [1, 65535] or range like 123:456).
Detach source port number or range.
Destination port number or range (integer in [1, 65535] or range like 123:456).
Detach destination port number or range.
Source IP address or subnet.
Detach source IP address.
Destination IP address or subnet.
Detach destination IP address.
Enable this rule (default is enabled).
Disable this rule.
Show information of a given firewall rule
openstack firewall group rule show
<firewall-rule>
Firewall rule to display (name or ID).
Unset firewall rule properties
openstack firewall group rule unset
Firewall rule to unset (name or ID).
Disable firewall rule.
Restrict use of the firewall rule to the current project.
Detach source port number or range.
Detach destination port number or range.
Detach source IP address.
Detach destination IP address.
Disable this rule.