Files
PSOPNSenseAPI/docs/Firewall-Rules.md
T

269 lines
9.2 KiB
Markdown

# Firewall Rules Management
This component provides cmdlets for managing firewall rules on OPNSense firewalls.
## Overview
The Firewall Rules Management component allows you to create, view, modify, and delete firewall rules on OPNSense firewalls. It provides a comprehensive set of cmdlets to manage all aspects of firewall rules, including enabling, disabling, and applying changes.
## Cmdlets
### Get-OPNSenseFirewallRule
Retrieves firewall rules from an OPNSense firewall.
#### Parameters
- **Uuid** - The UUID of a specific firewall rule to retrieve. If not specified, all rules are returned.
- **Interface** - Filter rules by interface.
- **Direction** - Filter rules by direction (in, out).
- **Protocol** - Filter rules by protocol.
- **Action** - Filter rules by action (pass, block, reject).
#### Examples
```powershell
# Get all firewall rules
Get-OPNSenseFirewallRule
# Get a specific firewall rule by UUID
Get-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6"
# Get all rules for a specific interface
Get-OPNSenseFirewallRule -Interface "lan"
# Get all block rules
Get-OPNSenseFirewallRule -Action "block"
```
### New-OPNSenseFirewallRule
Creates a new firewall rule on an OPNSense firewall.
#### Parameters
- **Enabled** - Whether the rule is enabled. Default is true.
- **Action** - The action to take (pass, block, reject). Default is "pass".
- **Interface** - The interface for the rule.
- **Direction** - The direction for the rule (in, out). Default is "in".
- **Protocol** - The protocol for the rule (tcp, udp, icmp, etc.).
- **Source** - The source address for the rule. Default is "any".
- **SourcePort** - The source port for the rule. Default is "any".
- **Destination** - The destination address for the rule. Default is "any".
- **DestinationPort** - The destination port for the rule.
- **Description** - A description for the rule.
- **Log** - Whether to log matches for this rule. Default is false.
- **Force** - Suppresses the confirmation prompt.
#### Examples
```powershell
# Create a rule to allow HTTP traffic
New-OPNSenseFirewallRule -Interface "lan" -Protocol "tcp" -Destination "any" -DestinationPort "80" -Description "Allow HTTP"
# Create a rule to block outgoing SMTP traffic
New-OPNSenseFirewallRule -Interface "lan" -Direction "out" -Protocol "tcp" -DestinationPort "25" -Action "block" -Description "Block outgoing SMTP" -Log
# Create a rule to allow traffic from a specific subnet to a specific server
New-OPNSenseFirewallRule -Interface "lan" -Protocol "tcp" -Source "192.168.1.0/24" -Destination "192.168.2.10" -DestinationPort "443" -Description "Allow subnet to server"
```
### Set-OPNSenseFirewallRule
Updates an existing firewall rule on an OPNSense firewall.
#### Parameters
- **Uuid** - The UUID of the firewall rule to update.
- **Enabled** - Whether the rule is enabled.
- **Action** - The action to take (pass, block, reject).
- **Interface** - The interface for the rule.
- **Direction** - The direction for the rule (in, out).
- **Protocol** - The protocol for the rule.
- **Source** - The source address for the rule.
- **SourcePort** - The source port for the rule.
- **Destination** - The destination address for the rule.
- **DestinationPort** - The destination port for the rule.
- **Description** - A description for the rule.
- **Log** - Whether to log matches for this rule.
- **Force** - Suppresses the confirmation prompt.
- **PassThru** - Returns the updated rule.
#### Examples
```powershell
# Update a firewall rule's description
Set-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6" -Description "Updated HTTP rule"
# Update a firewall rule's destination port
Set-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6" -DestinationPort "8080"
# Update multiple properties of a firewall rule
Set-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6" -Action "block" -Log -Description "Block traffic" -PassThru
```
### Remove-OPNSenseFirewallRule
Removes a firewall rule from an OPNSense firewall.
#### Parameters
- **Uuid** - The UUID of the firewall rule to remove.
- **Force** - Suppresses the confirmation prompt.
#### Examples
```powershell
# Remove a firewall rule
Remove-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6"
# Remove a firewall rule without confirmation
Remove-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6" -Force
```
### Enable-OPNSenseFirewallRule
Enables a firewall rule on an OPNSense firewall.
#### Parameters
- **Uuid** - The UUID of the firewall rule to enable.
- **Force** - Suppresses the confirmation prompt.
- **PassThru** - Returns the updated rule.
#### Examples
```powershell
# Enable a firewall rule
Enable-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6"
# Enable a firewall rule and return the updated rule
Enable-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6" -PassThru
```
### Disable-OPNSenseFirewallRule
Disables a firewall rule on an OPNSense firewall.
#### Parameters
- **Uuid** - The UUID of the firewall rule to disable.
- **Force** - Suppresses the confirmation prompt.
- **PassThru** - Returns the updated rule.
#### Examples
```powershell
# Disable a firewall rule
Disable-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6"
# Disable a firewall rule and return the updated rule
Disable-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6" -PassThru
```
### Apply-OPNSenseFirewallChanges
Applies pending firewall changes on an OPNSense firewall.
#### Parameters
- **Force** - Suppresses the confirmation prompt.
#### Examples
```powershell
# Apply firewall changes
Apply-OPNSenseFirewallChanges
# Apply firewall changes without confirmation
Apply-OPNSenseFirewallChanges -Force
```
## Common Scenarios
### Basic Firewall Configuration
```powershell
# Connect to the OPNSense firewall
Connect-OPNSense -Server "https://firewall.example.com" -ApiKey "your_api_key" -ApiSecret "your_api_secret" -SkipCertificateCheck
# Create rules for basic web access
New-OPNSenseFirewallRule -Interface "lan" -Protocol "tcp" -DestinationPort "80" -Description "Allow HTTP" -Force
New-OPNSenseFirewallRule -Interface "lan" -Protocol "tcp" -DestinationPort "443" -Description "Allow HTTPS" -Force
# Create a rule to allow DNS
New-OPNSenseFirewallRule -Interface "lan" -Protocol "udp" -DestinationPort "53" -Description "Allow DNS" -Force
# Apply the changes
Apply-OPNSenseFirewallChanges -Force
# Disconnect from the firewall
Disconnect-OPNSense
```
### Securing a Network
```powershell
# Connect to the OPNSense firewall
Connect-OPNSense -Server "https://firewall.example.com" -ApiKey "your_api_key" -ApiSecret "your_api_secret" -SkipCertificateCheck
# Block outgoing SMTP to prevent spam
New-OPNSenseFirewallRule -Interface "lan" -Direction "out" -Protocol "tcp" -DestinationPort "25" -Action "block" -Description "Block outgoing SMTP" -Log -Force
# Allow only specific hosts to access the management interface
New-OPNSenseFirewallRule -Interface "lan" -Protocol "tcp" -Source "192.168.1.10,192.168.1.11" -Destination "192.168.1.1" -DestinationPort "443" -Description "Allow management access" -Force
# Block all other access to the management interface
New-OPNSenseFirewallRule -Interface "lan" -Protocol "tcp" -Destination "192.168.1.1" -DestinationPort "443" -Action "block" -Description "Block management access" -Log -Force
# Apply the changes
Apply-OPNSenseFirewallChanges -Force
# Disconnect from the firewall
Disconnect-OPNSense
```
### Managing Existing Rules
```powershell
# Connect to the OPNSense firewall
Connect-OPNSense -Server "https://firewall.example.com" -ApiKey "your_api_key" -ApiSecret "your_api_secret" -SkipCertificateCheck
# Get all firewall rules
$rules = Get-OPNSenseFirewallRule
# Disable all rules with "Temporary" in the description
$rules | Where-Object { $_.Description -like "*Temporary*" } | ForEach-Object {
Disable-OPNSenseFirewallRule -Uuid $_.Uuid -Force
Write-Output "Disabled rule: $($_.Description)"
}
# Update all rules with "HTTP" in the description to use port 8080 instead of 80
$rules | Where-Object { $_.Description -like "*HTTP*" -and $_.DestinationPort -eq "80" } | ForEach-Object {
Set-OPNSenseFirewallRule -Uuid $_.Uuid -DestinationPort "8080" -Description "$($_.Description) (Updated Port)" -Force
Write-Output "Updated rule: $($_.Description)"
}
# Remove all rules with "Obsolete" in the description
$rules | Where-Object { $_.Description -like "*Obsolete*" } | ForEach-Object {
Remove-OPNSenseFirewallRule -Uuid $_.Uuid -Force
Write-Output "Removed rule: $($_.Description)"
}
# Apply the changes
Apply-OPNSenseFirewallChanges -Force
# Disconnect from the firewall
Disconnect-OPNSense
```
## Notes
- Firewall rules are processed in order, with the first matching rule being applied.
- Changes to firewall rules are not applied until you call `Apply-OPNSenseFirewallChanges`.
- When creating or updating rules, consider the rule order and potential security implications.
- Use the `-Log` parameter for rules that you want to monitor for security purposes.
- Use aliases for frequently used IP addresses or networks to make rules more maintainable.
- Consider using the `-PassThru` parameter when updating rules to verify the changes.
- Always apply the principle of least privilege when creating firewall rules.