mirror of
https://github.com/freedbygrace/PSOPNSenseAPI.git
synced 2026-07-26 20:08:30 +00:00
9.2 KiB
9.2 KiB
Firewall Rules Management
This component provides cmdlets for managing firewall rules on OPNSense firewalls.
Overview
The Firewall Rules Management component allows you to create, view, modify, and delete firewall rules on OPNSense firewalls. It provides a comprehensive set of cmdlets to manage all aspects of firewall rules, including enabling, disabling, and applying changes.
Cmdlets
Get-OPNSenseFirewallRule
Retrieves firewall rules from an OPNSense firewall.
Parameters
- Uuid - The UUID of a specific firewall rule to retrieve. If not specified, all rules are returned.
- Interface - Filter rules by interface.
- Direction - Filter rules by direction (in, out).
- Protocol - Filter rules by protocol.
- Action - Filter rules by action (pass, block, reject).
Examples
# Get all firewall rules
Get-OPNSenseFirewallRule
# Get a specific firewall rule by UUID
Get-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6"
# Get all rules for a specific interface
Get-OPNSenseFirewallRule -Interface "lan"
# Get all block rules
Get-OPNSenseFirewallRule -Action "block"
New-OPNSenseFirewallRule
Creates a new firewall rule on an OPNSense firewall.
Parameters
- Enabled - Whether the rule is enabled. Default is true.
- Action - The action to take (pass, block, reject). Default is "pass".
- Interface - The interface for the rule.
- Direction - The direction for the rule (in, out). Default is "in".
- Protocol - The protocol for the rule (tcp, udp, icmp, etc.).
- Source - The source address for the rule. Default is "any".
- SourcePort - The source port for the rule. Default is "any".
- Destination - The destination address for the rule. Default is "any".
- DestinationPort - The destination port for the rule.
- Description - A description for the rule.
- Log - Whether to log matches for this rule. Default is false.
- Force - Suppresses the confirmation prompt.
Examples
# Create a rule to allow HTTP traffic
New-OPNSenseFirewallRule -Interface "lan" -Protocol "tcp" -Destination "any" -DestinationPort "80" -Description "Allow HTTP"
# Create a rule to block outgoing SMTP traffic
New-OPNSenseFirewallRule -Interface "lan" -Direction "out" -Protocol "tcp" -DestinationPort "25" -Action "block" -Description "Block outgoing SMTP" -Log
# Create a rule to allow traffic from a specific subnet to a specific server
New-OPNSenseFirewallRule -Interface "lan" -Protocol "tcp" -Source "192.168.1.0/24" -Destination "192.168.2.10" -DestinationPort "443" -Description "Allow subnet to server"
Set-OPNSenseFirewallRule
Updates an existing firewall rule on an OPNSense firewall.
Parameters
- Uuid - The UUID of the firewall rule to update.
- Enabled - Whether the rule is enabled.
- Action - The action to take (pass, block, reject).
- Interface - The interface for the rule.
- Direction - The direction for the rule (in, out).
- Protocol - The protocol for the rule.
- Source - The source address for the rule.
- SourcePort - The source port for the rule.
- Destination - The destination address for the rule.
- DestinationPort - The destination port for the rule.
- Description - A description for the rule.
- Log - Whether to log matches for this rule.
- Force - Suppresses the confirmation prompt.
- PassThru - Returns the updated rule.
Examples
# Update a firewall rule's description
Set-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6" -Description "Updated HTTP rule"
# Update a firewall rule's destination port
Set-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6" -DestinationPort "8080"
# Update multiple properties of a firewall rule
Set-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6" -Action "block" -Log -Description "Block traffic" -PassThru
Remove-OPNSenseFirewallRule
Removes a firewall rule from an OPNSense firewall.
Parameters
- Uuid - The UUID of the firewall rule to remove.
- Force - Suppresses the confirmation prompt.
Examples
# Remove a firewall rule
Remove-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6"
# Remove a firewall rule without confirmation
Remove-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6" -Force
Enable-OPNSenseFirewallRule
Enables a firewall rule on an OPNSense firewall.
Parameters
- Uuid - The UUID of the firewall rule to enable.
- Force - Suppresses the confirmation prompt.
- PassThru - Returns the updated rule.
Examples
# Enable a firewall rule
Enable-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6"
# Enable a firewall rule and return the updated rule
Enable-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6" -PassThru
Disable-OPNSenseFirewallRule
Disables a firewall rule on an OPNSense firewall.
Parameters
- Uuid - The UUID of the firewall rule to disable.
- Force - Suppresses the confirmation prompt.
- PassThru - Returns the updated rule.
Examples
# Disable a firewall rule
Disable-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6"
# Disable a firewall rule and return the updated rule
Disable-OPNSenseFirewallRule -Uuid "a1b2c3d4-e5f6-g7h8-i9j0-k1l2m3n4o5p6" -PassThru
Apply-OPNSenseFirewallChanges
Applies pending firewall changes on an OPNSense firewall.
Parameters
- Force - Suppresses the confirmation prompt.
Examples
# Apply firewall changes
Apply-OPNSenseFirewallChanges
# Apply firewall changes without confirmation
Apply-OPNSenseFirewallChanges -Force
Common Scenarios
Basic Firewall Configuration
# Connect to the OPNSense firewall
Connect-OPNSense -Server "https://firewall.example.com" -ApiKey "your_api_key" -ApiSecret "your_api_secret" -SkipCertificateCheck
# Create rules for basic web access
New-OPNSenseFirewallRule -Interface "lan" -Protocol "tcp" -DestinationPort "80" -Description "Allow HTTP" -Force
New-OPNSenseFirewallRule -Interface "lan" -Protocol "tcp" -DestinationPort "443" -Description "Allow HTTPS" -Force
# Create a rule to allow DNS
New-OPNSenseFirewallRule -Interface "lan" -Protocol "udp" -DestinationPort "53" -Description "Allow DNS" -Force
# Apply the changes
Apply-OPNSenseFirewallChanges -Force
# Disconnect from the firewall
Disconnect-OPNSense
Securing a Network
# Connect to the OPNSense firewall
Connect-OPNSense -Server "https://firewall.example.com" -ApiKey "your_api_key" -ApiSecret "your_api_secret" -SkipCertificateCheck
# Block outgoing SMTP to prevent spam
New-OPNSenseFirewallRule -Interface "lan" -Direction "out" -Protocol "tcp" -DestinationPort "25" -Action "block" -Description "Block outgoing SMTP" -Log -Force
# Allow only specific hosts to access the management interface
New-OPNSenseFirewallRule -Interface "lan" -Protocol "tcp" -Source "192.168.1.10,192.168.1.11" -Destination "192.168.1.1" -DestinationPort "443" -Description "Allow management access" -Force
# Block all other access to the management interface
New-OPNSenseFirewallRule -Interface "lan" -Protocol "tcp" -Destination "192.168.1.1" -DestinationPort "443" -Action "block" -Description "Block management access" -Log -Force
# Apply the changes
Apply-OPNSenseFirewallChanges -Force
# Disconnect from the firewall
Disconnect-OPNSense
Managing Existing Rules
# Connect to the OPNSense firewall
Connect-OPNSense -Server "https://firewall.example.com" -ApiKey "your_api_key" -ApiSecret "your_api_secret" -SkipCertificateCheck
# Get all firewall rules
$rules = Get-OPNSenseFirewallRule
# Disable all rules with "Temporary" in the description
$rules | Where-Object { $_.Description -like "*Temporary*" } | ForEach-Object {
Disable-OPNSenseFirewallRule -Uuid $_.Uuid -Force
Write-Output "Disabled rule: $($_.Description)"
}
# Update all rules with "HTTP" in the description to use port 8080 instead of 80
$rules | Where-Object { $_.Description -like "*HTTP*" -and $_.DestinationPort -eq "80" } | ForEach-Object {
Set-OPNSenseFirewallRule -Uuid $_.Uuid -DestinationPort "8080" -Description "$($_.Description) (Updated Port)" -Force
Write-Output "Updated rule: $($_.Description)"
}
# Remove all rules with "Obsolete" in the description
$rules | Where-Object { $_.Description -like "*Obsolete*" } | ForEach-Object {
Remove-OPNSenseFirewallRule -Uuid $_.Uuid -Force
Write-Output "Removed rule: $($_.Description)"
}
# Apply the changes
Apply-OPNSenseFirewallChanges -Force
# Disconnect from the firewall
Disconnect-OPNSense
Notes
- Firewall rules are processed in order, with the first matching rule being applied.
- Changes to firewall rules are not applied until you call
Apply-OPNSenseFirewallChanges. - When creating or updating rules, consider the rule order and potential security implications.
- Use the
-Logparameter for rules that you want to monitor for security purposes. - Use aliases for frequently used IP addresses or networks to make rules more maintainable.
- Consider using the
-PassThruparameter when updating rules to verify the changes. - Always apply the principle of least privilege when creating firewall rules.