Fri Oct 19, 2018 7:50 pm
For firewall rules, for some uses, current address list feature is good enough. But not for everything, e.g. srcnat's to-addresses can be only address.
So possibility to have address aliases sounds interesting. Ideally as global thing, so that the alias could be used in every single place where router accepts IP address (firewall rules, ipsec, tunnels, dns servers, firewall's address list could also take entries as aliases, ...). It could allow really nice high-level and easy to work with approach. But it looks like a lot of work would be required.