Page 1 of 1

request feature: grouping / filtering

Posted: Sun Oct 29, 2006 6:30 pm
by Hellbound
hi guys
it will be great to have some kind of grouping in firewall/mangle etc rules... like you group your photoshop layers I have hundreds of rules need to be grouping...

and also if possible to assign certain variable like Dst-address to all those group member at onces.


second thing is the filtering. like microsoft excel or something if you can filter for example CONNECTION MANAGER then I can easily monitor one specific range or user or port. this filter can also apply to others... just like FIND feature in shell.

thanks

any idea if are these things useful for others?

Posted: Sun Oct 29, 2006 6:59 pm
by 111111
This can be used in overseas split and blocking list

Posted: Sun Oct 29, 2006 8:23 pm
by changeip
use chains - put all your rules in that group in a chain. then they are all grouped in a single view.

use jump rules with a dst-address and then on the rules in the chain leave out the dst-addresses. . . that way you can change one entry and it will affect all rules in the chain it traverses.

Posted: Sun Oct 29, 2006 8:25 pm
by Hellbound
use chains - put all your rules in that group in a chain. then they are all grouped in a single view.

use jump rules with a dst-address and then on the rules in the chain leave out the dst-addresses. . . that way you can change one entry and it will affect all rules in the chain it traverses.
problem will dynamic rules are that they jump from buttom of a chain to top

however grouping and chain are two different thing...

you cannot apply a certain value to all of them in winbox... in command shell yes by using FIND.

using chain is good for shaping a network flow but grouping is just to organize them

Posted: Mon Oct 30, 2006 12:30 am
by 111111
add some /ex please

Would help sooo much

Posted: Tue Oct 31, 2006 7:35 pm
by wonderlan
Guys, grouping would be awesome to simply views, if you could manage mangle rules in groups, for example I might make a mangle group call exchange. In that i might have 20 friggin different rules for all my different sites, servers, ports, connection vs. packet markings... I really don't want to see all these when looking at the top view, I would much rather see my mangling groups and drill down.
Firewall grouping is also nice, yes you can use chains and jumps to pull it off, but this could be cleaned up, made more intuitive, and easier to manage. Why is it that your first reaction to any suggestion is we already do that just use this instead? Why not step back and look at the questions with no preconceptions and really look to see how you can IMPROVE.

Re: Would help sooo much

Posted: Tue Oct 31, 2006 7:49 pm
by Hellbound
Guys, grouping would be awesome to simply views, if you could manage mangle rules in groups, for example I might make a mangle group call exchange. In that i might have 20 friggin different rules for all my different sites, servers, ports, connection vs. packet markings... I really don't want to see all these when looking at the top view, I would much rather see my mangling groups and drill down.
Firewall grouping is also nice, yes you can use chains and jumps to pull it off, but this could be cleaned up, made more intuitive, and easier to manage. Why is it that your first reaction to any suggestion is we already do that just use this instead? Why not step back and look at the questions with no preconceptions and really look to see how you can IMPROVE.
I don't quite understand what you meant in last question by improve, but maybe you got the wrong idea, I'm also a routeros user and not a website official

Posted: Tue Oct 31, 2006 8:13 pm
by wonderlan
it was a dig at changeip for routinely replying with oh well you can do that if you just use this feature this particular way and it works fine. The problem is yes, that will accomplish the task, but it does not improve the situation. The task is still difficult, hard to manage when your dealing with very large complex installs, and that the attitude dosen't help improve the mikrotik as a whole. It does solve situational problems, but when talking about feature requests, its a whole different story.

Grouping is one of the things I miss from many of the $2000+ firewalls I'm used to working with. With large sites it made management much simpler. Digging through my firewall chains and esspecially dealing with the mangling is an absolute nightmere at many sites now.

Posted: Tue Oct 31, 2006 8:23 pm
by Hellbound
it was a dig at changeip for routinely replying with oh well you can do that if you just use this feature this particular way and it works fine. The problem is yes, that will accomplish the task, but it does not improve the situation. The task is still difficult, hard to manage when your dealing with very large complex installs, and that the attitude dosen't help improve the mikrotik as a whole. It does solve situational problems, but when talking about feature requests, its a whole different story.

Grouping is one of the things I miss from many of the $2000+ firewalls I'm used to working with. With large sites it made management much simpler. Digging through my firewall chains and esspecially dealing with the mangling is an absolute nightmere at many sites now.
:cry: :cry: :cry:

I have same requiem for this feature

Posted: Sat Dec 09, 2006 9:51 pm
by Hellbound
any idea if it is going to be added?

Posted: Tue Feb 27, 2007 8:59 pm
by Hellbound
any response?

thanks