2.5. Group

With this particular item you can group a series of elements you have previously defined; these elements can be zones, nets or hosts. A Group is identified by a name and it can be used in the firewall rules like a normal system element. This feature makes very simple to define rules which are common to more hosts (even nets or zones), thus the firewall configuration is more synthetic, readable and simple to maintain. If, for example, we want to give ssh access towards a server to our 3 system admins, it will be sufficient to create a group called "administrators" that will be made up of the 3 admin hosts, and then apply only a ssh rule to the "administrators" group.

To create a new Group you have to click on "Create new group", assign it a name (ex. servers, privileged_host, etc.) and finally, checking a series of check-box, set which items will belong to the Group we are defining.