I often find myself changing several rules at once for groups of IP
addresses/ranges that I think of in terms like "remote office networks",
"family vpn", or "provider subnets".
Maybe I'm stretching it too much (as I sometimes do), but wouldn't having
the option of defining symbolic names for groups of hosts and networks be
terribly handy? It will really simplify rule base maintenance, and it is
easy to see how this could be unified with the current built-in
pre-defined names such as "LAN subnet" and "PPTP clients".
Over here in Holland we have a saying that goes something like "give them
a finger, and they'll want to take the whole hand", which is probably
applicable here. m0n0wall is *so* good that it reminds you of, and creates
the desire for, perfection.
Bart Smit <bit at pipe dot nl> (yeah, address change)