Hello,
No, multiple zones cannot be used in single firewall rule. However, there are few things, which might ease the rule creating process:
- To begin with, take note that in single port forwarding rule you can specify "port range" and not just single TCP/UDP port. (Example: instead of creating 5 separate rules for ports 5001, 5002, 5003, 5004, 5005, you can just create one rule with "5001-5005" ports specified in both "External port"/"Internal port" fields)
- If you have to have a lot of port forwarding rules (e.g. each for specific device in router's LAN), you can either:
a) create these rules once for one single interface (e.g. WAN) from WebUI, then connect to router via SSH and duplicate necessary rules and change their "Source zone"
b) create all of the rules from SSH entirely. When doing so, I would recommend to create 2 port forwarding rules, each for each "Source zone". Then connect to router via SSH and configure adding desired amount of rules following previously created rule structure.
The process would look like this:
1. Connect to router via SSH (e.g. using "Putty" software for windows OS):
- SSH login: root
- SSH password: <your router's password>
2. Open "Firewall" configuration and inspect how rules, which you have created from WebUI, are described in router's configuration file:
3. Copy rule structure into, e.g. "notepad" application (since it is easier to edit rule in notepad, than from SSH). Keep duplicating same rule and then change IP address/Port number so that in the end you would have all your desired firewall rules listed in this "notepad" file.
4. Open firewall configuration file in editable format and copy all your firewall rules to it. Make sure to not duplicate the rules (i.e. so that rules, which you have already created from WebUI, would not be added again from SSH). To open firewall configuration file in editable format:
- vi /etc/config/firewall
- press "a" keyboard button
- navigate with keyboard arrow keys to the bottom of configuration file
- paste your firewall rules
- press "esc" keyboard button
- type ":x" and press enter
- reboot the router for rules to take effect.
Would be waiting for your feedback if this method was relevant for you and, if yes, did it actually helped to configure port forwarding rules faster.