Floating rules

The leftmost tab on the Rules page is Floating. From this tab, you can create rules that are different from the rules described previously in several ways:

To begin creating Floating rules, we first click on the Rules page and then click on one of the Add buttons. You will notice that the options are similar to those we saw before, when creating non-floating rules, with some significant differences:

The Quick option is a powerful one, and potentially useful. A floating rule without Quick enabled is enforced only if none of the rules on the subnet/interface tabs and (since rules are evaluated on a top-down basis) only if none of the rules above it on the Floating tab match the traffic first. Thus, if we need to enforce a rule before all other rules, we can use the Quick option. Floating rules without Quick enabled, however, are an effective way of enforcing default behavior on multiple interfaces.

If Quick is enabled, the fast-forward icon (two adjacent green sideways triangles) will appear on the left hand side of a rule’s entry in the Floating Rules table.

Because this can seem confusing at first, it should be mentioned that non-floating rules are always enforced on traffic that is inbound to an interface. Thus, if we want to create a floating rule that behaves the same as non-floating rules, we would set Direction to in. If you need to filter outbound traffic or traffic in both directions, then select the out or any option.