Hank wrote:stig@ER-bgp-test# set firewall group network-group SPAMHAUS_DROP [edit] stig@ER-bgp-test# commit [edit]Note it is a network-group.
This thread has been bleeping in my inbox for a couple of days.
Hank is correct. It works with a SPAMHAUS_DROP network-group. If you created an address-group by mistake, you need to remove it first (remember to commit) and then create the SPAMHAUS_DROP network -group. Then you can add the drop firewall rule to any interface needed (applied it to WAN_IN and WAN_OUT myself).