Digi Control documentation
Network and firewall
Interfaces/routes, dynamic backends, profiles, transactions and remote safety.
What it covers
- Network overview shows interfaces, addresses, link state, routes, DNS-related state and deviations.
- The firewall module is dynamic: nftables or firewalld according to the actually installed backend.
- Guided actions can include server/strict/maintenance profiles, known service/port, reload, plan/dry-run/apply/rollback and drift review.
- Remote source allow-lists normally use a single /32 IPv4 or /128 IPv6.
How to use it
- Check the current snapshot.
- Plan/dry-run.
- Ensure the management source remains allowed.
- Apply.
- Verify connectivity/rollback.
Important rules
- Do not edit native firewall state in parallel.
- Remote enablement and allow-list are separate.
- A remote change without rollback planning is high risk.