Hi,
please add negated network objects when defining a packet filter rule. iptables supports them via the "!" symbol in front of a network definition, so it should be trivial to implement and it would enhance functionality tremendously. Every other firewall on the market has this capability, so why not astaro?
Thanks!