I wonder if it would make sense to add an additional section to specify options: example /etc/pve/firewall/100.fw --------- [options] enabled: 1 policy-in: DROP policy-out: ACCEPT log-level-in: 4 log-level-out: 0 ... Does that make sense?