diff --git a/src/opnsense/mvc/app/controllers/OPNsense/Firewall/forms/dialogFilterRule.xml b/src/opnsense/mvc/app/controllers/OPNsense/Firewall/forms/dialogFilterRule.xml
index 90f55638eb..9ceb276c15 100644
--- a/src/opnsense/mvc/app/controllers/OPNsense/Firewall/forms/dialogFilterRule.xml
+++ b/src/opnsense/mvc/app/controllers/OPNsense/Firewall/forms/dialogFilterRule.xml
@@ -55,6 +55,13 @@
When a rule does not have quick enabled, the last matching rule wins.
+
+ rule.allowopts
+
+ checkbox
+ This allows packets with IP options to pass. Otherwise they are blocked by default.
+ true
+ rule.interfacenot
diff --git a/src/opnsense/mvc/app/models/OPNsense/Firewall/Filter.xml b/src/opnsense/mvc/app/models/OPNsense/Firewall/Filter.xml
index 75e2274e5e..cc6350bd37 100644
--- a/src/opnsense/mvc/app/models/OPNsense/Firewall/Filter.xml
+++ b/src/opnsense/mvc/app/models/OPNsense/Firewall/Filter.xml
@@ -131,6 +131,10 @@
0Y
+
+ 0
+ Y
+ 0Y