PasteZap
🌐 Français
Gratuit · Sans compte

Gratuit · Réseau et infrastructure IT

Générateur de règles de pare-feu.

Écrivez vos règles une fois et générez la configuration iptables, nftables, UFW, firewalld, pare-feu Windows, ACL Cisco et MikroTik.

Avant de commencer

Certains contrôles techniques restent en anglais. Les textes Unicode sont acceptés ; les formats et langues de sortie dépendent de l’outil.

Les limites techniques sont indiquées en anglais ci-dessous. Vérifiez-les avant de traiter de gros fichiers ou d’utiliser le résultat.

CALCULATED IN YOUR BROWSER · NOTHING IS UPLOADED
Rules (first match wins, top to bottom)

Policy

Rules4nftables

nftables ruleset

#!/usr/sbin/nft -f
# Load: sudo nft -f rules.nft — replaces only the table "inet filter".
table inet filter
delete table inet filter
table inet filter {
	chain input {
		type filter hook input priority 0; policy drop;
		iif "lo" accept
		ct state established,related accept
		ct state invalid drop
		icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, nd-router-solicit, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert } accept
		icmp type echo-request accept
		icmpv6 type echo-request accept
		ip saddr 203.0.113.10/32 tcp dport 22 accept comment "SSH from admin"
		tcp dport { 80, 443 } accept comment "Web"
		udp dport 443 accept comment "HTTP/3"
		ip saddr 10.0.0.0/8 tcp dport 9100 accept comment "Metrics from LAN"
		limit rate 5/minute log prefix "nft input drop: "
	}
	chain forward {
		type filter hook forward priority 0; policy drop;
	}
	chain output {
		type filter hook output priority 0; policy accept;
		oif "lo" accept
		ct state established,related accept
	}
}

Rule summary

#ActionDirectionProtocolSourceDestinationPortsComment
1allowInboundtcp203.0.113.10/32any22SSH from admin
2allowInboundtcpanyany80, 443Web
3allowInboundudpanyany443HTTP/3
4allowInboundtcp10.0.0.0/8any9100Metrics from LAN
  • Generated text only: nothing is applied to any machine. Review it, test on a non-production host and keep out-of-band access before loading it.
  • Rules match traffic to and from this host. Routed (forwarded) traffic needs FORWARD/forward chains or the router’s own configuration.

Comment utiliser cet outil: Générateur de règles de pare-feu

Saisissez ou sélectionnez vos données. Réglez les options, générez le résultat puis vérifiez-le avant de le copier ou de le télécharger.

Limites et formats acceptés

Vos données sont traitées sur votre appareil.

Notes techniques en anglais

Text generation only; nothing is applied. Rules protect the host itself (input/output), not routed traffic. ICMP rules cannot be written as UFW commands; firewalld outbound rules need policies. Everything is calculated in your browser; nothing is sent or probed on the network.

Rules are validated (addresses, CIDR, ports, protocols), split per IP family and translated into each syntax: multiport for iptables, sets for nftables, rich rules for firewalld, wildcard masks for Cisco and quoted lists for PowerShell.

Allow SSH from 203.0.113.10 and web from anywhere with a default-drop policy, and get an nftables table, iptables-restore files or Cisco ACLs.