PasteZap
🌐 हिन्दी
मुफ़्त · बिना खाते के

मुफ़्त · नेटवर्क और आईटी इन्फ्रास्ट्रक्चर

फ़ायरवॉल नियम जनरेटर.

नियम एक बार लिखें और iptables, nftables, UFW, firewalld, Windows फ़ायरवॉल, Cisco ACL और MikroTik कॉन्फ़िगरेशन बनाएँ।

शुरू करने से पहले

कुछ तकनीकी नियंत्रण अंग्रेज़ी में हैं। Unicode टेक्स्ट समर्थित है; फ़ाइल फ़ॉर्मैट और परिणाम की भाषाएं टूल पर निर्भर हैं।

तकनीकी सीमाएं नीचे अंग्रेज़ी में दी गई हैं। बड़ी फ़ाइलों को संसाधित करने या परिणाम का उपयोग करने से पहले इन्हें जांचें।

CALCULATED IN YOUR BROWSER · NOTHING IS UPLOADED
Rules (first match wins, top to bottom)

Policy

Rules4nftables

nftables ruleset

#!/usr/sbin/nft -f
# Load: sudo nft -f rules.nft — replaces only the table "inet filter".
table inet filter
delete table inet filter
table inet filter {
	chain input {
		type filter hook input priority 0; policy drop;
		iif "lo" accept
		ct state established,related accept
		ct state invalid drop
		icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, nd-router-solicit, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert } accept
		icmp type echo-request accept
		icmpv6 type echo-request accept
		ip saddr 203.0.113.10/32 tcp dport 22 accept comment "SSH from admin"
		tcp dport { 80, 443 } accept comment "Web"
		udp dport 443 accept comment "HTTP/3"
		ip saddr 10.0.0.0/8 tcp dport 9100 accept comment "Metrics from LAN"
		limit rate 5/minute log prefix "nft input drop: "
	}
	chain forward {
		type filter hook forward priority 0; policy drop;
	}
	chain output {
		type filter hook output priority 0; policy accept;
		oif "lo" accept
		ct state established,related accept
	}
}

Rule summary

#ActionDirectionProtocolSourceDestinationPortsComment
1allowInboundtcp203.0.113.10/32any22SSH from admin
2allowInboundtcpanyany80, 443Web
3allowInboundudpanyany443HTTP/3
4allowInboundtcp10.0.0.0/8any9100Metrics from LAN
  • Generated text only: nothing is applied to any machine. Review it, test on a non-production host and keep out-of-band access before loading it.
  • Rules match traffic to and from this host. Routed (forwarded) traffic needs FORWARD/forward chains or the router’s own configuration.

इस टूल का उपयोग कैसे करें: फ़ायरवॉल नियम जनरेटर

डेटा दर्ज करें या फ़ाइल चुनें। विकल्प बदलें, परिणाम बनाएं और कॉपी या डाउनलोड करने से पहले उसकी जांच करें।

सीमाएं और समर्थित फ़ॉर्मैट

आपका डेटा आपके उपकरण पर संसाधित होता है।

अंग्रेज़ी में तकनीकी जानकारी

Text generation only; nothing is applied. Rules protect the host itself (input/output), not routed traffic. ICMP rules cannot be written as UFW commands; firewalld outbound rules need policies. Everything is calculated in your browser; nothing is sent or probed on the network.

Rules are validated (addresses, CIDR, ports, protocols), split per IP family and translated into each syntax: multiport for iptables, sets for nftables, rich rules for firewalld, wildcard masks for Cisco and quoted lists for PowerShell.

Allow SSH from 203.0.113.10 and web from anywhere with a default-drop policy, and get an nftables table, iptables-restore files or Cisco ACLs.