मुफ़्त · नेटवर्क और आईटी इन्फ्रास्ट्रक्चर
फ़ायरवॉल नियम जनरेटर.
नियम एक बार लिखें और iptables, nftables, UFW, firewalld, Windows फ़ायरवॉल, Cisco ACL और MikroTik कॉन्फ़िगरेशन बनाएँ।
Policy
nftables ruleset
#!/usr/sbin/nft -f
# Load: sudo nft -f rules.nft — replaces only the table "inet filter".
table inet filter
delete table inet filter
table inet filter {
chain input {
type filter hook input priority 0; policy drop;
iif "lo" accept
ct state established,related accept
ct state invalid drop
icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, nd-router-solicit, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert } accept
icmp type echo-request accept
icmpv6 type echo-request accept
ip saddr 203.0.113.10/32 tcp dport 22 accept comment "SSH from admin"
tcp dport { 80, 443 } accept comment "Web"
udp dport 443 accept comment "HTTP/3"
ip saddr 10.0.0.0/8 tcp dport 9100 accept comment "Metrics from LAN"
limit rate 5/minute log prefix "nft input drop: "
}
chain forward {
type filter hook forward priority 0; policy drop;
}
chain output {
type filter hook output priority 0; policy accept;
oif "lo" accept
ct state established,related accept
}
}Rule summary
| # | Action | Direction | Protocol | Source | Destination | Ports | Comment |
|---|---|---|---|---|---|---|---|
| 1 | allow | Inbound | tcp | 203.0.113.10/32 | any | 22 | SSH from admin |
| 2 | allow | Inbound | tcp | any | any | 80, 443 | Web |
| 3 | allow | Inbound | udp | any | any | 443 | HTTP/3 |
| 4 | allow | Inbound | tcp | 10.0.0.0/8 | any | 9100 | Metrics from LAN |
- Generated text only: nothing is applied to any machine. Review it, test on a non-production host and keep out-of-band access before loading it.
- Rules match traffic to and from this host. Routed (forwarded) traffic needs FORWARD/forward chains or the router’s own configuration.
इस टूल का उपयोग कैसे करें: फ़ायरवॉल नियम जनरेटर
डेटा दर्ज करें या फ़ाइल चुनें। विकल्प बदलें, परिणाम बनाएं और कॉपी या डाउनलोड करने से पहले उसकी जांच करें।
सीमाएं और समर्थित फ़ॉर्मैट
आपका डेटा आपके उपकरण पर संसाधित होता है।
अंग्रेज़ी में तकनीकी जानकारी
Text generation only; nothing is applied. Rules protect the host itself (input/output), not routed traffic. ICMP rules cannot be written as UFW commands; firewalld outbound rules need policies. Everything is calculated in your browser; nothing is sent or probed on the network.
Rules are validated (addresses, CIDR, ports, protocols), split per IP family and translated into each syntax: multiport for iptables, sets for nftables, rich rules for firewalld, wildcard masks for Cisco and quoted lists for PowerShell.
Allow SSH from 203.0.113.10 and web from anywhere with a default-drop policy, and get an nftables table, iptables-restore files or Cisco ACLs.