PasteZap
🌐 日本語
無料 · アカウント不要

無料 · ネットワーク・IT インフラ

ファイアウォールルール生成.

ルールを一度書くだけで、iptables、nftables、UFW、firewalld、Windows ファイアウォール、Cisco ACL、MikroTik の設定を生成します。

はじめる前に

一部の技術的な操作項目は英語です。Unicode テキストに対応していますが、ファイル形式と出力言語はツールによって異なります。

技術的な制限は以下に英語で記載されています。大きなファイルを処理する前や結果を使用する前に確認してください。

CALCULATED IN YOUR BROWSER · NOTHING IS UPLOADED
Rules (first match wins, top to bottom)

Policy

Rules4nftables

nftables ruleset

#!/usr/sbin/nft -f
# Load: sudo nft -f rules.nft — replaces only the table "inet filter".
table inet filter
delete table inet filter
table inet filter {
	chain input {
		type filter hook input priority 0; policy drop;
		iif "lo" accept
		ct state established,related accept
		ct state invalid drop
		icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, nd-router-solicit, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert } accept
		icmp type echo-request accept
		icmpv6 type echo-request accept
		ip saddr 203.0.113.10/32 tcp dport 22 accept comment "SSH from admin"
		tcp dport { 80, 443 } accept comment "Web"
		udp dport 443 accept comment "HTTP/3"
		ip saddr 10.0.0.0/8 tcp dport 9100 accept comment "Metrics from LAN"
		limit rate 5/minute log prefix "nft input drop: "
	}
	chain forward {
		type filter hook forward priority 0; policy drop;
	}
	chain output {
		type filter hook output priority 0; policy accept;
		oif "lo" accept
		ct state established,related accept
	}
}

Rule summary

#ActionDirectionProtocolSourceDestinationPortsComment
1allowInboundtcp203.0.113.10/32any22SSH from admin
2allowInboundtcpanyany80, 443Web
3allowInboundudpanyany443HTTP/3
4allowInboundtcp10.0.0.0/8any9100Metrics from LAN
  • Generated text only: nothing is applied to any machine. Review it, test on a non-production host and keep out-of-band access before loading it.
  • Rules match traffic to and from this host. Routed (forwarded) traffic needs FORWARD/forward chains or the router’s own configuration.

使い方: ファイアウォールルール生成

データを入力するかファイルを選び、設定を調整して結果を生成します。コピーやダウンロードの前に結果を確認してください。

制限と対応形式

入力内容はお使いの端末で処理されます。

英語の技術説明

Text generation only; nothing is applied. Rules protect the host itself (input/output), not routed traffic. ICMP rules cannot be written as UFW commands; firewalld outbound rules need policies. Everything is calculated in your browser; nothing is sent or probed on the network.

Rules are validated (addresses, CIDR, ports, protocols), split per IP family and translated into each syntax: multiport for iptables, sets for nftables, rich rules for firewalld, wildcard masks for Cisco and quoted lists for PowerShell.

Allow SSH from 203.0.113.10 and web from anywhere with a default-drop policy, and get an nftables table, iptables-restore files or Cisco ACLs.