FREE · NETWORK & IT INFRASTRUCTURE
Firewall Rule Analyzer.
Audit iptables-save output or Cisco ACLs for shadowed and redundant rules, catch-all permits, internet-exposed services and risky default policies.
- Rules parsed
- 8
- Chains or ACLs
- 1
- Format
- iptables-save
- Rules with conditions not analysed
- 0 Negations, rate limits, TCP flags, object groups…
Findings
| Severity | Line | Finding | Rule |
|---|---|---|---|
| HIGH | 8 | MySQL (port 3306) is open to any source address. Restrict it to trusted addresses or a VPN. | -A INPUT -p tcp -m tcp --dport 3306 -j ACCEPT |
| HIGH | 10 | Shadowed: line 9 (ACCEPT) matches first, so this DROP never applies. | -A INPUT -s 10.1.0.0/16 -p tcp -m tcp --dport 443 -j DROP |
| MEDIUM | 2 | INPUT policy is ACCEPT with no final drop rule: anything not explicitly blocked is allowed. | :INPUT ACCEPT |
| MEDIUM | 6 | SSH (port 22) is open to any source address. Restrict it to trusted addresses or a VPN. | -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT |
| LOW | 7 | Redundant: line 6 already accepts everything this rule matches. | -A INPUT -s 203.0.113.10/32 -p tcp -m tcp --dport 22 -j ACCEPT |
| LOW | 12 | Redundant: line 11 already accepts everything this rule matches. | -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT |
| INFO | — | No LOG rule in INPUT: dropped traffic leaves no trace for troubleshooting or detection. |
- Static analysis of the text you pasted, done in your browser. Rules with conditions the analyser does not model are never treated as hiding other rules, so it errs on the side of missing findings rather than inventing them.
- Only the iptables filter table is analysed; nat and mangle tables are skipped. Jumps to user chains are treated as non-final.
How to use Firewall Rule Analyzer
Paste the output of iptables-save (or ip6tables-save) or Cisco IOS access lists. Findings are sorted by severity and can be exported as CSV.
How it works
Each rule becomes a set of ranges (protocol, addresses, ports, interface, state). A later rule is shadowed or redundant when an earlier final rule covers all its ranges; accepts from any source to sensitive ports are flagged.
Example
In the example, SSH and MySQL are open to any source, a DROP for 10.1.0.0/16 is shadowed by an earlier ACCEPT for 10.0.0.0/8 and a port-80 rule is redundant.
Questions about Firewall Rule Analyzer
Is Firewall Rule Analyzer free, and do I need an account?
Yes. This tool is free to use in your browser without an account. Processing takes place on your device.
What are the limits and what should I check?
Static analysis of the filter table and standard IOS ACL syntax; nftables, vendor NGFW policies, NAT and object groups are not analysed. Rules with unmodelled conditions are never treated as hiding others. Everything is calculated in your browser; nothing is sent or probed on the network. Review the result before using it in your work.
Is my input sent to a server?
Your input is processed in your browser and is not uploaded by this tool. Files and pasted text are cleared when the page is refreshed. Normal website requests are still required to load the page and its libraries. Read the privacy explanation.