FREE · NETWORK & IT INFRASTRUCTURE
Firewall Rule Generator.
Write firewall rules once and generate iptables, nftables, UFW, firewalld, Windows Defender Firewall, Cisco ACL and MikroTik configurations.
Policy
nftables ruleset
#!/usr/sbin/nft -f
# Load: sudo nft -f rules.nft — replaces only the table "inet filter".
table inet filter
delete table inet filter
table inet filter {
chain input {
type filter hook input priority 0; policy drop;
iif "lo" accept
ct state established,related accept
ct state invalid drop
icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, nd-router-solicit, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert } accept
icmp type echo-request accept
icmpv6 type echo-request accept
ip saddr 203.0.113.10/32 tcp dport 22 accept comment "SSH from admin"
tcp dport { 80, 443 } accept comment "Web"
udp dport 443 accept comment "HTTP/3"
ip saddr 10.0.0.0/8 tcp dport 9100 accept comment "Metrics from LAN"
limit rate 5/minute log prefix "nft input drop: "
}
chain forward {
type filter hook forward priority 0; policy drop;
}
chain output {
type filter hook output priority 0; policy accept;
oif "lo" accept
ct state established,related accept
}
}Rule summary
| # | Action | Direction | Protocol | Source | Destination | Ports | Comment |
|---|---|---|---|---|---|---|---|
| 1 | allow | Inbound | tcp | 203.0.113.10/32 | any | 22 | SSH from admin |
| 2 | allow | Inbound | tcp | any | any | 80, 443 | Web |
| 3 | allow | Inbound | udp | any | any | 443 | HTTP/3 |
| 4 | allow | Inbound | tcp | 10.0.0.0/8 | any | 9100 | Metrics from LAN |
- Generated text only: nothing is applied to any machine. Review it, test on a non-production host and keep out-of-band access before loading it.
- Rules match traffic to and from this host. Routed (forwarded) traffic needs FORWARD/forward chains or the router’s own configuration.
How to use Firewall Rule Generator
Choose the output format, list rules (action, direction, protocol, source, destination, ports, comment), set the default policies, and copy or download the result. Presets cover web, database, mail, DNS and VPN servers.
How it works
Rules are validated (addresses, CIDR, ports, protocols), split per IP family and translated into each syntax: multiport for iptables, sets for nftables, rich rules for firewalld, wildcard masks for Cisco and quoted lists for PowerShell.
Example
Allow SSH from 203.0.113.10 and web from anywhere with a default-drop policy, and get an nftables table, iptables-restore files or Cisco ACLs.
One rule table, seven syntaxes
Firewall rules say the same thing everywhere — allow or block traffic of a protocol, from some addresses, to some ports — but every platform spells it differently. This generator lets you describe the policy once and writes it for iptables (as iptables-restore files for IPv4 and IPv6), nftables, UFW, firewalld rich rules, Windows Defender Firewall in PowerShell, Cisco IOS access lists and MikroTik RouterOS.
Rules are checked before anything is written: addresses and CIDR blocks must be valid, ports must be between 1 and 65535 and only appear with TCP or UDP, and a rule cannot mix IPv4 sources with IPv6 destinations.
A safe default policy
- Drop inbound traffic by default and allow only what a service needs.
- Allow replies to connections the host opened (established and related).
- Allow loopback, and on IPv6 the ICMPv6 messages neighbour discovery needs — without them IPv6 stops working.
- Restrict administration (SSH, RDP, WinRM) to known addresses or a VPN.
- Log dropped packets with a rate limit so logs stay readable.
The presets apply this pattern to a web server, a database server, a mail server, a DNS server, a WireGuard gateway and a workstation with strict outbound rules.
Differences that matter
| Platform | Behaviour to know |
|---|---|
| iptables / nftables | First matching rule wins. nftables handles IPv4 and IPv6 in one inet table. |
| UFW | Loopback, established traffic and ping are allowed in before.rules; ICMP cannot be written as a command. |
| firewalld | Rich rules filter inbound traffic of a zone; outbound filtering needs policy objects. |
| Windows | Block rules win over allow rules whatever their order. |
| Cisco IOS ACL | Stateless: “established” only matches TCP replies; UDP replies need reflexive ACLs or a zone-based firewall. |
| MikroTik | Rules are appended after the existing default configuration; move them with place-before if needed. |
The generator warns when a default-drop policy has no rule for remote management, because applying it over SSH or RDP would lock you out.
Before you apply the rules
Nothing is applied by this page: it only produces text. Read the output, test it on a non-production machine and keep console or out-of-band access. On Linux, iptables-apply and nftables’ “nft -c -f” check a file without loading it. Afterwards, paste the live rules into the firewall rule analyzer to look for shadowed or redundant entries, and use the port lookup to confirm which services you are exposing.
Questions about Firewall Rule Generator
Do these rules filter traffic routed through the machine?
No. They protect the host itself (input and output). Routed traffic needs FORWARD or forward chains, or the router’s own policy.
Why are there separate IPv4 and IPv6 files for iptables?
iptables and ip6tables are separate tables. A rule without addresses is written to both; a rule with IPv4 addresses only to the IPv4 file.
Can I remove the Windows rules later?
Yes. Every rule is created in the “PasteZap” group, so Remove-NetFirewallRule -Group "PasteZap" removes them all.
Is Firewall Rule Generator free, and do I need an account?
Yes. This tool is free to use in your browser without an account. Processing takes place on your device.
What are the limits and what should I check?
Text generation only; nothing is applied. Rules protect the host itself (input/output), not routed traffic. ICMP rules cannot be written as UFW commands; firewalld outbound rules need policies. Everything is calculated in your browser; nothing is sent or probed on the network. Review the result before using it in your work.
Is my input sent to a server?
Your input is processed in your browser and is not uploaded by this tool. Files and pasted text are cleared when the page is refreshed. Normal website requests are still required to load the page and its libraries. Read the privacy explanation.