PasteZap
🌐 简体中文
免费 · 无需注册

免费 · 网络与 IT 基础设施

防火墙规则分析器.

审查 iptables-save 输出或 Cisco ACL,找出被遮蔽和重复的规则、全放行规则、暴露在互联网的服务和有风险的默认策略。

开始之前

部分技术控件使用英语。支持 Unicode 文本;文件格式和输出语言取决于具体工具。

下面以英语列出技术限制。处理大型文件或使用结果之前,请先查看这些限制。

CALCULATED IN YOUR BROWSER · NOTHING IS UPLOADED
Findings72 high · 2 medium · 2 low
Rules parsed
8
Chains or ACLs
1
Format
iptables-save
Rules with conditions not analysed
0
Negations, rate limits, TCP flags, object groups…

Findings

SeverityLineFindingRule
HIGH8MySQL (port 3306) is open to any source address. Restrict it to trusted addresses or a VPN.-A INPUT -p tcp -m tcp --dport 3306 -j ACCEPT
HIGH10Shadowed: line 9 (ACCEPT) matches first, so this DROP never applies.-A INPUT -s 10.1.0.0/16 -p tcp -m tcp --dport 443 -j DROP
MEDIUM2INPUT policy is ACCEPT with no final drop rule: anything not explicitly blocked is allowed.:INPUT ACCEPT
MEDIUM6SSH (port 22) is open to any source address. Restrict it to trusted addresses or a VPN.-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
LOW7Redundant: line 6 already accepts everything this rule matches.-A INPUT -s 203.0.113.10/32 -p tcp -m tcp --dport 22 -j ACCEPT
LOW12Redundant: line 11 already accepts everything this rule matches.-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
INFO—No LOG rule in INPUT: dropped traffic leaves no trace for troubleshooting or detection.
  • Static analysis of the text you pasted, done in your browser. Rules with conditions the analyser does not model are never treated as hiding other rules, so it errs on the side of missing findings rather than inventing them.
  • Only the iptables filter table is analysed; nat and mangle tables are skipped. Jumps to user chains are treated as non-final.

使用方法: 防火墙规则分析器

输入数据或选择文件,调整设置并生成结果。复制或下载之前,请检查结果。

限制与支持格式

输入内容在您的设备上处理。

英语技术说明

Static analysis of the filter table and standard IOS ACL syntax; nftables, vendor NGFW policies, NAT and object groups are not analysed. Rules with unmodelled conditions are never treated as hiding others. Everything is calculated in your browser; nothing is sent or probed on the network.

Each rule becomes a set of ranges (protocol, addresses, ports, interface, state). A later rule is shadowed or redundant when an earlier final rule covers all its ranges; accepts from any source to sensitive ports are flagged.

In the example, SSH and MySQL are open to any source, a DROP for 10.1.0.0/16 is shadowed by an earlier ACCEPT for 10.0.0.0/8 and a port-80 rule is redundant.