免费 · 网络与 IT 基础设施
防火墙规则生成器.
规则只写一次,即可生成 iptables、nftables、UFW、firewalld、Windows 防火墙、Cisco ACL 和 MikroTik 配置。
Policy
nftables ruleset
#!/usr/sbin/nft -f
# Load: sudo nft -f rules.nft — replaces only the table "inet filter".
table inet filter
delete table inet filter
table inet filter {
chain input {
type filter hook input priority 0; policy drop;
iif "lo" accept
ct state established,related accept
ct state invalid drop
icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, nd-router-solicit, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert } accept
icmp type echo-request accept
icmpv6 type echo-request accept
ip saddr 203.0.113.10/32 tcp dport 22 accept comment "SSH from admin"
tcp dport { 80, 443 } accept comment "Web"
udp dport 443 accept comment "HTTP/3"
ip saddr 10.0.0.0/8 tcp dport 9100 accept comment "Metrics from LAN"
limit rate 5/minute log prefix "nft input drop: "
}
chain forward {
type filter hook forward priority 0; policy drop;
}
chain output {
type filter hook output priority 0; policy accept;
oif "lo" accept
ct state established,related accept
}
}Rule summary
| # | Action | Direction | Protocol | Source | Destination | Ports | Comment |
|---|---|---|---|---|---|---|---|
| 1 | allow | Inbound | tcp | 203.0.113.10/32 | any | 22 | SSH from admin |
| 2 | allow | Inbound | tcp | any | any | 80, 443 | Web |
| 3 | allow | Inbound | udp | any | any | 443 | HTTP/3 |
| 4 | allow | Inbound | tcp | 10.0.0.0/8 | any | 9100 | Metrics from LAN |
- Generated text only: nothing is applied to any machine. Review it, test on a non-production host and keep out-of-band access before loading it.
- Rules match traffic to and from this host. Routed (forwarded) traffic needs FORWARD/forward chains or the router’s own configuration.
使用方法: 防火墙规则生成器
输入数据或选择文件,调整设置并生成结果。复制或下载之前,请检查结果。
限制与支持格式
输入内容在您的设备上处理。
英语技术说明
Text generation only; nothing is applied. Rules protect the host itself (input/output), not routed traffic. ICMP rules cannot be written as UFW commands; firewalld outbound rules need policies. Everything is calculated in your browser; nothing is sent or probed on the network.
Rules are validated (addresses, CIDR, ports, protocols), split per IP family and translated into each syntax: multiport for iptables, sets for nftables, rich rules for firewalld, wildcard masks for Cisco and quoted lists for PowerShell.
Allow SSH from 203.0.113.10 and web from anywhere with a default-drop policy, and get an nftables table, iptables-restore files or Cisco ACLs.