PasteZap
🌐 简体中文
免费 · 无需注册

免费 · 网络与 IT 基础设施

防火墙规则生成器.

规则只写一次,即可生成 iptables、nftables、UFW、firewalld、Windows 防火墙、Cisco ACL 和 MikroTik 配置。

开始之前

部分技术控件使用英语。支持 Unicode 文本;文件格式和输出语言取决于具体工具。

下面以英语列出技术限制。处理大型文件或使用结果之前,请先查看这些限制。

CALCULATED IN YOUR BROWSER · NOTHING IS UPLOADED
Rules (first match wins, top to bottom)

Policy

Rules4nftables

nftables ruleset

#!/usr/sbin/nft -f
# Load: sudo nft -f rules.nft — replaces only the table "inet filter".
table inet filter
delete table inet filter
table inet filter {
	chain input {
		type filter hook input priority 0; policy drop;
		iif "lo" accept
		ct state established,related accept
		ct state invalid drop
		icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, nd-router-solicit, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert } accept
		icmp type echo-request accept
		icmpv6 type echo-request accept
		ip saddr 203.0.113.10/32 tcp dport 22 accept comment "SSH from admin"
		tcp dport { 80, 443 } accept comment "Web"
		udp dport 443 accept comment "HTTP/3"
		ip saddr 10.0.0.0/8 tcp dport 9100 accept comment "Metrics from LAN"
		limit rate 5/minute log prefix "nft input drop: "
	}
	chain forward {
		type filter hook forward priority 0; policy drop;
	}
	chain output {
		type filter hook output priority 0; policy accept;
		oif "lo" accept
		ct state established,related accept
	}
}

Rule summary

#ActionDirectionProtocolSourceDestinationPortsComment
1allowInboundtcp203.0.113.10/32any22SSH from admin
2allowInboundtcpanyany80, 443Web
3allowInboundudpanyany443HTTP/3
4allowInboundtcp10.0.0.0/8any9100Metrics from LAN
  • Generated text only: nothing is applied to any machine. Review it, test on a non-production host and keep out-of-band access before loading it.
  • Rules match traffic to and from this host. Routed (forwarded) traffic needs FORWARD/forward chains or the router’s own configuration.

使用方法: 防火墙规则生成器

输入数据或选择文件,调整设置并生成结果。复制或下载之前,请检查结果。

限制与支持格式

输入内容在您的设备上处理。

英语技术说明

Text generation only; nothing is applied. Rules protect the host itself (input/output), not routed traffic. ICMP rules cannot be written as UFW commands; firewalld outbound rules need policies. Everything is calculated in your browser; nothing is sent or probed on the network.

Rules are validated (addresses, CIDR, ports, protocols), split per IP family and translated into each syntax: multiport for iptables, sets for nftables, rich rules for firewalld, wildcard masks for Cisco and quoted lists for PowerShell.

Allow SSH from 203.0.113.10 and web from anywhere with a default-drop policy, and get an nftables table, iptables-restore files or Cisco ACLs.