← All Tools
Firewall Rule Analyzer
Find shadowed, redundant and overly permissive rules in iptables, UFW and nftables rulesets.
Your rules are analysed in this browser only. Nothing is uploaded or stored.
Use the output of iptables-save, ufw status verbose or nft list ruleset. The format is detected automatically when it is unambiguous.
How it works
- Shadowed rule: an earlier rule in the same chain already matches every packet the later rule would match (same or wider interface, protocol, addresses, ports and connection state) with a different action. The later rule never takes effect, so what it was meant to allow or block does not happen.
- Redundant rule: same situation, same action. It is harmless but hides the real policy and usually means an earlier rule is broader than intended.
- Overly permissive: an accept rule with no protocol, port, address, interface or state restriction (an “allow everything” rule).
- Sensitive port exposed: remote-access, file-sharing and database ports (Telnet, FTP, SMB, RDP, VNC, MySQL, PostgreSQL, Redis, MongoDB, Elasticsearch…) accepted from any source.
- Default policy: incoming and forwarded traffic should end in drop/deny, either through the chain policy or a final catch-all rule.
Address containment is computed for IPv4 CIDRs (use the CIDR calculator to check a range by hand); IPv6 addresses are compared literally. Rules with negations (!), jumps to user chains or matches the analyzer does not understand are never treated as covering later rules, so it errs on the side of missing a shadow rather than inventing one. It is a static review aid, not a replacement for testing the live ruleset.