← All Tools

Network Flow Matrix

Define the flows authorised between your network zones, see them as a source-to-destination matrix and check them against segmentation policy.

Everything stays in this browser tab and is not saved: reloading the page clears it. Use Import / Export to keep your work as JSON or CSV.

NameTypeCIDRsTagsDescriptionActions
SourceDestinationDirProtoPortsActionStatusTagsDescriptionActions

Rows are source zones, columns destination zones. Each cell shows how many flows exist for that pair; select a cell to list them. allow deny both = allows an insecure port or any port

0 issues

Validation runs each time you open this tab.

Import

JSON (full configuration)

Zones, port profiles and flows from a file exported here. Replaces the current data.

Zones CSV

Columns: name (required), type, cidrs, tags, description, id. Separate list values with ;.

Flows CSV

Columns: source_zone and dest_zone (zone names, required), direction, protocol, ports, action, tags, status, description. Import zones first.

Sample dataset

A 3-tier architecture with Internet, DMZ, app, database, intranet, management and PCI zones, including a few deliberate policy violations.

Export

JSON (full configuration)

All zones, port profiles and flows in one file you can import again later.

CSV (separate files)

zones.csv and flows.csv, e.g. for a firewall change request or a spreadsheet review.

How it works

Each zone gets a trust level from its type: External < DMZ < Other < Environment < Intranet < Management. Validation checks every flow (both directions for two-way flows) against these rules:

  • insecure_port (error): a cleartext or high-risk service (FTP, Telnet, TFTP, POP3, IMAP, SNMP v1/v2c, SMB, r-services, database and cache ports, VNC…) allowed from a less-trusted zone into a more-trusted one.
  • unmapped_zone (error): the flow points to a zone that no longer exists.
  • overly_broad (warning): an allow rule on any port, or on any protocol and any port.
  • cross_zone (warning): an allow rule into a Management zone from any other zone. Management networks should only receive what they strictly need.
  • duplicate (info): another flow has the same zones, protocol, ports and action.

The matrix is a review aid for segmentation (for example PCI DSS scoping or a DORA/NIS2 network review), not a firewall configuration. To check an actual ruleset, paste it into the Firewall Rule Analyzer.