Firewall Rule Generator

Pick what the server runs and who may reach it. You get matching rules for nftables, iptables and UFW, with a default-deny policy that keeps your SSH session open.

  • Free
  • No Sign-Up
  • Runs in Your Browser

Services to Open

Check Before You Apply

SSH is open to the whole internet. Limit it to your own addresses if they are fixed.

These rules replace the existing input rules. Check nothing else (Docker, fail2ban, the Proxmox firewall) manages this server's firewall first.

/etc/nftables.conf

#!/usr/sbin/nft -f
# /etc/nftables.conf: generated at frabs.net/tools/firewall-rule-generator/
flush ruleset

table inet filter {
  chain input {
    type filter hook input priority 0; policy drop;

    ct state established,related accept
    ct state invalid drop
    iif "lo" accept
    ip protocol icmp icmp type { echo-request, destination-unreachable, time-exceeded } limit rate 10/second accept
    ip6 nexthdr icmpv6 accept  # IPv6 needs ICMPv6 for neighbour discovery
    tcp dport 22 accept  # SSH
  }

  chain forward {
    type filter hook forward priority 0; policy accept;
  }

  chain output {
    type filter hook output priority 0; policy accept;
  }
}

# Apply:  nft -f /etc/nftables.conf
# Keep at boot:  systemctl enable nftables

How to Use

How to use the Firewall Rule Generator

  1. 01

    Choose the services

    Tick the ports to open, or add your own.

  2. 02

    Limit who can connect

    Restrict SSH and admin ports to your own addresses.

  3. 03

    Copy the rules

    Pick nftables, iptables or UFW, and paste the commands on the server.

Security & Abuse

About the Firewall Rule Generator

A safe order of work

Always allow established connections and your SSH port before setting the default policy to drop, or you will lock yourself out. The generated rules do that in the right order. On a remote server, run them inside a screen or tmux session, or schedule a rollback (for example: at now + 5 minutes <<< 'nft flush ruleset') and cancel it once you have checked you can still connect.

nftables, iptables or UFW?

nftables is the modern Linux firewall and the default on Debian 10+, Ubuntu 20.10+ and RHEL 8+. iptables commands still work through the iptables-nft layer. UFW is a simpler front end on Ubuntu. Use one of them, not several: rules from different tools on the same host are hard to reason about.

Docker and Proxmox's firewall manage their own rules; check how they interact before adding host rules on those systems.

Outbound rules

Most firewalls only filter what comes in. On servers that host other people's VMs, outbound is where abuse comes from: spam on port 25, scans and floods. Blocking outbound 25 for VMs that do not need it removes most spam complaints. Frabs goes further and watches each VM's traffic for the behaviour itself.

What it can't tell you

  • Rules are for the host's own traffic (INPUT), not for routed or bridged VM traffic (FORWARD).
  • Saving rules across reboots differs by distribution; the commands to do it are included for each.

Frequently asked questions

How do I keep iptables rules after a reboot?
On Debian and Ubuntu install iptables-persistent and run netfilter-persistent save. On RHEL-based systems use iptables-services and service iptables save. nftables reads /etc/nftables.conf at boot.
Should I block ping?
No. Blocking all ICMP breaks path MTU discovery and makes troubleshooting harder. Allow it, and rate-limit if you are worried.
How do I limit SSH to my own IP?
Enter your address under SSH. The rules then accept port 22 only from it. Check your address first with the What Is My IP tool.

Firewalls stop traffic coming in

Frabs stops the abuse going out: spam, scans and floods from any VM, caught by behaviour, not by port.