NetworkFirewallSimulator.

Drop packets into a real rule engine. See exactly which ACL rule matches, how stateful sessions get tracked, and why your DMZ isn't as isolated as you think.

10
ACL Rules
3
Network Zones
Injections
OWASP ALIGNED
How it works
ARCHITECTURE

DMZ Isolation

Three-zone segmentation: WAN → DMZ → LAN with dual firewall gates.

ENGINE

Stateful Inspection

Bidirectional session tracking. Return traffic auto-permitted via state table.

RULESET

Sequential ACL

Top-to-bottom rule evaluation. First match terminates. Priority is everything.

AUDIT

Conflict Auditor

Auto-detect shadowed rules, redundant policies, insecure DMZ bypasses.

LOGGING

SIEM Syslog

Color-coded real-time log feed with ms-precision event timestamping.

SECURITY

Default Deny

Fail-closed posture. Unknown traffic silently blocked by implicit deny.

Quick Attack Presets

Test These Scenarios

Each preset describes a real packet: source IP, destination port, protocol flags. The engine evaluates it against the ACL and returns ALLOW, DENY, or REJECT.

HTTP → DMZ
:80 TCP SYN
ALLOW
DB Intrusion
:3306 TCP SYN
DENY
SSH Brute
:22 TCP SYN
REJECT
Spoofed ACK
TCP ACK
STATEFUL