NetworkFirewallSimulator.
Drop packets into a real rule engine. See exactly which ACL rule matches, how stateful sessions get tracked, and why your DMZ isn't as isolated as you think.
10
ACL Rules
3
Network Zones
∞
Injections
OWASP ALIGNED
How it works
ARCHITECTURE
DMZ Isolation
Three-zone segmentation: WAN → DMZ → LAN with dual firewall gates.
ENGINE
Stateful Inspection
Bidirectional session tracking. Return traffic auto-permitted via state table.
RULESET
Sequential ACL
Top-to-bottom rule evaluation. First match terminates. Priority is everything.
AUDIT
Conflict Auditor
Auto-detect shadowed rules, redundant policies, insecure DMZ bypasses.
LOGGING
SIEM Syslog
Color-coded real-time log feed with ms-precision event timestamping.
SECURITY
Default Deny
Fail-closed posture. Unknown traffic silently blocked by implicit deny.
Quick Attack Presets
Test These Scenarios
Each preset describes a real packet: source IP, destination port, protocol flags. The engine evaluates it against the ACL and returns ALLOW, DENY, or REJECT.
HTTP → DMZ
:80 TCP SYN
→ ALLOW
DB Intrusion
:3306 TCP SYN
→ DENY
SSH Brute
:22 TCP SYN
→ REJECT
Spoofed ACK
TCP ACK
→ STATEFUL