Logo

Rule Base

Manage, reorder, and audit your firewall access control list. Rules are evaluated top-to-bottom by priority.

Logo10 rules
0 total hits
No policy conflicts detected. Click "Run Audit" to re-scan after making changes.
Top-to-Bottom Evaluation: Rules are matched in strict priority order. The first matching rule terminates evaluation. Drag rules to reorder. Lower priority number = evaluated first.
LogoRule Base(10 rules)
ALLOW DENY REJECT Drag to reorder
#10
Allow HTTP traffic from WAN to DMZ Web Server
TCP · any:any192.168.100.10:80 · WAN_TO_DMZ
#20
Allow HTTPS traffic from WAN to DMZ Web Server
TCP · any:any192.168.100.10:443 · WAN_TO_DMZ
#30
Allow SMTP traffic from WAN to DMZ Mail Server
TCP · any:any192.168.100.20:25 · WAN_TO_DMZ
#40
Block SSH access to DMZ from WAN (brute-force protection)
TCP · any:anyany:22 · WAN_TO_DMZ
#50
Allow DMZ Web Server to query internal Database Server (MySQL)
TCP · 192.168.100.10:any10.0.0.5:3306 · DMZ_TO_LAN
#60
Block all unauthorized DMZ to LAN lateral movement
ANY · any:anyany:any · DMZ_TO_LAN
#70
Block direct WAN to Database — prevent external DB intrusion
TCP · any:anyany:3306 · WAN_TO_LAN
#80
Reject SSH brute-force to internal LAN — send RST
TCP · any:anyany:22 · WAN_TO_LAN
#90
Block ICMP ping flood/reconnaissance from WAN
ICMP · any:anyany:any · WAN_TO_DMZ
#999
IMPLICIT DEFAULT DENY — catch-all fallback rule
ANY · any:anyany:any · ANY