Firewall Rule Optimizer
Optimize and analyze firewall rules for conflicts and redundancies.
Last reviewed by the Radiatus Cloud team
One rule per line.
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
Rulesets rot, and order matters
Firewall rules are evaluated in order, and over time a ruleset accumulates rules that shadow one another, contradict one another, or repeat one another. A permit that can never be reached because a deny above it matches first is a latent bug; two rules that do the same thing are clutter that hides intent. This tool analyses a pasted ruleset for conflicts and redundancies so you can clean it up.
The three problems it looks for
Shadowing is when an earlier rule fully covers a later one, so the later rule never fires; that later rule is either dead or a sign the order is wrong. Redundancy is two rules with the same effect, where one can go. Contradiction is a permit and a deny for overlapping traffic, where which one wins depends on order and is easy to get backwards. Naming which rules fall into each category turns a wall of rules into a short fix list.
Cleaner rules are safer rules
A ruleset you can read is a ruleset you can trust. Removing dead and duplicate rules and resolving contradictions makes the real policy visible, which is what lets you spot the genuine gaps. Paste your rules as source, destination, port and action; the analysis runs in your browser and nothing is uploaded.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
What is a shadowed rule?
A rule that can never fire because an earlier rule already matches all its traffic. It is either dead weight or a sign the rule order is wrong.
What counts as a redundant rule?
Two rules with the same effect on the same traffic. One of them can be removed without changing behaviour.
What is a rule conflict?
A permit and a deny that both match overlapping traffic. Which one wins depends on their order, which is a common source of subtle mistakes.
What format should I paste the rules in?
As rows of source, destination IP, destination port and action, which the analyser reads to compare rules against one another.
Is my ruleset uploaded?
No. The analysis runs entirely in your browser.
Privacy & Security
Analysis done locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.