Code tool

IP Allowlist

Edit and validate an IPv4/IPv6 allowlist locally, detect duplicate networks, and check whether an IP matches. Generate Nginx, Apache, iptables, UFW, nftables, AWS security group, or Cloudflare rule drafts.

In-browser processingNo account requiredPrivacy details ↗

Use IPv4, IPv6, or CIDR (IPv4 /0–32; IPv6 /0–128). Bare IPs become /32 or /128. Host bits are cleared. Private/local hints cover 10/8, 172.16/12, 192.168/16, 127/8, 169.254/16, fc00::/7, fe80::/10 and ::1/128. Hints do not establish that other addresses are publicly routable. Use up to 1,000 rules and 100,000 characters.

Runs only in this browser. Rules are not saved, uploaded, or applied to your system or firewall. No network scans or connectivity checks are performed.

Nginx and Apache snippets restrict access to this list in the context where you place them. Firewall snippets only add TCP allow rules; they require an existing deny policy and do not remove other permits. nftables assumes an existing inet filter input chain. AWS output is an IpPermissions fragment for the selected TCP port, not a complete security group; IPv6 must be enabled for UFW. Cloudflare output is a matching expression: block its negation in a rule you review. Existing policies, rule order and provider limits still apply. Review every draft before use; this page never executes commands or writes cloud configuration.

Enter IP addresses or CIDR networks.

A QUICK WALKTHROUGH

How to use this tool

  1. Enter one allowed IP or CIDR per line.
  2. Optionally enter one IP, then validate and review the report.

Allowed IPs or CIDRs — one per line

Use IPv4, IPv6, or CIDR (IPv4 /0–32; IPv6 /0–128). Bare IPs become /32 or /128. Host bits are cleared. Private/local hints cover 10/8, 172.16/12, 192.168/16, 127/8, 169.254/16, fc00::/7, fe80::/10 and ::1/128. Hints do not establish that other addresses are publicly routable.

Configuration draft

Nginx and Apache snippets restrict access to this list in the context where you place them. Firewall snippets only add TCP allow rules; they require an existing deny policy and do not remove other permits. nftables assumes an existing inet filter input chain. AWS output is an IpPermissions fragment for the selected TCP port, not a complete security group; IPv6 must be enabled for UFW. Cloudflare output is a matching expression: block its negation in a rule you review. Existing policies, rule order and provider limits still apply. Review every draft before use; this page never executes commands or writes cloud configuration.

Validation report

Runs only in this browser. Rules are not saved, uploaded, or applied to your system or firewall. No network scans or connectivity checks are performed.

GOOD TO KNOW

Common questions

Does a matching IP prove access is allowed?

No. This only compares the IP with your list. It does not inspect firewall rules, denied ranges, or live network access.