Input files and options
Your files never leave this device
This tool runs entirely in your browser. The spreadsheets you add are read into memory on this computer, processed here, and the results are handed straight back to you as downloads. Nothing is uploaded, sent or stored, and there is no server behind this page to receive anything.
Verify it yourself
- Watch the network. Press F12, open the Network tab, tick "Preserve log" and reload the page. Every request listed goes to this site's own address. Now add your files and export: no new requests appear, because nothing is sent.
- Run it offline. Wait until the bottom left of this page says "Ready", then disconnect from the network (or choose "Offline" in the Network tab). Add files and export as usual. It keeps working, because all of the processing happens on your device.
- Read the security policy. In the Network tab, select the first request and look at the response headers. The Content-Security-Policy tells your browser to refuse any connection to another site, so even a mistake in this page could not send your data elsewhere.
- Check the build. The Privacy and verification page lists the SHA-256 of every file this site serves and the commit it was built from.
- Prefer no browser at all? The same engine is available as a Windows desktop app on that page, with its checksum.
Traffic exports and firewall logs
Include in firewall ruleset
Output format
The suffix turns hostnames into FQDNs.
Target mapping
Where each server ends up after migration. Rehost = same name, new IP. Replatform = new name and new IP. App servers come from your input files; remote peers are the servers they talk to in the kept flows. Map those too if they are migrating. NSG rules always use the target addresses; a server whose target IP is not known yet shows as "IP TBC (name)".
Select a server above.
Target name is only used for Replatform. Leave the IP blank if it is not known yet.
FW rules preview
Add one or more traffic exports to begin.
NSG rules preview
The same kept flows as Azure NSG rules.
Traffic review
Rows marked in green go into the ruleset. Double-click a row (or use the buttons) to force it in or out; overrides survive re-analysis.
Classification rules
One entry per line. Rules apply to this session only and are never stored by this site. Save them to a file to reuse them here or in the desktop app (it is the same fw_rules_config.json format).
Connection diagram
The application servers and every host they exchange the kept flows with.
Export
Builds the workbook, the Azure CLI script and the connection diagram on this device and offers them as downloads.
Nothing has been exported yet.
Privacy and verification
What this site does with your files, and how to check each claim for yourself.
Your files never leave this device
Files are read into your browser's memory and processed there by a copy of Python running on your own computer. The results are created in memory and handed to you as downloads. Nothing is transmitted and nothing is stored. Closing or reloading the tab discards everything.
- Watch the network. Press F12, open the Network tab, tick "Preserve log" and reload. Every request goes to this site's own address. Add your files and export: no new requests appear.
- Run it offline. Once the bottom left says "Ready", disconnect from the network or choose "Offline" in the Network tab, then add files and export as usual.
- Read the security policy. The Content-Security-Policy response header allows connections to this site only (connect-src 'self'), forbids forms being sent anywhere (form-action 'none') and forbids framing. Your browser enforces it.
- Check what is served. There is no server code, no analytics, no error reporting and no third party script, font or stylesheet. The list below is every file this site serves, with its SHA-256.
- Use the desktop app instead. It runs the same engine with no browser and no network use at all.
This build
- Build
- Loading
Desktop app for Windows
Loading