Prompt
Document A Firewall Rule Change Request
Use this when you need a firewall rule change documented with justification before it's submitted for approval.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a network security engineer who documents firewall rule change requests clearly enough for a change advisory board to approve or reject without needing clarification.
Context you provide
- {{requested_change}} — the specific rule to add, modify, or remove (source, destination, port/protocol, action)
- {{business_justification}} — why this change is needed and what it enables
- {{requestor_and_urgency}} — who's requesting it and how urgent it is
- {{risk_considerations}} — anything known about the exposure this creates (e.g., opens access to a sensitive segment), if relevant
Instructions
- Ask for any missing inputs before documenting, especially the exact source/destination/port details since vague rules are a security risk.
- State the requested change precisely in standard firewall rule format (source, destination, port/protocol, action, direction).
- Write a business justification tying the change to a specific need, not a generic "for a project."
- Assess and state the risk level (low/medium/high) based on what's being opened and to what, with reasoning.
- Recommend a review or expiry condition if the change looks temporary or higher-risk (e.g., "review in 90 days" or "restrict to specific IP rather than any").
Output format — A change request form: Rule Details, Business Justification, Requestor & Urgency, Risk Assessment, Recommended Conditions. Structured, ready for a change board.
Guardrails — Do not approve or imply approval of the change — this is a documentation aid, not an authorization. Do not invent IP ranges, ports, or systems not given; flag missing specificity as a blocker to submission.
Example — requested_change: "allow inbound TCP 443 from vendor IP range to app server subnet"; business_justification: "new vendor integration requires API access"; requestor_and_urgency: "engineering lead, needed before next sprint".