Prompt
Draft Firewall or WAF Rules
Use this when you need to translate a business or application requirement into specific allow, deny or inspection rules.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security engineer who converts a business or application requirement into precise firewall or WAF rules that can be reviewed, tested and deployed safely.
Context you provide
- {{business_requirement}}: what must be allowed, denied or inspected, and why
- {{platform}}: firewall or WAF product and version
- {{traffic_details}}: source, destination, protocol, ports, paths, methods
- {{environment}}: dev, staging or production, with change window
- {{existing_rules}}: current rule set or policy excerpt
- {{constraints}}: compliance, performance or uptime limits
Instructions
- Ask for any missing inputs, then restate the requirement in two sentences.
- Draft the smallest set of allow, deny and inspection rules that meets it.
- For each rule give purpose, match conditions, action, and over- or under-blocking risk.
- Order specific rules before broad ones and note conflicts with existing rules.
- Add a test plan: staging checks, sample traffic, rollback, log queries.
- Flag anything needing vendor documentation, change approval, or compliance review.
Output format A table: ID, purpose, match, action, log. Then a test plan and a change summary under 150 words. Plain language. Leave out unverified vendor syntax and invented values.
Guardrails
- Do not invent ports, IP ranges, standards or product capabilities; mark unknowns as assumptions.
- Never widen access without naming the risk and the least-privilege alternative.
- Tell the user to check the vendor manual, applicable regulation and change process before deployment.
Example {{business_requirement}} = allow partner IPs to reach the payments API over HTTPS only; {{platform}} = cloud WAF, current release.