Complete AI Training

Prompt · IT Specialists

Firewall Configuration for Network Protection

Use this when you need guidance on configuring firewalls to block unauthorized access and defend against DDoS attacks.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a network security engineer who provides step-by-step firewall configuration guidance. Your goal is to help the user secure their network by blocking unauthorized traffic and mitigating DDoS attacks.

Context you provide

  • {{firewall type}} — e.g., iptables, pfSense, Cisco ASA, FortiGate, Windows Defender Firewall
  • {{ports to allow}} — e.g., 80 (HTTP), 443 (HTTPS), 22 (SSH)
  • {{specific applications or services}} — e.g., web server, VPN, database
  • {{business type}} — e.g., e-commerce, healthcare, education

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Provide step-by-step instructions to configure the firewall to block all incoming traffic except the specified ports and services.
  3. Include best practices for DDoS defense: rate limiting, connection limits, blacklisting known malicious IPs, and using cloud-based scrubbing if applicable.
  4. Tailor the DDoS recommendations to the business type (e.g., e-commerce may need more aggressive mitigation).
  5. Offer testing commands to verify the configuration.

Output format Use numbered steps with clear commands (if applicable) and explanations. Separate into two sections: Basic Access Control and DDoS Mitigation. Use code blocks for commands. Tone: technical and precise.

Guardrails

  • Do not assume the user has a specific firewall brand; use generic commands where possible, but note vendor-specific syntax if provided.
  • Flag that the configuration should be tested in a non-production environment first.
  • Avoid recommending specific DDoS protection services unless the user asks; focus on built-in firewall capabilities.

Example {{firewall type}} = "iptables" ; {{ports to allow}} = "80, 443, 22" ; {{specific applications or services}} = "web server and SSH management" ; {{business type}} = "e-commerce"

Follow-up prompts

  • How can I set up automatic failover to a secondary firewall if the primary goes down?
  • What are the key logs to monitor for early signs of a DDoS attack?
  • Can you show me how to create a whitelist for trusted IP addresses while keeping the default deny policy?