Home · Business · IT, Data & Security · Cybersecurity
As of 13 August 2026, AI can only partly check your business firewall rules.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededpower-user
Who has to check ita colleague
What the alternative costsA specialist firewall review is the alternative; no price for it is stated in the available tool data.
If this goes wrong, a mistaken finding or rule change can block business traffic or leave an exposed service reachable.
What to actually do
Hand it to a person
The route this page recommends
A person who owns the outcome does this end to end, worth it when the failure is dear.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, power-user skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open the firewall management console and export the current rules, including rule order, source, destination, service, action, schedule and logging settings, without including credentials or secret keys.
- Open the current network diagram, asset list and service documentation, then gather the business purpose of each important connection, including supplier access, remote access, public services and internal administration.
- Redact passwords, API keys, private personal data and unnecessary public IP details from the export, while preserving rule identifiers, ranges, ports, protocols, order and comments.
- Paste the prompt and the redacted export, network notes and relevant denied or allowed traffic examples into an AI chat, then ask it to keep the configuration read-only and separate evidence from assumptions.
- Copy the findings into a review table and compare every claimed conflict or exposure with the original rule order and the firewall manufacturer's current documentation.
- Ask a network or security colleague to confirm the intended traffic flows, investigate every low-confidence finding and reject any recommendation whose operational impact is unclear.
- Test only approved, reversible changes in a non-production path or controlled maintenance window while monitoring allowed traffic, denied traffic and service availability, then record the final decision and approver.
Prompt
Act as a cautious firewall-review assistant, not an administrator. Review the firewall configuration and network context below for security weaknesses, accidental exposure, redundant or shadowed rules, overly broad source or destination ranges, unsafe ports and protocols, ordering problems, missing logging, and rules that appear stale. Do not invent the purpose of a rule, claim that a port is safe without evidence, or recommend deleting or changing a rule without stating the risk and the information needed first. Return: 1. A short summary of the highest-priority findings. 2. A table with rule identifier, observed behaviour, concern, evidence from the supplied text, confidence, and safer next question or action. 3. Possible rule conflicts, including which rule is evaluated first and why. 4. Items that cannot be assessed without live traffic, packet captures, asset ownership, vendor documentation or a network diagram. 5. A reversible validation plan that does not change production, including what to monitor and what would make the test unsafe. 6. A list of questions for the person responsible for the network. Treat the configuration as read-only. Separate observations from assumptions. Do not provide credentials, secrets or personal data in your response. Do not tell me to apply a change until a qualified network or security professional has reviewed it. Firewall platform and version: [platform and version] Environment and business purpose: [brief description] Network diagram or traffic-flow notes: [paste or describe] Firewall rule export: [paste the export] Relevant logs or denied-traffic examples: [paste redacted examples] Known services, suppliers and required traffic: [list] Maintenance and testing constraints: [describe]
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot see undocumented network paths, live traffic, device ownership or the operational effect of a rule unless you provide reliable evidence.
- It cannot establish whether an apparently broad rule is required by a supplier, legacy system or business process.
- It cannot safely validate a proposed change in production or guarantee that rule ordering behaves as expected across your firewall platform.
- It cannot take responsibility for an outage, breach or compliance failure caused by a wrong finding or implementation.
- It cannot replace an experienced reviewer when the configuration, topology or traffic is ambiguous.
What caps this at PARTLY: verification cost, stakes of error and private data access.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 1 |
| Total | 6 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT check my firewall rules?
- Partly. It can analyse a redacted export and flag obvious overlaps, broad permissions, ordering issues and missing information, but it cannot inspect your live network or prove that a rule is safe. Have a network or security colleague verify the findings before any change.
- Can AI tell me which firewall rules to delete?
- No, not reliably from a rule export alone. A rule that looks unused may support a legacy system, supplier or emergency process, so deletion needs traffic evidence, an owner and a reversible test.
- Is it safe to upload my firewall configuration to AI?
- Only after removing credentials, keys, personal data and unnecessary sensitive network details, and only under your organisation's data policy. Treat the output as an untrusted review and do not upload anything your security policy forbids.
- Do I need a cybersecurity professional to review firewall rules?
- For a business firewall, you usually need someone with sufficient network and security expertise to confirm intent, assess exposure and test changes safely. Serious exposure, suspected compromise or high-impact production changes need a qualified cybersecurity professional.
Nearby answers
- Can AI check whether my business meets Cyber Essentials requirements?PARTLY
- Can AI choose cybersecurity software for my business?PARTLY
- Can AI detect phishing emails for my business?PARTLY
- Can AI help me report a data breach to the ICO?PARTLY
- Can AI help me choose and secure a VPN for my business?PARTLY
- Can AI help me set up multi-factor authentication for my business?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.