The AI firewall rule builder turns a plain description of your policy into the exact rules for your firewall, in the order to apply them. It supports CSF, firewalld, nftables, iptables, UFW and Windows Defender Firewall through PowerShell.
AI answers can be wrong. Read every command before you run it, and test on a non-production server first. Your input is sent to our AI provider (srvScripts AI) to write the answer. srvScripts does not log your input; the answer, which can quote it, is cached for 24 hours so a repeat question is answered instantly. See the privacy policy.
Table of Contents
Firewall changes are where admins lock themselves out, so every answer puts the allow rule for your own access first, keeps your session open and gives a timed rollback or CSF testing mode before anything that could cut SSH or RDP.
How to use the AI firewall rule builder
- Pick your firewall.
- Describe what to allow and block, one rule per line: ports, source ranges, directions and exceptions.
- Press Build rules and apply them in the order shown, keeping a second session open.
What you get
- The rules or commands in a code block, in order.
- How to make them persistent across reboots.
- Commands to list and verify the active rules, and how to roll back.
Worked example
Example: “Allow SSH on port 2222 only from our office range, open web ports to everyone and block outgoing SMTP except for the mail server.” For firewalld the builder creates a rich rule for the office range first, opens http and https, removes the default ssh service, and adds a direct rule for outbound port 25 — with a timed rollback in case the new rules cut your session.
Tips for better answers
- Use CIDR ranges for office or VPN networks rather than single IPs that change.
- If a blocked IP is your own customer, check it with the IP blacklist checker before banning it.
Related guides: CSF on AlmaLinux 10 with nftables, replace CSF with firewalld and fail2ban and Windows Firewall with Group Policy.
Privacy and limits
Before anything is sent, srvScripts removes private keys, passwords, tokens and API keys it recognises. With the box ticked it also swaps public IP addresses and e-mail addresses for placeholders, which lowers the risk when you paste real logs. The masking is automatic and best effort: it can miss names, hostnames, keys or other customer details, so remove anything confidential before you paste. Your text goes to our AI provider only to write the answer. srvScripts does not save your input as a record of its own, but the masked input is sent to the AI provider to produce the answer, and the answer, which can quote parts of your input, is cached on our server for 24 hours so a repeat question is answered instantly, and is then deleted. The provider’s own API data terms apply to what it receives. Without an account you get 5 runs a day, a free account gets 15 and srvScripts Pro 200, with larger inputs.
At a glance


Official documentation: firewalld documentation, nftables wiki, NetSecurity PowerShell module.
Frequently asked questions
Can the AI firewall rule builder convert CSF rules to firewalld?
Yes. Paste your csf.allow or csf.conf port lines and ask for the firewalld equivalent.
Will it stop me locking myself out?
It orders rules to keep your access and gives a rollback, but always keep a console or second session available.
Does it support IPv6?
Yes. Mention IPv6 ranges and it writes the matching rules.