📁 Other
pfSense Firewall Rule Map from Config Inventory (No Invented Packet Counts)
Turn a pfSense config inventory into a firewall rule map only. No invented packet counts, connection rates, or latency claims beyond the inventory.
0Reviews
Prompt
Act as a pfSense firewall configuration specialist who only uses a pasted config inventory. You write a firewall rule map the inventory already supports. You do not invent packet counts, connection rates, latency claims, or throughput Mbps. This is not a live pfSense API call and not a penetration test. You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs. Inputs: - Config inventory I lock (interface stubs, rule cues, alias notes): [Inventory] - pfSense / version notes I lock: [Version] - Firewall or site label I may quote (or UNKNOWN): [Workspace] - Required interface or rule names I may quote (or UNKNOWN): [SpecNames] - Words I must not use: [Banned] - What I must never invent (packet counts, connection rates, latency claims, throughput Mbps): [Never] - Output format: [Format] - Language: [Lang] Generate: 1. Honesty ledger: Inventory nouns, Version, Workspace, SpecNames, Lang. Forbidden: invented packet counts, connection rates, latency claims, throughput Mbps. Banner: not a live pfSense API call; not a penetration test. 2. Firewall rule map table: one row per Inventory interface stub or rule cue. Missing alias notes write NOT IN INPUTS. Use pfSense Interfaces, Firewall Rules, Aliases, and NAT language when Inventory supports it. 3. Spec name set: only names in SpecNames. Unnamed interfaces stay NOT IN INPUTS. Never print packet-count or throughput VALUES not in Inventory. 4. Version lock: print Version. Refuse pfSense features newer than Version if Version is named. 5. Refuse list: inventing packet counts, inventing connection rates, inventing latency claims, inventing throughput Mbps. 6. Compliance pass: quote Banned and Never hits. Cut them. Format as Format. Constraints: - Map from Inventory only. No invented packet-count VALUES. Teach pfSense firewall rule mapping, not a generic router-UI swap. - Honor Version. No emojis.
Instructions
Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.
Generated Output
This image was generated using the prompt above.

Examples
Example Input
Inventory: interface Harbor Quay Berth LAN as pasted rule cue pass TCP 443 from LAN net as pasted alias note berth_hosts as pasted; interface River Ops Gate WAN as pasted rule cue block RFC1918 inbound as pasted. Packet count NOT IN INPUTS. Throughput NONE. Version: pfSense CE 2.7 as pasted (do not invent unreleased AI firewall APIs) Workspace: Harbor Quay pfSense Site as pasted SpecNames: Berth LAN as pasted; Gate WAN as pasted. Tide OPT1 UNKNOWN. Banned: guaranteed packet count, connection invent, latency invent, throughput invent Never: invent packet counts, invent connection rates, invent latency claims, invent throughput Mbps Format: ledger + table + specs + version + refuse + compliance Lang: English
Example Output
1. Ledger. Inventory: interface Harbor Quay Berth LAN rule cue pass TCP 443 from LAN net alias note berth_hosts; interface River Ops Gate WAN rule cue block RFC1918 inbound. Packet count NOT IN INPUTS. Throughput NONE. Version pfSense CE 2.7. Workspace Harbor Quay pfSense Site. SpecNames Berth LAN; Gate WAN; Tide OPT1 UNKNOWN. Lang English. Banner: not a live pfSense API call; not a penetration test. Forbidden: invented packet counts, connection rates, latency claims, throughput Mbps, guaranteed packet count, connection invent, latency invent, throughput invent. 2. Firewall rule map. 1. Harbor Quay Berth LAN | rule pass TCP 443 from LAN net as pasted | alias berth_hosts as pasted | packet count NOT IN INPUTS | throughput NONE | pfSense firewall rule map only. 2. River Ops Gate WAN | rule block RFC1918 inbound as pasted | alias NOT IN INPUTS | packet count NOT IN INPUTS | throughput NONE. Connection rates not printed. Latency claims not invented. 3. Spec name set. Berth LAN; Gate WAN as SpecNames. Tide OPT1 UNKNOWN so write Tide OPT1 NOT IN INPUTS. No packet-count VALUES printed. No third interface invented. 4. Version lock. pfSense CE 2.7 as pasted. Unreleased AI firewall APIs not used. Floating rule schema NOT IN INPUTS. 5. Refuse. Packet invent: refused. Connection invent: refused. Latency invent: refused. Throughput invent: refused. Guaranteed packet count: refused. 6. Compliance. Banned hits none. Format ledger+table+specs+version+refuse+compliance. Gaps: alias for River Ops Gate WAN, Tide OPT1 decision, NAT mappings, schedule, gateway groups if any. Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.