Agent skill

Configuring Firewalls

by ancoleman in ancoleman/ai-design-components

Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.

MITAuto-check: notesSecurity

Install Configuring Firewalls

skills CLI
$ npx skills add ancoleman/ai-design-components --skill configuring-firewalls -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ancoleman/ai-design-components configuring-firewalls --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/configuring-firewalls .claude/skills/configuring-firewalls && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuring-firewalls
GitHub stars
526
Token cost
~3.5k tokens
SKILL.md length
1,093 words
Files
20 (incl. references)
Skills in repo
75
Repo updated
First seen
Licence
MIT

At a glance

Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.

  • Works in 8 steps: Default Deny: Start with deny-all,… → Principle of Least Privilege: Only open… → No 0.0.0.0/0 on Sensitive Ports: Never… → …
  • Exposing services
  • SKILL.md covers Purpose, When to Use This Skill, Decision Framework: Which… and Quick Start Examples, plus 8 more sections
  • Runs Shell scripts from its folder; calls aws and kubectl

What it does

Configuring Firewalls is an agent skill from ancoleman/ai-design-components. Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts. Use when exposing services, hardening servers, or implementing network segmentation with defense-in-depth strategies.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 25 other files, including reference files (for example `examples/kubernetes/default-deny-allow-dns.yaml`, `examples/ufw/basic-web-server.sh` and `outputs.yaml`).

It sits in Security, covering Cloud security and Secure coding. It works with Amazon Web Services, Google Cloud, Microsoft Azure and Kubernetes. The repository describes itself as: Comprehensive UI/UX and Backend component design skills for AI-assisted development with Claude. The licence is MIT.

When your agent uses it

  • Exposing services
  • Hardening servers
  • Implementing network segmentation with defense-in-depth strategies

Example prompts

  • “/configuring-firewalls”

Requirements

  • A Bash shell

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Default Deny: Start with deny-all, explicitly allow required traffic
  2. Principle of Least Privilege: Only open necessary ports/IPs
  3. No 0.0.0.0/0 on Sensitive Ports: Never allow SSH/RDP/database from anywhere
  4. Version Control: Store firewall rules in Git
  5. Logging: Enable and monitor firewall logs
  6. Regular Audits: Review rules quarterly, remove unused
  7. Don't Mix Tools: Avoid running iptables and nftables simultaneously
  8. Test Before Production: Use staging environment first

What it can do on your machine

Read from SKILL.md and the folder at commit 76551b7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • aws
    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws and kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuring Firewalls loads about 3.5k tokens when it runs, and up to ~45k if it reads all its reference files. Until then it costs about 83 tokens; SKILL.md has 1,093 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~45k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:90
    sudo ufw default deny incoming
  • NoteRuns commands with sudoSKILL.md:91
    sudo ufw default allow outgoing
  • NoteRuns commands with sudoSKILL.md:94
    sudo ufw allow ssh
  • NoteRuns commands with sudoSKILL.md:95
    sudo ufw limit ssh  # Rate-limit to prevent brute force
  • NoteRuns commands with sudoSKILL.md:98
    sudo ufw allow http    # Port 80
  • NoteRuns commands with sudoSKILL.md:99
    sudo ufw allow https   # Port 443
  • NoteRuns commands with sudoSKILL.md:102
    sudo ufw allow from 192.168.1.100 to any port 5432
  • NoteRuns commands with sudoSKILL.md:105
    sudo ufw enable
  • NoteRuns commands with sudoSKILL.md:108
    sudo ufw status verbose
  • NoteRuns commands with sudoSKILL.md:154
    Apply: `sudo nft -f /etc/nftables.conf`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ancoleman/ai-design-components at commit 76551b7, republished under its MIT licence (© ancoleman). 1,093 words, ~3,468 tokens.

Download SKILL.mdSave it as .claude/skills/configuring-firewalls/SKILL.md (or your agent's skills folder). This skill also uses 19 other files; get the full folder from GitHub.
name
configuring-firewalls
description
Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts. Use when exposing services, hardening servers, or implementing network segmentation with defense-in-depth strategies.

Configuring Firewalls

Purpose

Guide engineers through configuring firewalls across host-based (iptables, nftables, UFW), cloud-based (AWS Security Groups, NACLs), and container-based (Kubernetes NetworkPolicies) environments with practical rule examples and safety patterns to prevent lockouts and security misconfigurations.

When to Use This Skill

Trigger Phrases:

  • "Configure firewall for [server/service]"
  • "Set up security groups for [AWS resource]"
  • "Allow port [X] through firewall"
  • "Block IP address [X.X.X.X]"
  • "Set up UFW on Ubuntu server"
  • "Create iptables/nftables rules"
  • "Configure bastion host firewall"
  • "Implement egress filtering"

Common Scenarios:

  • Initial server setup and hardening
  • Exposing a new service (web server, API, database)
  • Implementing network segmentation
  • Creating bastion host or jump box
  • Migrating from iptables to nftables
  • Configuring cloud security groups
  • Troubleshooting connectivity issues

Decision Framework: Which Firewall Tool?

Cloud Environments

AWS:

  • Instance-level control → Security Groups (stateful, allow-only rules)
  • Subnet-level enforcement → Network ACLs (stateless, allow + deny rules)
  • Use both for defense-in-depth

GCP:

  • Use VPC Firewall Rules (stateful, priority-based)

Azure:

  • Use Network Security Groups (NSGs) (stateful, priority-based)
Host-Based Linux Firewalls

Ubuntu/Debian + Simplicity:

  • Use UFW (Uncomplicated Firewall) - recommended for most users
  • Front-end for iptables/nftables with simplified syntax

RHEL/CentOS/Fedora:

  • Use firewalld (default on Red Hat ecosystem)
  • Zone-based configuration with dynamic updates

Modern Distro + Advanced Control:

  • Use nftables (best performance, modern standard)
  • O(log n) performance vs iptables O(n)
  • Unified IPv4/IPv6/NAT syntax

Legacy Systems:

  • Use iptables (migrate to nftables when feasible)
  • Required for older kernels (< 4.14)
Kubernetes/Containers
  • Use NetworkPolicies (requires CNI plugin: Calico, Cilium, Weave)
  • See references/k8s-networkpolicies.md
Stateful vs Stateless

Stateful (recommended for most cases):

  • Automatically allows return traffic
  • Simpler configuration
  • Examples: Security Groups, UFW, nftables default

Stateless (specialized use):

  • Must explicitly allow both directions
  • Fine-grained control, less state tracking
  • Examples: Network ACLs, custom nftables rules

Quick Start Examples

UFW (Ubuntu/Debian)
bash
# 1. Set defaults
sudo ufw default deny incoming
sudo ufw default allow outgoing

# 2. CRITICAL: Allow SSH before enabling (prevent lockout)
sudo ufw allow ssh
sudo ufw limit ssh  # Rate-limit to prevent brute force

# 3. Allow web traffic
sudo ufw allow http    # Port 80
sudo ufw allow https   # Port 443

# 4. Allow from specific IP (e.g., database access)
sudo ufw allow from 192.168.1.100 to any port 5432

# 5. Enable firewall
sudo ufw enable

# 6. Verify rules
sudo ufw status verbose

For complete UFW patterns, see references/ufw-patterns.md

nftables (Modern Linux)
nftables
#!/usr/sbin/nft -f
# /etc/nftables.conf

flush ruleset

table inet filter {
    chain input {
        type filter hook input priority 0; policy drop;

        # Accept loopback
        iif "lo" accept

        # Accept established connections (stateful)
        ct state established,related accept

        # Drop invalid packets
        ct state invalid drop

        # Allow SSH
        tcp dport 22 accept

        # Allow HTTP/HTTPS
        tcp dport { 80, 443 } accept

        # Log dropped packets
        log prefix "nftables-drop: " drop
    }

    chain forward {
        type filter hook forward priority 0; policy drop;
    }

    chain output {
        type filter hook output priority 0; policy accept;
    }
}

Apply: sudo nft -f /etc/nftables.conf Enable on boot: sudo systemctl enable nftables

For advanced patterns (sets, maps), see references/nftables-patterns.md

AWS Security Groups (Terraform)
hcl
# Web server security group
resource "aws_security_group" "web" {
  name        = "web-server-sg"
  description = "Security group for web servers"
  vpc_id      = aws_vpc.main.id

  # Allow HTTP/HTTPS from anywhere
  ingress {
    description = "HTTPS from anywhere"
    from_port   = 443
    to_port     = 443
    protocol    = "tcp"
    cidr_blocks = ["0.0.0.0/0"]
  }

  # Allow SSH from bastion only
  ingress {
    description     = "SSH from bastion"
    from_port       = 22
    to_port         = 22
    protocol        = "tcp"
    security_groups = [aws_security_group.bastion.id]
  }

  # Allow all outbound
  egress {
    from_port   = 0
    to_port     = 0
    protocol    = "-1"
    cidr_blocks = ["0.0.0.0/0"]
  }

  tags = {
    Name = "web-server-sg"
  }
}

For Security Groups vs NACLs guide, see references/aws-security-groups.md

Safety Checklist

Before enabling any firewall:

  • Always allow SSH before enabling (prevent lockout)
  • Test rules before enabling (dry-run when possible)
  • Enable logging for debugging
  • Document rules in version control (Git)
  • Verify externally with nmap: nmap -Pn <server-ip>
  • Have console access (cloud) or physical access (on-prem)
  • Start with default deny, explicitly allow required traffic
  • Use rate limiting for SSH (ufw limit ssh)

Common Patterns

Pattern 1: Basic Web Server

Requirements:

  • Allow HTTP (80) and HTTPS (443) from anywhere
  • Allow SSH from specific IP or bastion only
  • Default deny all other inbound traffic

UFW:

bash
sudo ufw default deny incoming
sudo ufw allow from 203.0.113.0/24 to any port 22  # Office IP
sudo ufw allow http
sudo ufw allow https
sudo ufw enable

nftables: See references/nftables-patterns.md for complete example

AWS Security Group: See references/aws-security-groups.md for Terraform module

Pattern 2: Database Server (Private)

Requirements:

  • Allow database port (5432, 3306, etc.) from app tier only
  • No public internet access
  • SSH from bastion only

See references/database-patterns.md for implementation

Pattern 3: Bastion Host (Jump Box)

Purpose: Single hardened entry point for SSH access

See references/bastion-pattern.md for complete implementation

Pattern 4: Egress Filtering

Purpose: Control outbound traffic to prevent data exfiltration

See references/egress-filtering.md for implementation

Key Concepts

Stateful Firewalls

Track connection state (established, related, new):

  • Automatically allow return traffic
  • Simpler rule configuration
  • Used by: Security Groups, UFW, nftables (default)
Stateless Firewalls

No connection tracking:

  • Must explicitly allow both directions
  • Must allow ephemeral ports (1024-65535) for return traffic
  • Used by: Network ACLs
Defense-in-Depth

Layer multiple firewall controls:

  • Cloud: Security Groups + NACLs
  • Host: UFW/nftables + fail2ban
  • Container: NetworkPolicies
Rule Evaluation

Security Groups (AWS): All rules evaluated, most permissive wins Network ACLs (AWS): Sequential evaluation, first match wins nftables/iptables: Sequential, first match wins UFW: Sequential by rule number

Universal Best Practices

  1. Default Deny: Start with deny-all, explicitly allow required traffic
  2. Principle of Least Privilege: Only open necessary ports/IPs
  3. No 0.0.0.0/0 on Sensitive Ports: Never allow SSH/RDP/database from anywhere
  4. Version Control: Store firewall rules in Git
  5. Logging: Enable and monitor firewall logs
  6. Regular Audits: Review rules quarterly, remove unused
  7. Don't Mix Tools: Avoid running iptables and nftables simultaneously
  8. Test Before Production: Use staging environment first
Show full SKILL.md (444 more words)Show less

Advanced Topics

Bastion Host Architecture: See references/bastion-pattern.md for single entry point patterns

DMZ (Demilitarized Zone): See references/dmz-pattern.md for network segmentation

Egress Filtering: See references/egress-filtering.md for outbound traffic control

Kubernetes NetworkPolicies: See references/k8s-networkpolicies.md for pod-to-pod isolation

Migrating iptables to nftables: See references/migration-guide.md for conversion process

Cloud Firewall Comparisons:

  • AWS: references/aws-security-groups.md
  • GCP: references/gcp-firewall.md
  • Azure: references/azure-nsg.md

Troubleshooting

"I locked myself out via SSH":

  • Cloud: Use console/session manager to access
  • On-prem: Physical console access or IPMI/iLO
  • Prevention: Always allow SSH before enabling firewall

Connection timeouts:

  • Check if firewall is blocking traffic: sudo ufw status or sudo nft list ruleset
  • Verify service is listening: ss -tuln | grep <port>
  • Test externally: nmap -Pn <ip> -p <port>
  • Check logs: /var/log/ufw.log or journalctl -u nftables

AWS: Ephemeral port issues:

  • NACLs need return traffic: Allow 1024-65535 inbound
  • Security Groups are stateful (no ephemeral config needed)

Kubernetes pods can't communicate:

  • Check NetworkPolicies: kubectl get networkpolicies -n <namespace>
  • Verify CNI plugin supports NetworkPolicies (Calico, Cilium)
  • Test without policies first

For complete troubleshooting guide, see references/troubleshooting.md

Common Mistakes to Avoid

❌ Allowing 0.0.0.0/0 on SSH/RDP → Use bastion or VPN ❌ Forgetting to enable firewall → Rules configured but not active ❌ Not testing before enabling → Risk of lockout ❌ Missing ephemeral ports in NACLs → Return traffic blocked ❌ Running iptables + nftables → Conflicts and unpredictable behavior ❌ No logging → Can't debug or audit ❌ Large port ranges → Unnecessary attack surface ❌ Not documenting rules → Future confusion

Tool-Specific Commands

UFW
bash
# Status
sudo ufw status verbose
sudo ufw status numbered

# Add rules
sudo ufw allow <port>/<protocol>
sudo ufw allow from <ip> to any port <port>
sudo ufw limit ssh  # Rate limiting

# Delete rules
sudo ufw delete <rule-number>
sudo ufw delete allow 80/tcp

# Logging
sudo ufw logging on
tail -f /var/log/ufw.log

# Reset (disable and remove all rules)
sudo ufw reset
nftables
bash
# List ruleset
sudo nft list ruleset

# Load config
sudo nft -f /etc/nftables.conf

# Flush all rules
sudo nft flush ruleset

# Add rule dynamically
sudo nft add rule inet filter input tcp dport 8080 accept

# Enable on boot
sudo systemctl enable nftables
iptables
bash
# List rules
sudo iptables -L -v -n
sudo iptables -L INPUT --line-numbers

# Add rule
sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT

# Delete rule
sudo iptables -D INPUT <rule-number>

# Save rules
sudo netfilter-persistent save  # Debian/Ubuntu
sudo service iptables save      # RHEL/CentOS
AWS CLI
bash
# List security groups
aws ec2 describe-security-groups --group-ids sg-xxxxx

# List NACLs
aws ec2 describe-network-acls --network-acl-ids acl-xxxxx

# Add rule to security group
aws ec2 authorize-security-group-ingress \
  --group-id sg-xxxxx \
  --protocol tcp \
  --port 443 \
  --cidr 0.0.0.0/0

For infrastructure as code approach, use Terraform (see references/aws-security-groups.md)

Examples Directory

Complete working examples available in:

  • examples/ufw/ - UFW configuration scripts
  • examples/nftables/ - nftables rulesets
  • examples/iptables/ - iptables rule scripts
  • examples/terraform-aws/ - AWS Security Groups and NACLs
  • examples/terraform-gcp/ - GCP firewall rules
  • examples/terraform-azure/ - Azure NSGs
  • examples/kubernetes/ - NetworkPolicy manifests

Integration Points

Related Skills:

  • security-hardening - Firewalls are one component of server hardening. See security-hardening skill for SSH hardening, fail2ban, auditd, and SELinux.

  • building-ci-pipelines - CI runners need network access to repos and artifact stores. Configure firewall rules for self-hosted runners.

  • deploying-applications - Applications need firewall rules for service exposure. See deploying-applications for integration.

  • infrastructure-as-code - Manage firewalls as code with Terraform/CloudFormation. See infrastructure-as-code for IaC best practices.

  • kubernetes-operations - Advanced K8s networking beyond basic NetworkPolicies. See kubernetes-operations for Services, Ingress, and CNI configuration.

  • network-architecture - Broader network design patterns. See network-architecture for VPC design, subnets, and routing.

Reference Files

Tool-Specific Guides:

  • references/ufw-patterns.md - Complete UFW guide with examples
  • references/nftables-patterns.md - nftables syntax, sets, maps, logging
  • references/iptables-patterns.md - iptables basics and migration path
  • references/migration-guide.md - Convert iptables to nftables

Cloud Provider Guides:

  • references/aws-security-groups.md - Security Groups vs NACLs with Terraform
  • references/gcp-firewall.md - GCP VPC firewall rules
  • references/azure-nsg.md - Azure Network Security Groups

Advanced Patterns:

  • references/bastion-pattern.md - Jump box architecture
  • references/dmz-pattern.md - Network segmentation with DMZ
  • references/egress-filtering.md - Outbound traffic control
  • references/k8s-networkpolicies.md - Kubernetes pod isolation

Support:

  • references/troubleshooting.md - Common issues and solutions
  • references/decision-tree.md - Visual guide for tool selection

© ancoleman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 19 other files (references) in skills/configuring-firewalls of ancoleman/ai-design-components.

  • SKILL.md
  • examples/kubernetes/default-deny-allow-dns.yaml
  • examples/nftables/web-server.nft
  • examples/terraform-aws/three-tier-architecture.tf
  • examples/ufw/basic-web-server.sh
  • outputs.yaml
  • references/aws-security-groups.md
  • references/azure-nsg.md
  • references/bastion-pattern.md
  • references/database-patterns.md
  • references/decision-tree.md
  • references/dmz-pattern.md
  • references/egress-filtering.md
  • references/gcp-firewall.md
  • references/iptables-patterns.md
  • … and 5 more

Open the folder on GitHubat commit 76551b7

Compare with similar skills

Configuring Firewalls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuring Firewalls compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuring Firewalls this skillancoleman/ai-design-components526—~3.5kAutomated safety check: NotesMIT
Cloud AuditCommonHuman-Lab/nyxstrike157—~1.1kAutomated safety check: PassCustom licence
Agent Bom Scan InfraLeoYeAI/openclaw-master-skills2.2k—~1.5kAutomated safety check: PassApache-2.0
Cloud Auditbriiirussell/cybersecurity-skills413—~1.3kAutomated safety check: NotesMIT
Auditing Cloud With Cis Benchmarksmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0

Similar skills

  • Cloud Audit

    CommonHuman-Lab/nyxstrike

    Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images

    157 GitHub stars~1.1k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Agent Bom Scan Infra

    LeoYeAI/openclaw-master-skills

    Scan infrastructure-as-code, cloud configurations, and find secrets.

    2.2k GitHub stars~1.5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Auditing Cloud With Cis Benchmarks

    mukul975/Anthropic-Cybersecurity-Skills

    Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Cloud Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hardening Cloud Posture

    trilwu/secskills

    Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…

    157 GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from ancoleman/ai-design-components

All 75 skills in this repo
  • Building AI Chat

    ancoleman/ai-design-components

    Builds AI chat interfaces and conversational UI with streaming responses, context management, and multi-modal support.

    526 GitHub stars~3.4k tokensUpdated 10 mo ago
    Auto-check passed
  • Building Forms

    ancoleman/ai-design-components

    Builds form components and data collection interfaces including contact forms, registration flows, checkout processes, surveys, and settings pages.

    526 GitHub stars~3.7k tokensUpdated 10 mo ago
    Auto-check passed
  • Building Tables

    ancoleman/ai-design-components

    Builds tables and data grids for displaying tabular information, from simple HTML tables to complex enterprise data grids.

    526 GitHub stars~1.8k tokensUpdated 10 mo ago
    Auto-check passed
  • Creating Dashboards

    ancoleman/ai-design-components

    Creates comprehensive dashboard and analytics interfaces that combine data visualization, KPI cards, real-time updates, and interactive layouts.

    526 GitHub stars~3.5k tokensUpdated 10 mo ago
    Auto-check passed
  • Designing Layouts

    ancoleman/ai-design-components

    Designs layout systems and responsive interfaces including grid systems, flexbox patterns, sidebar layouts, and responsive breakpoints.

    526 GitHub stars~1.7k tokensUpdated 10 mo ago
    Auto-check passed
  • Displaying Timelines

    ancoleman/ai-design-components

    Displays chronological events and activity through timelines, activity feeds, Gantt charts, and calendar interfaces.

    526 GitHub stars~2.7k tokensUpdated 10 mo ago
    Auto-check passed

Questions about Configuring Firewalls

What does Configuring Firewalls do?

Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts. Configuring Firewalls is an agent skill from ancoleman/ai-design-components. Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.

When should I use Configuring Firewalls?

Configuring Firewalls fits situations like: exposing services; hardening servers; implementing network segmentation with defense-in-depth strategies.

How do I install Configuring Firewalls in Claude Code?

Run `npx skills add ancoleman/ai-design-components --skill configuring-firewalls -a claude-code`. Or copy the skill folder (skills/configuring-firewalls in ancoleman/ai-design-components) into .claude/skills/configuring-firewalls in your project. Claude Code loads it when a task matches its description.

How do I install Configuring Firewalls in Codex?

Run `npx skills add ancoleman/ai-design-components --skill configuring-firewalls -a codex`. Or copy the skill folder (skills/configuring-firewalls in ancoleman/ai-design-components) into .agents/skills/configuring-firewalls in your project. Codex loads it when a task matches its description.

Can I use Configuring Firewalls in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ancoleman/ai-design-components --skill configuring-firewalls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuring-firewalls, .gemini/skills/configuring-firewalls, .github/skills/configuring-firewalls and .opencode/skills/configuring-firewalls in your project.

What does Configuring Firewalls need to run?

Going by SKILL.md and its folder, Configuring Firewalls needs a shell for the scripts in its folder and the command-line tools its instructions call (aws and kubectl). Our summary lists: A Bash shell.

Does Configuring Firewalls access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Configuring Firewalls safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Configuring Firewalls use?

Configuring Firewalls is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuring Firewalls use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 41k tokens, read only when the agent opens those files.

What are the alternatives to Configuring Firewalls?

Skills that share tags, products or a category with Configuring Firewalls: Cloud Audit (CommonHuman-Lab/nyxstrike, 157 stars), Agent Bom Scan Infra (LeoYeAI/openclaw-master-skills, 2.2k stars), Cloud Audit (briiirussell/cybersecurity-skills, 413 stars) and Auditing Cloud With Cis Benchmarks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuring Firewalls?

ancoleman (a GitHub user) maintains it in ancoleman/ai-design-components, which has 526 GitHub stars. The repository holds 75 skills in this directory. The repository was last updated on December 11, 2025.

Source: ancoleman/ai-design-components on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.