Some general examples:
* Does firewall 1 accept a subset of the packets accepted by firewall 2?
* Does firewall 1 accept the same set of packets as firewall 2?
* Does this firewall accept some arbitrary set of packets? (useful for proving implementation of security rules)
* Do any of the firewall rules overlap?
* Do any of the firewall rules conflict?
Z3 will also provide examples or counter-examples to the above true/false questions. I like to think of Z3 as an Oracle. You give it a bunch of statements describing what you're looking for, and it magically spits out an answer.
Just curious: Have you encountered rules that cannot be cast into predicate logic framework in Z3?
On the network firewall rules (at multi-tenant Azure, I presume), what were Z3's runtimes look like?