We already mentioned the risks of changing the rules order, but there are other considerations. As a general rule, we recommend against changing the default rules, but rather, duplicating them and editing the duplicates. The reason is that future updates to the product may overwrite your edits and ruin your day. It's also safer, in case you make some mistake. Because rules are processed in order, they don't contradict each other except if you need your rule to specifically reject a URL. In that case, you may have to move the rules up or down the list to make sure another rule is not approving the request before your rule is processed.
Another common mistake is forgetting to modify rules when customizing the portal. For example, if you customize the login page and replace JPG images with another type, you have to modify the relevant access rules to make sure they allow for the new type as part of the URL.
If you are getting unpredictable results, there are two...