Gary VirkIT support / infrastructure
← All work

02 Networking · Cisco ACLs · Batfish

Network access-control change

A four-zone policy change tested as baseline, controlled regression, correction, rollback, and clean repeat.

Validated result

One deliberate HTTPS deny changed exactly one modeled policy row; correction and byte-identical rollback restored the baseline.
  • Cisco Packet Tracer 9
  • PT8200
  • 802.1Q
  • Batfish
15Policy rows per state
05Evaluated states
03Packet Tracer checks

What needed to be known?

An ACL can solve one access request while quietly breaking another path. The project needed a pre-change policy model, a visible failure, and proof that both correction and rollback returned the network to its known-good state.

A controlled path from fault to retest.

  1. 01

    Defined required, prohibited, and unaffected flows across Users, Admin, Servers, and Guests.

  2. 02

    Evaluated all 15 policy rows through five hash-bound Batfish states.

  3. 03

    Built the matching four-VLAN router-on-a-stick lab in Packet Tracer.

  4. 04

    Inserted one deny rule, observed the timeout and counter change, removed it, then reopened the untouched baseline file for rollback.

Four-zone access-control topology connecting users, admin, servers, and guests through a router
Published topology · four VLANs · policy applied at the routed boundary

Evidence tied to the claim.

01

Controlled regression

Only ACL-REQ-001 changed from delivered to denied; the Packet Tracer request timed out and the new deny recorded 12 matches.

02

Correction

Removing sequence 5 restored the HTTPS page and the intended permit recorded six matches.

03

Rollback

The rollback file is byte-identical to baseline; HTTPS and admin reachability passed while guest-to-admin remained blocked.