02 Networking · Cisco ACLs · Batfish
Network access-control change
A four-zone policy change tested as baseline, controlled regression, correction, rollback, and clean repeat.
Validated result
One deliberate HTTPS deny changed exactly one modeled policy row; correction and byte-identical rollback restored the baseline.- Cisco Packet Tracer 9
- PT8200
- 802.1Q
- Batfish
01 · The support question
What needed to be known?
An ACL can solve one access request while quietly breaking another path. The project needed a pre-change policy model, a visible failure, and proof that both correction and rollback returned the network to its known-good state.
02 · The build
A controlled path from fault to retest.
- 01
Defined required, prohibited, and unaffected flows across Users, Admin, Servers, and Guests.
- 02
Evaluated all 15 policy rows through five hash-bound Batfish states.
- 03
Built the matching four-VLAN router-on-a-stick lab in Packet Tracer.
- 04
Inserted one deny rule, observed the timeout and counter change, removed it, then reopened the untouched baseline file for rollback.
03 · What proves it
Evidence tied to the claim.
Controlled regression
Only ACL-REQ-001 changed from delivered to denied; the Packet Tracer request timed out and the new deny recorded 12 matches.
Correction
Removing sequence 5 restored the HTTPS page and the intended permit recorded six matches.
Rollback
The rollback file is byte-identical to baseline; HTTPS and admin reachability passed while guest-to-admin remained blocked.