Nobody can tell from the diff alone. Rebuild the devices the change touches on the same network OS, apply the change there and compare the device output before and after: routing table, neighbours, the prefixes you expect and the ones you do not. Take the verified commands and both outputs into the change window as the rollback evidence. With NetPilot connected in ChatGPT, Claude or Meta Muse, you ask the assistant to build the devices, apply the change and show the before and after, and it runs the commands on real Cisco, Arista, Juniper, Nokia, SONiC or FRR images in your own lab VM.
Name the devices the change touches
Two or three devices is usually enough: the one you edit and the neighbours whose state can move. Give the assistant their network OS and the current configs, pasted with the secrets removed, or describe them. It designs the matching topology and deploys it on your lab VM with containerlab.
Capture the before state
Ask for the routing table, the neighbour summary and the prefixes on each device. The assistant runs the show commands on the real devices and quotes the output. This is the baseline the change is judged against.
Apply the change
Paste the exact lines you plan to push in the window. The assistant applies them to the lab devices, nothing else, and tells you if a line is rejected by that OS version.
Capture the after state with the same commands
Same commands, same devices. The difference between the two outputs is the whole effect of the change: a prefix that disappeared, a neighbour that reset, a next hop that moved. If something moved that should not have, you found it here.
Carry both outputs into the window
The before output is the rollback target, the after output is what success looks like, and the command list is the verification script. Run the same commands on the production devices after the push and compare.
Say this to the assistant
Build R1 and R2 on Cisco IOL with the configs I pasted. Run show ip bgp summary and show ip route bgp on R1. Then apply the inbound prefix-list on R1 toward R2, clear the session soft inbound, run the same two commands again and show me both outputs side by side.
An inbound prefix-list on R1 is meant to drop one prefix from the peer and leave the rest alone. The same two commands, run before and after, say whether it did exactly that. Here the prefix count on the session goes from 3 to 2, the one prefix is gone from the routing table, and the session never reset, since Up/Down kept counting.
R1# show ip bgp summary BGP router identifier 10.255.0.1, local AS number 65001 Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 10.0.12.2 4 65002 48 46 7 0 0 00:41:17 3 R1# show ip route bgp B 10.20.0.0/24 [20/0] via 10.0.12.2, 00:41:17 B 10.30.0.0/24 [20/0] via 10.0.12.2, 00:41:17 B 10.99.0.0/16 [20/0] via 10.0.12.2, 00:41:17
R1# show ip bgp summary BGP router identifier 10.255.0.1, local AS number 65001 Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 10.0.12.2 4 65002 52 49 8 0 0 00:44:03 2 R1# show ip route bgp B 10.20.0.0/24 [20/0] via 10.0.12.2, 00:44:03 B 10.30.0.0/24 [20/0] via 10.0.12.2, 00:44:03
Run the same set before and after. The assistant knows the syntax for each network OS, so you can say "show me the BGP neighbours on every device" and read the per-vendor output it quotes.
| Network OS | Commands to run before and after |
|---|---|
| Cisco IOS (IOL) | show ip bgp summaryshow ip routeshow ip ospf neighbor |
| Arista EOS (cEOS) | show ip bgp summaryshow ip routeshow bgp evpn summary |
| Juniper Junos (cRPD) | show bgp summaryshow routeshow ospf neighbor |
| Nokia SR Linux | show network-instance default protocols bgp neighborshow network-instance default route-table |
| SONiC | show ip bgp summaryshow ip routeshow vxlan tunnel |
| FRR | vtysh -c "show ip bgp summary"vtysh -c "show ip route" |
Ask for the comparison as a table and the assistant lays the before and after side by side per check, with the line that changed called out. The same report from the NetPilot web app, for an iBGP change on a branch router, looks like this.
The method in full: mirror lab, pre and post snapshot, the diff a change board signs off on.
Three worked experiments with the before command, the change and the after output.
The smallest topology that shows the symptom, the configs and the commands whose output is wrong.
BGP, ACL and routing change validation patterns, with the commands.
How to connect, what the tools do, which plan is needed, lab credits and the idle timeout.
What each plan includes, with lab credits and idle timeouts.
Create a NetPilot account, pick Pro or above, and connect NetPilot in ChatGPT, Claude or Meta Muse.