How do I test a route-map, ACL or OSPF cost change before I push it?

A policy change is a two-command experiment: capture the state, apply, capture again. Build the two or three routers involved with their current configs, run show ip bgp or show ip route and the neighbour summary, apply the route-map, prefix-list, ACL or interface cost, and run the same commands. The difference is the change's whole effect. In ChatGPT, Claude or Meta Muse with NetPilot connected, the assistant builds the routers, keeps the exact commands and quotes both outputs, so the same commands verify the change on the production devices during the window.

The experiment, in four steps

  1. 1

    Build only the routers the policy touches

    The router you edit plus one neighbour on each side is enough to see the effect. Give the assistant their current configs and it deploys them on real images in your lab VM.

  2. 2

    Run the before commands

    One command for the state the policy acts on (the BGP table, the route, the interface cost, the ACL counters) and one for the neighbour. The assistant quotes the output.

  3. 3

    Apply the exact lines

    Paste the route-map, prefix-list, access-list or interface line as you will push it. For a BGP policy, follow with a soft clear so the policy is re-evaluated without resetting the session.

  4. 4

    Run the same commands again

    Read the two outputs next to each other. The lines that differ are the change. Anything else that moved is a side effect you now know about before the window.

Say this to the assistant

Build R1, R2 and R3 on Cisco IOL in a triangle running OSPF area 0, with a loopback 10.3.0.1/24 on R3. On R1 run show ip ospf interface brief and show ip route 10.3.0.0. Then set ip ospf cost 50 on R1 GigabitEthernet0/2, run the same two commands and show me both outputs.

Route-map: stop advertising one prefix

R1 advertises two prefixes to AS 65002 and the change is an outbound route-map that keeps 10.99.0.0/16 inside. The before command is the advertised-routes list for that neighbour. The change is the prefix-list, the route-map, the neighbour line and a soft clear outbound so the policy runs without resetting the session.

The change on R1
ip prefix-list NO-LAB seq 5 deny 10.99.0.0/16
ip prefix-list NO-LAB seq 10 permit 0.0.0.0/0 le 32
route-map TO-AS65002 permit 10
 match ip address prefix-list NO-LAB
router bgp 65001
 neighbor 10.0.12.2 route-map TO-AS65002 out
end
clear ip bgp 10.0.12.2 soft out
Before the change
R1# show ip bgp neighbors 10.0.12.2 advertised-routes
     Network          Next Hop            Metric LocPrf Weight Path
 *>  10.1.0.0/24      0.0.0.0                  0         32768 i
 *>  10.99.0.0/16     0.0.0.0                  0         32768 i

Total number of prefixes 2
After the change
R1# show ip bgp neighbors 10.0.12.2 advertised-routes
     Network          Next Hop            Metric LocPrf Weight Path
 *>  10.1.0.0/24      0.0.0.0                  0         32768 i

Total number of prefixes 1

ACL: block one port, count the hits

The ACL denies telnet inbound on GigabitEthernet0/1 and permits everything else. The before output proves the list exists and the interface has no inbound ACL. After the change, the interface shows the list and the match counters on each line say what it is catching and what it is letting through once a host behind it sends traffic.

The change on R1
ip access-list extended BLOCK-TELNET
 deny tcp any any eq 23
 permit ip any any
interface GigabitEthernet0/1
 ip access-group BLOCK-TELNET in
Before the change
R1# show ip access-lists BLOCK-TELNET
Extended IP access list BLOCK-TELNET
    10 deny tcp any any eq telnet
    20 permit ip any any

R1# show ip interface GigabitEthernet0/1 | include access list
  Inbound  access list is not set
After the change
R1# show ip access-lists BLOCK-TELNET
Extended IP access list BLOCK-TELNET
    10 deny tcp any any eq telnet (6 matches)
    20 permit ip any any (142 matches)

R1# show ip interface GigabitEthernet0/1 | include access list
  Inbound  access list is BLOCK-TELNET

OSPF cost: move the path

R1 reaches 10.3.0.0/24 directly over GigabitEthernet0/2 at metric 2. Raising the cost on that interface to 50 should move the route through R2 instead. The before output shows the cost column and the current next hop. The after output shows the new cost and the route re-installed via GigabitEthernet0/1 at metric 3, a few seconds old.

The change on R1
interface GigabitEthernet0/2
 ip ospf cost 50
Before the change
R1# show ip ospf interface brief
Interface    PID   Area            IP Address/Mask    Cost  State Nbrs F/C
Gi0/1        1     0               10.0.12.1/30       1     P2P   1/1
Gi0/2        1     0               10.0.13.1/30       1     P2P   1/1

R1# show ip route 10.3.0.0
Routing entry for 10.3.0.0/24
  Known via "ospf 1", distance 110, metric 2, type intra area
  * 10.0.13.2, from 10.255.0.3, 00:12:40 ago, via GigabitEthernet0/2
After the change
R1# show ip ospf interface brief
Interface    PID   Area            IP Address/Mask    Cost  State Nbrs F/C
Gi0/1        1     0               10.0.12.1/30       1     P2P   1/1
Gi0/2        1     0               10.0.13.1/30       50    P2P   1/1

R1# show ip route 10.3.0.0
Routing entry for 10.3.0.0/24
  Known via "ospf 1", distance 110, metric 3, type intra area
  * 10.0.12.2, from 10.255.0.3, 00:00:09 ago, via GigabitEthernet0/1

What it looks like on a lab router

The assistant runs the commands through NetPilot and quotes the output in the chat. Every device in the lab is also a normal SSH target, so you can open the router yourself and read show ip route ospf by hand, as in this capture from the NetPilot web app.

app.netpilot.io

What you need

  • A NetPilot account on Pro, Max, Team or Signature, including a Team seat or a Signature seat in an organization. On Free or Plus you can connect and sign in, and each tool answers with a note that the feature is included from Pro.
  • NetPilot connected in your assistant: ChatGPT, Claude.ai, Claude Code or Meta Muse. The lab VM is created the first time you ask the assistant to start it.
  • The current configs of the routers the policy touches, with the secrets removed. Cisco IOL runs as bring-your-own-image (BYOI), added once in the NetPilot app. The same experiment runs on Nokia SR Linux and FRR, which are built in, and on Arista cEOS or Juniper cRPD (BYOI).

Run it from the chat you already have open

  1. 1Connect NetPilot in ChatGPT, Claude or Meta Muse: how to connect, step by step.
  2. 2A NetPilot account on Pro, Max, Team or Signature, including a Team seat or a Signature seat in an organization. On Free or Plus you can connect and sign in, and each tool answers with a note that the feature is included from Pro. Plans and lab credits.

Common questions

Build the two or three routers the policy touches with their current configs, run the show command for the state the policy acts on and the neighbour summary, apply the route-map, prefix-list, ACL or interface cost, and run the same commands again. The lines that differ are the change. With NetPilot connected in ChatGPT, Claude or Meta Muse, the assistant builds the routers on real images in your lab VM, applies the lines and quotes both outputs, so the same command list verifies the change on the production devices in the window.
No. A route-map, ACL or interface cost acts on one router and is seen by its neighbours, so the router you edit plus one neighbour on each side shows the effect. For a BGP policy that is the peer the route-map is attached to and one router behind it that originates or receives the prefixes. For an OSPF cost change it is the two paths the cost chooses between. Add a device only when the before output does not contain the state you need to watch.
The config states the intent, the output shows the effect. A prefix-list with the wrong sequence order, an ACL applied in the wrong direction, or an OSPF cost that does not change the chosen path all look right in the config and wrong in the output. Running one command set twice also gives you the verification script for the window: the after output from the lab is what the production device should print once the change is in.

Run the next policy change as an experiment

Create a NetPilot account, pick Pro or above, and connect NetPilot in ChatGPT, Claude or Meta Muse.