network-config-validation
affaan-m/everything-claude-code
Pre-deployment validation for Cisco IOS/IOS-XE configs: dangerous commands, IP conflicts, credential exposure, and security hygiene.
What is network-config-validation?
Validates network device configurations before deployment by detecting destructive commands, duplicate/overlapping IP addresses, credential exposure, stale ACL/route-map references, and security best-practice gaps. Use this when reviewing generated configs, automation scripts, or manual changes destined for production routers and switches.
- Detects dangerous commands (reload, erase, format, crypto key changes, routing process removal)
- Finds duplicate IP addresses and overlapping subnets across interfaces
- Checks management-plane security (VTY access-class, SSH-only, exec-timeout, Telnet blocking)
- Identifies stale references to undefined ACLs, route-maps, prefix-lists, and interfaces
- Audits security hygiene (SNMPv3 vs v2, enable secret vs password, NTP, logging, banners)
- Validates credentials and sensitive data exposure in config snippets
How to install network-config-validation
npx skills add https://github.com/affaan-m/everything-claude-code --skill network-config-validationHow to use network-config-validation
- 1.Load the network configuration text (Cisco IOS/IOS-XE format) into the skill
- 2.Run dangerous-command detection on the exact snippet to be deployed
- 3.Run duplicate IP and subnet overlap checks against the full candidate config
- 4.Verify all referenced ACLs, route-maps, prefix-lists, and interfaces are defined
- 5.Check VTY blocks for access-class restrictions, SSH-only transport, and exec-timeout
- 6.Review security hygiene findings and confirm best-practice gaps are acceptable for the change scope
- 7.Confirm rollback commands and out-of-band access before applying any management-plane changes
Use cases
- Pre-flight check before pasting config snippets into a change window
- Blocking gate for network automation (Netmiko, NAPALM, Ansible) before pushing generated configs
- Auditing template-generated device configurations for overlapping subnets and duplicate IPs
- Reviewing security posture of existing configs for credential exposure and weak protocols
- Validating rollback and out-of-band access before management-plane changes
- Network engineers reviewing configs before deployment
- Network automation engineers validating generated configurations
- DevOps/SRE teams managing infrastructure-as-code for network devices
- Security auditors checking device configurations for compliance gaps
network-config-validation FAQ
No. Regex checks provide pre-flight warnings but are not a complete parser. A network engineer must still review intent, platform-specific syntax, and rollback steps before deployment.
Warn on hygiene gaps but do not block the change if it is outside scope. Use the findings to plan future hardening work separately.
The patterns are optimized for Cisco IOS and IOS-XE syntax. Other platforms (Juniper, Arista, etc.) may require adapted regex patterns.
The skill identifies stale references (commands that reference undefined objects), but you must manually confirm that all referenced ACLs, route-maps, and prefix-lists exist in the full config.
No. Read counters and logs instead. Disabling ACLs is an anti-pattern that masks real security issues.
Full instructions (SKILL.md)
Source of truth, from affaan-m/everything-claude-code.
name: network-config-validation description: Pre-deployment checks for router and switch configuration, including dangerous commands, duplicate addresses, subnet overlaps, stale references, management-plane risk, and IOS-style security hygiene. metadata: origin: community
Network Config Validation
Use this skill to review network configuration before a change window or before an automation run touches production devices.
When to Use
- Reviewing Cisco IOS or IOS-XE style snippets before deployment.
- Auditing generated config from scripts or templates.
- Looking for dangerous commands, duplicate IP addresses, or subnet overlaps.
- Checking whether ACLs, route-maps, prefix-lists, or line policies are referenced but not defined.
- Building lightweight pre-flight scripts for network automation.
How It Works
Treat config validation as layered evidence, not as a complete parser. Regex checks are useful for pre-flight warnings, but final approval still needs a network engineer to review intent, platform syntax, and rollback steps.
Validate in this order:
- Destructive commands.
- Credential and management-plane exposure.
- Duplicate addresses and overlapping subnets.
- Stale references to ACLs, route-maps, prefix-lists, and interfaces.
- Operational hygiene such as NTP, timestamps, remote logging, and banners.
Dangerous Command Detection
import re
DANGEROUS_PATTERNS: list[tuple[re.Pattern[str], str]] = [
(re.compile(r"\breload\b", re.I), "reload causes downtime"),
(re.compile(r"\berase\s+(startup|nvram|flash)", re.I), "erases persistent storage"),
(re.compile(r"\bformat\b", re.I), "formats a device filesystem"),
(re.compile(r"\bno\s+router\s+(bgp|ospf|eigrp)\b", re.I), "removes a routing process"),
(re.compile(r"\bno\s+interface\s+\S+", re.I), "removes interface configuration"),
(re.compile(r"\baaa\s+new-model\b", re.I), "changes authentication behavior"),
(re.compile(r"\bcrypto\s+key\s+(zeroize|generate)\b", re.I), "changes device SSH keys"),
]
def find_dangerous_commands(lines: list[str]) -> list[dict[str, str | int]]:
findings = []
for line_number, line in enumerate(lines, start=1):
stripped = line.strip()
for pattern, reason in DANGEROUS_PATTERNS:
if pattern.search(stripped):
findings.append({
"line": line_number,
"command": stripped,
"reason": reason,
})
return findings
Duplicate IPs And Subnet Overlaps
import ipaddress
import re
from collections import Counter
IP_ADDRESS_RE = re.compile(
r"^\s*ip address\s+"
r"(?P<ip>\d{1,3}(?:\.\d{1,3}){3})\s+"
r"(?P<mask>\d{1,3}(?:\.\d{1,3}){3})\b",
re.I | re.M,
)
def extract_interfaces(config: str) -> list[dict[str, str]]:
results = []
current = None
for line in config.splitlines():
if line.startswith("interface "):
current = line.split(maxsplit=1)[1]
continue
match = IP_ADDRESS_RE.match(line)
if current and match:
ip = match.group("ip")
mask = match.group("mask")
network = ipaddress.ip_interface(f"{ip}/{mask}").network
results.append({"interface": current, "ip": ip, "network": str(network)})
return results
def find_duplicate_ips(config: str) -> list[str]:
ips = [entry["ip"] for entry in extract_interfaces(config)]
counts = Counter(ips)
return sorted(ip for ip, count in counts.items() if count > 1)
def find_subnet_overlaps(config: str) -> list[tuple[str, str]]:
networks = [ipaddress.ip_network(entry["network"]) for entry in extract_interfaces(config)]
overlaps = []
for index, left in enumerate(networks):
for right in networks[index + 1:]:
if left.overlaps(right):
overlaps.append((str(left), str(right)))
return overlaps
Management-Plane Checks
Parse VTY blocks by section so access-class checks do not spill across unrelated lines.
import re
def iter_blocks(config: str, starts_with: str) -> list[str]:
blocks = []
current: list[str] = []
for line in config.splitlines():
if line.startswith(starts_with):
if current:
blocks.append("\n".join(current))
current = [line]
continue
if current:
if line and not line.startswith(" "):
blocks.append("\n".join(current))
current = []
else:
current.append(line)
if current:
blocks.append("\n".join(current))
return blocks
def check_vty_blocks(config: str) -> list[str]:
issues = []
for block in iter_blocks(config, "line vty"):
if re.search(r"transport\s+input\s+.*telnet", block, re.I):
issues.append("VTY allows Telnet; require SSH only.")
if not re.search(r"\baccess-class\s+\S+\s+in\b", block, re.I):
issues.append("VTY block has no inbound access-class source restriction.")
if not re.search(r"\bexec-timeout\s+\d+\s+\d+\b", block, re.I):
issues.append("VTY block has no explicit exec-timeout.")
return issues
Security Hygiene Checks
SECURITY_PATTERNS = [
(re.compile(r"\bsnmp-server community\s+(public|private)\b", re.I),
"default SNMP community configured"),
(re.compile(r"\bsnmp-server community\s+\S+", re.I),
"SNMPv2 community string configured; prefer SNMPv3 authPriv"),
(re.compile(r"\bip ssh version 1\b", re.I),
"SSH version 1 enabled"),
(re.compile(r"\benable password\b", re.I),
"enable password is present; use enable secret"),
(re.compile(r"\busername\s+\S+\s+password\b", re.I),
"local username uses password instead of secret"),
]
BEST_PRACTICE_PATTERNS = [
(re.compile(r"\bntp server\b", re.I), "NTP server"),
(re.compile(r"\bservice timestamps\b", re.I), "log timestamps"),
(re.compile(r"\blogging\s+\S+", re.I), "logging destination or buffer"),
(re.compile(r"\bsnmp-server group\s+\S+\s+v3\s+priv\b", re.I), "SNMPv3 authPriv group"),
(re.compile(r"\bbanner\s+(login|motd)\b", re.I), "login banner"),
]
def check_security(config: str) -> list[str]:
return [message for pattern, message in SECURITY_PATTERNS if pattern.search(config)]
def check_missing_hygiene(config: str) -> list[str]:
return [
f"Missing {description}"
for pattern, description in BEST_PRACTICE_PATTERNS
if not pattern.search(config)
]
Examples
Change-Window Preflight
- Run dangerous-command checks on the exact snippet to be pasted.
- Run duplicate IP and subnet overlap checks against the full candidate config.
- Confirm every referenced ACL, route-map, and prefix-list exists.
- Confirm rollback commands and out-of-band access before any management-plane change.
Automation Preflight
Use validation as a blocking gate before Netmiko, NAPALM, Ansible, or vendor API automation pushes a generated config. Fail closed on dangerous commands and credentials. Warn on best-practice gaps that are outside the change scope.
Anti-Patterns
- Treating regex validation as a device parser.
- Applying generated config without a dry-run diff.
- Recommending SNMPv2 community strings as a monitoring requirement.
- Checking VTY blocks with regex that can accidentally span unrelated sections.
- Testing firewall behavior by disabling ACLs instead of reading counters/logs.
See Also
- Agent:
network-config-reviewer - Agent:
network-troubleshooter - Skill:
network-interface-health
Related skills
More from affaan-m/everything-claude-code and the wider catalog.

network-interface-health
Diagnose physical link, duplex, and interface counter issues on network devices.

nextjs-turbopack
Next.js 16+ incremental bundler with Rust-powered Turbopack for faster dev startup and HMR.

nodejs-keccak256
Use Ethereum's Keccak-256, not Node's NIST SHA3, to prevent silent hashing bugs in selectors, signatures, and storage slots.

nutrient-document-processing
Convert, extract, OCR, redact, sign, and fill documents via Nutrient DWS API.

nuxt4-patterns
Nuxt 4 patterns for SSR, hydration safety, route rules, and data fetching.

openclaw-persona-forge
Forge complete OpenClaw lobster personas with identity, soul rules, names, and avatar prompts—guided design or random gacha.