...
| Config to validate | Match mode | Rationale |
|---|---|---|
| Baseline configuration and security hardening - NTP servers, DNS servers, syslog host, password encryption, telnet disabled, HTTP disabled | Loose | The required lines are independent of each other and may appear in different parts of the configuration. Only their presence matters. |
| Firewall and ACL rules, route-maps | Sequential | The required lines must appear in a specific order, while other configuration lines may appear between them. |
| Multiline MOTD banner, interface configurations | Strict | The required lines form a complete configuration block and must appear consecutively without any other lines between them. |