Note: This feature is currently in beta and is available only to early adopters.
All Compliance Condition types support three match modes:
Loose
Sequential
Strict
Match mode controls how multiple condition input lines are matched against the source:
Loose mode verifies that all input lines are present somewhere in the source. Their order is ignored, and any content may appear between matching lines in the source.
Sequential mode requires all input lines to appear in the source in the same order as entered. Additional text/lines may appear between them.
Strict mode requires input lines to appear in the same order as entered and consecutively in the source. No additional text or lines may appear between the matching lines.
Match Mode | Line order matters | Lines must be consecutive |
|---|---|---|
Loose | No | No |
Sequential | Yes | No |
Strict | Yes | Yes |
The compliance condition examples throughout this article are matching against the following device configuration:
hostname R1 ! interface Ethernet1 description Uplink ip address 10.0.0.1/24 no shutdown ! interface Ethernet2 description LAN ip address 192.168.1.1/24 no shutdown ! interface Loopback0 description Management Loopback ip address 10.255.255.1 255.255.255.255 ! router ospf router-id 1.1.1.1 network 10.0.0.0/24 area 0 ! |
Note: The Compliance engine can validate MCP automation outputs in addition to device configurations. To validate an automation output, select Source → Mass Config Push Result on the Compliance preset screen. The same condition types and matching principles described in this article apply when evaluating automation output.
The following examples demonstrate how the Loose, Sequential, and Strict match modes affect condition evaluation when using the Source contains condition type.
Loose mode
Example Input 1:
description LAN hostname R1 |
Result: Condition successful
Although the order of the input lines differs from the source, both lines are present.
hostname R1 description WAN |
Result: Condition failed
The line description WAN does not exist in the source.
Example Input 3:
interface Ethernet1 ip address 10.0.0.1/24 |
Result: Condition successful
Both input lines appear in the source in the correct order. The "description Uplink" line between them is ignored.
ip address 10.0.0.1/24 interface Ethernet1 |
Result: Condition failed
The input lines appear in the source in reverse order.
Example Input 5:
interface Ethernet1 description Uplink ip address 10.0.0.1/24 |
Result: Condition successful
All three lines appear consecutively in the source.
interface Ethernet1 ip address 10.0.0.1/24 |
Result: Condition failed
The source contains the line "description Uplink" between the two input lines. Strict mode therefore fails.
The same three match modes are available for the Source matches regex condition type. When using this condition type, each input line is treated as a separate regular expression and matched against the source. The selected match mode controls how these regex inputs are matched: whether they can match in any order, must match in the specified order, or must match consecutively.
router ospf hostname R[0-9]+ |
Result: Condition successful
This verifies that the device follows the R<number> hostname convention and has OSPF enabled. The two matches are independent, so their order does not matter.
router ospf hostname R[A-Z]+ |
Result: Condition failed
The router ospf line matches the source, but hostname R[A-Z]+ regex does not match hostname R1. Because all input lines must match the source, the condition fails.
router ospf network [0-9]+\.[0-9]+\.[0-9]+\.[0-9]+/([0-9]+) area [0-9]+ |
Result: Condition successful
This verifies that an OSPF network statement appears after the "router ospf" command. Other matching lines may appear between the two lines.
network [0-9]+\.[0-9]+\.[0-9]+\.[0-9]+/([0-9]+) area [0-9]+ router ospf |
Result: Condition failed
Both lines in the source, but they appear in the opposite order. Sequential mode therefore fails.
interface Loopback[0-9]+ description Management Loopback ip address 10\.255\.255\.[0-9]+ 255\.255\.255\.255 |
Result: Condition successful
This verifies that a Loopback interface with a variable interface number has the required "Management Loopback" description and uses a /32 address from the 10.255.255.0/24 management subnet.
interface Loopback[0-9]+ ip address 10\.255\.255\.[0-9]+ 255\.255\.255\.255 |
Result: Condition failed
Both lines match in the source, but the description Management Loopback line appears between them. Strict mode requires the matching lines to be consecutive, so the condition fails.
Requirement | Recommended match mode |
|---|---|
Required lines can appear anywhere and in any order | Loose |
Required lines must appear in a specific order, but may have other lines between them | Sequential |
Required lines must appear in a specific order with no lines between them | Strict |
The following are some example scenarios where each match mode is particularly useful:
| Use case | Match mode | Rationale |
|---|---|---|
| Baseline configuration - NTP, AAA, logging... | Loose | Requirements are independent lines scattered across the config, only presence matters |
| Security hardening - telnet disabled, no SNMPv2, management ACLs... | Loose | Independent requirements with no meaningful ordering relative to each other |
| Firewall and ACL rules | Sequential | Rule ordering matters, such as when specific rules must precede broader rules. |
| Route-maps | Sequential | Match and set clauses must appear in a required sequence. |
| Multiline MOTD banner | Strict | The complete banner block must be present and uninterrupted |
| Interface config blocks | Strict | Validate that a required set of interface configuration commands appears together as a consecutive block. |