Review an IPv4 ACL Change with Exact Boundary and Exclusion Tests
Use documentation-range fixtures to verify a /26, test addresses just outside it, subtract one host and preserve ordered firewall-rule semantics.
An address calculator can verify a set of addresses; it cannot establish the effect of a complete firewall policy. Review direction, protocol, port, action and rule order alongside the address set. The examples use documentation addresses, not a production rollout target.
Tools in this guide
1. Make the intended address set explicit
For 192.0.2.64/26, expect mask 255.255.255.192, wildcard 0.0.0.63 and an inclusive address range of 192.0.2.64–192.0.2.127, containing 64 addresses. An ACL membership test concerns this whole set, not only addresses traditionally assignable to hosts.
Check that the source input is aligned. A host address such as 192.0.2.70/26 normalizes to the same network; record that normalization rather than silently editing the change ticket.
2. Test both sides of each boundary
Use IP in CIDR Checker for .63, .64, .127 and .128 against 192.0.2.64/26. Expected membership is outside, inside, inside, outside. Write these four checks into the review so a one-bit prefix error is visible.
Network or broadcast conventions, point-to-point links and a cloud provider’s reserved addresses are separate from set membership. Do not subtract two addresses when deciding which addresses an ACL matches.
CIDR: 192.0.2.64/26
192.0.2.63 → outside
192.0.2.64 → inside
192.0.2.127 → inside
192.0.2.128 → outside3. Verify exceptions without widening access
To exclude 192.0.2.65/32 from this /26, the exact remaining set can be written as 192.0.2.64/32, 192.0.2.66/31, 192.0.2.68/30, 192.0.2.72/29, 192.0.2.80/28 and 192.0.2.96/27. The output contains 63 addresses and must not include .65.
An exact merger may combine aligned adjacent blocks but must preserve gaps. Merge only entries with identical policy meaning; combining addresses across allow and deny actions or different ports can change behavior even when the address union is correct.
192.0.2.64/32
192.0.2.66/31
192.0.2.68/30
192.0.2.72/29
192.0.2.80/28
192.0.2.96/274. Review the actual device policy and a reversal plan
Check first-match or last-match rules, default action, direction and connection tracking on the target platform. A mathematically correct set does not prove the rendered device configuration enforces the intended policy.
Before an authorized change, preserve the previous configuration and an independent management path. Test one expected allowed flow and one expected denied flow, inspect counters or logs and define the observable condition for reverting. This checklist does not apply any rule or certify reachability.