# Phase 1 verification plan

All tests are pending. Commands vary by device support. For first pings allow ARP resolution and repeat; persistent failures require troubleshooting.

| ID | Objective | Procedure | Expected result |
|---|---|---|---|
| T01 | Same-VLAN connectivity | Ping between each pair of PCs on HQ VLANs 10,20,30,40 and branch VLANs 10,40. | Each pair communicates. |
| T02 | HQ inter-VLAN routing | Ping HQ VLAN 20 PC from HQ VLAN 10 PC; repeat with VLANs 30 and 40. | Packets route through HQ-CORE. |
| T03 | Cardiff inter-VLAN routing | Ping a branch VLAN 40 PC from a branch VLAN 10 PC. | Packets route through BR-R1 subinterfaces. |
| T04 | Swansea to Cardiff | Ping both branch client VLANs from HQ PCs. | Both branch VLANs reachable. |
| T05 | Cardiff to Swansea | Ping HQ PCs and 10.10.0.82 from branch PCs. | HQ clients and server reachable. |
| T06 | OSPF neighbours | show ip ospf neighbor on HQ-CORE, HQ-R1 and BR-R1. | FULL neighbours: core 1, HQ router 2, branch router 1. |
| T07 | OSPF routes | show ip route on all Layer 3 devices. | Core learns three branch VLAN networks; branch learns all six HQ VLAN networks; HQ router learns site VLAN routes. |
| T08 | HQ DHCP | Select DHCP on all eight HQ PCs; ipconfig /all. | Addresses match their VLAN pool, mask, gateway and DNS. |
| T09 | Cardiff DHCP relay | Select DHCP on all four branch PCs; inspect a DHCP exchange in Simulation mode. | Correct branch pools; relay reaches central server and reply returns. |
| T10 | Gateways and masks | ipconfig /all on PCs; show ip interface brief and show running-config on gateways. | Matches proposed addressing table; each PC can ping its gateway. |
| T11 | Trunks and VLANs | show interfaces trunk and show vlan brief on switches; inspect BR-R1 subinterfaces. | Required allowed VLANs only, native VLAN 999, correct access-port membership. |
| T12 | Management access | From HQ IT PC: ssh -l netadmin 10.10.0.98; repeat for all six devices. | SSH succeeds with private lab credentials. |
| T13 | Security baseline | Test SSH denial from HQ VLAN 10; inspect shutdown ports, VTY settings, show port-security interface fa0/1 and spanning-tree settings. | Unauthorised-source SSH denied; unused ports shut; configured endpoint protections present. |
| T14 | Persistence | Save device startup configs and .pkt, close and reopen working copy; repeat routing, DHCP and SSH checks. | Configurations persist and connectivity still works. |

Record device/source/destination details, actual addresses, command outputs, actual results and evidence filenames in test-results.md. Suggested commands on all Cisco devices: `show ip interface brief`, `show running-config`; on switches: `show vlan brief`, `show interfaces trunk`; on routing devices: `show ip route`, `show ip ospf neighbor`, `show ip protocols`.

Use evidence/topology for cable/device views; evidence/routing for neighbour and route output; evidence/dhcp for pool settings and PC lease output; evidence/connectivity for pings and SSH. Store redacted configuration exports separately from these templates and remove secret/password lines before publishing.
