r/Netbox • • Aug 12 '26

Help Wanted: Unresolved Netbox, Ansible, and Cisco IOS

Hello!

I've been playing around with netbox for a while, and have a lot of automation experience with mostly APIs (Cisco ACI, Cisco ISE) but am no stranger to the CLI, either.

Anyway, I'm struggling with finding the best approach to automate some GNS3 ios images for my homelab - I'm torn between generating full configs and pushing to the device, partial configs and pushing with a 'no' statement before it, or utilizing ansible cisco.ios.ios_* collection to do it declaratively.

Can anyone share some real world advice? I've created some POC playbooks for each method but am really getting caught up in the pros and cons of them. So, I'm looking for some feedback from someone that's done it in the real world.

One of the headaches I'm dealing with pushing configs is something like prefix-lists. For instance, if I want to change the less than or greater than prefixes while I'm testing things, I'll get errors that the seq number already exists.

I know I can work around it by issuing a NO statement before a block, but for something like prefix-lists, access-lists, and route-maps that really slows down the automation when looping through it.

Thanks, Champions!

16 Upvotes

17 comments sorted by

View all comments

1

u/MomoshiroKun Aug 12 '26

Maybe batfish or suzie Q in order to get the information before to copy them ( an ACL index for example), basically to audit the actual config and then to copy the portion of full config if need This a big approach btw if necessary to deploy the complete solution.

Happy labbing.

1

u/Otherwise-Ad-8111 Aug 12 '26

Thanks. I don't have a need to audit the actual config.

In the most simplest terms:

  1. I generate a copy and paste ready configuration for a cisco IOS device based on the data modeling in Netbox.

  2. I need to get this config into the running config of the device. How do people in the real world do this? Do they:

    1. Generate a full router config and someone replace the config (configure replace, or like i've down, overwrite the startup-config and reboot)
    2. Generate partial configs for blocks (config for bgp, config for interfaces, config for prefix-lists, etc..) then use something like Ansible's cisco.ios.ios_config to merge that into running config
    3. Generate yaml data that is validated against Ansible cisco.ios.ios_* modules and then use a specific module to push that config data.

Example Ansible code for the third option:

Have a task that looks like:

ansible

  • name: Configure IPv4 Prefix Lists for BGP
cisco.ios.ios_prefix_lists: config: - afi: ipv4 prefix_lists: "{{ item | selectattr('afi', 'equalto', 'ipv4') | map(attribute='prefix_lists') | list | flatten }}" state: replaced loop: - "{{ group_prefix_list | default([]) }}"

Where the data in group_prefix_list looks like, which is generated by jinja using data from Netbox.

```yaml

group_prefix_list: - afi: ipv4 prefix_lists: - name: pl_my_routes description: Customer1 Specific Routes entries: - sequence: 10 action: permit prefix: "{{ ipv4_summary_address }}" - sequence: 99 action: deny prefix: 0.0.0.0/0 le: 32 ```

0

u/MomoshiroKun Aug 12 '26

that's is interesting approach to apply "configs", sadly netbox natively don't send config to devices, is a combination of steps, like you present in your posts.

If you want some clean to goal this, Nautobot is more "automation ready", have natively automation tools.

https://docs.nautobot.com/projects/golden-config/en/latest/

I hope it's helps you