configuration sanity check

Justin Seabrook-Rocha xenith at
Thu Oct 29 14:42:00 UTC 2015

On Oct 29, 2015, at 01:16, marcel.duregards at wrote:
> Hi Nanogers,
> Any recommendation about a software which check the live config of cisco/juniper devices against some templates ?
> The goal is to have a template about different function device, like:
> - CORE device must have this bloc and this clock
> - PE device must have at least that and that
> - CPE must have this and that
> - Distrib switch block 1 and block2
> - etc...
> And the software run once every day to check which device do not comply with those rules and generate an alert.
> Thank,
> - Marcel

We implemented an in-house solution using Cisco Template Manager ( Its basically a bunch of bash/perl scripts doing regex matching against the saved configs from RANCID. Works fine for both Cisco and Juniper.

It requires some hand tooling, but we have it doing exactly what you want (checking against different device function templates).

Justin Seabrook-Rocha
Xenith || xenith at ||
Jabber: xenith at

More information about the NANOG mailing list