「jeremiah windle — spokane, WA」

IT → Networking  ·  Labs · Roadmap  ·  Spokane, WA
TIME IN SPOKANE — --:--:-- PST

← blog  ·  2026-10-02

Netmiko: Be Everywhere Doing Everything All At Once

A wonderful compliment to the stateful nature of Ansible.

tags: automation, python, netmiko

Ansible answers “what should this be?” Netmiko answers “what is the current config right now?”

Problem

I keep a mental checklist of switches I audit by hand: SSH in, show vlan brief, eyeball it, SSH into the next one, repeat. It works until you have more than two switches or you need to do it more than once. Also saving the output is difficutl to standarize and sometimes copy and past gets truncated or the text just scrolls off the terminal and you remember it or you (usually) don’t.

Design

Netmiko isn’t a framework like ansible, so it should be treated differently. Ansible hands you a model of “this is what a network should look like” and does the reconciliation for you. Netmiko gets you an SSH session and you are in charge of the direct changes based on the script you right. It’s the same conversation a human has with a switch, just one you can run from a Python script instead of a terminal.

Build

The VLAN audit idea is what got me started down this path, and its a pretty simple script to write:

from netmiko import ConnectHandler
import os

devices = ["switch1", "switch2"]
username = os.environ["NET_USER"]
password = os.environ["NET_PASS"]

for host in devices:
    conn = ConnectHandler(
        device_type="cisco_ios",
        host=host,
        username=username,
        password=password,
    )
    output = conn.send_command("show vlan brief")
    print(f"--- {host} ---")
    print(output)
    conn.disconnect()

Under 20 lines and you have the VLAN table from every switch in one place. From there it’s just Python, diff two outputs to catch drift between switches that are supposed to match:

import difflib

diff = difflib.unified_diff(
    switch1_output.splitlines(),
    switch2_output.splitlines(),
    lineterm="",
)
print("\n".join(diff))

Or run the raw output through TextFSM if you want structured data instead of a wall of text to eyeball:

result = conn.send_command("show vlan brief", use_textfsm=True)
# result is now a list of dicts, one per VLAN row

Tradeoffs

Netmiko doesn’t know or care what the VLAN table should be. It gets the same output a human would see from the CLI, which can be great if that is your goal but can be harder to maintain if scripts are not stored in a central repository and outputs aren’t tracked and diffed.

Netmiko answers “what’s the live config right now?”

Results

If I sat down and did this by hand, focused, no interruptions, it’s still about an hour across a handful of switches. The script runs the same audit in a few minutes, and the output goes straight into a file I can git-diff against last week’s.

Reproduce

I will be posting the labs soon but im in the middle of rebuilding my homelab.

Takeaway

Ansible and Netmiko sound like competitors, they’re not really answering the same question at all. In fact they work much better when used in tandem and can scale networks quickly while maintaining the same visibility.


← Back to blog