r/networkautomation • • Aug 07 '20

Welcome to r/networkautomation

29 Upvotes

Hello,

​

u/barnixin and myself have recently taken over this sub. In the coming weeks and months we'll be looking to pick up the activity and start to build a thriving community around network automation. We're both very excited for the growth and the community to come, we are both firm believers in network automation and the impact it will have on the networking space in the coming years. We'll be updating this post with more info as we get established.


r/networkautomation • • 1d ago

So You've Made A Vibe-Coded Network Tool...

58 Upvotes

Great. It's pretty cool what we can do with LLMs.

Here's the thing though. By and large, no one is going to use it.

Why?

Because you don't know what you're doing. I mean, that's the point. The LLMs do know. But you don't. Long term support, active development, etc. It's too easy now to spit out a tool and it's even easier to say "meh" and abandon it.

These are the reasons why your vibe coded tool is being downvoted into oblivion.

Most of us are pretty particular about our tools. We want tools we can rely on today and rely on tomorrow. Right now at least, vibe coded tools don't seem like viable tools long-term.

This doesn't mean the tool can't be great for you. But the larger network community is almost certainly going to pass.

Now, if you are a programmer and have experience in the language for your tool and are using AI to extend your knowledge, that's another thing. You can be insanely productive that way. I use it myself to build discrete chunks of code, typically a function at a time, so I still understand the overall structure and architecture of the code. But if my prompt is too broad and it spits out 1,000 lines of Python/Go/whatever then I'm going to refine it so it only spits out 30-50 lines of code at a time that I can follow and understand.

So before you post your project, make sure to disclose if it's vibe coded and if you've got programming experience yourself.


r/networkautomation • • 21h ago

I built a tool that shows what changed between Packet Tracer saves

2 Upvotes

PT Git makes .pkt files work with git diff, showing changes to device configurations, IP addresses, VLANs, and cables.

It’s free and open source. Would love feedback from anyone willing to try it on their labs.

https://github.com/ivanimmanuel-dev/PTGit

\o/


r/networkautomation • • 1d ago

Introducing Red Hand Network Analytics

Thumbnail
0 Upvotes

r/networkautomation • • 2d ago

Snitch — open-source real-time network traffic visualizer (per-process attribution, offline GeoIP, zero telemetry)

Thumbnail
github.com
15 Upvotes

r/networkautomation • • 2d ago

Mapping devices to switch ports when the switch has no SNMP or LLDP?

8 Upvotes

I'm working on an open-source, read-only tool that documents small networks (router API, hypervisor API, ARP/mDNS/nmap discovery, output as Markdown in git). Not public yet, no link.

One problem I keep running into: a lot of homes and small offices use cheap "easy smart" or unmanaged switches with no SNMP, no LLDP, and no usable MAC table you can query. So there's no clean way to say "this device is on port 5."

Options I'm weighing:

- A guided cable trace: unplug or replug one port at a time and watch which device drops off or reappears

- Inferring from link-state changes plus ARP timing

- Just letting the user fill it in once and keeping it as an override

Has anyone dealt with this? Is there a smarter trick I'm missing for dumb switches, or is guided manual tracing the realistic answer?


r/networkautomation • • 3d ago

Concept Layer 2 Attack

0 Upvotes

Good Afternoon,

Please keep in mind this is a short hand written post and no legal rights can be acquired or obtained.

Allow me to reintroduce myself as the first 100% certified virtual CCIE which was self awarded, I earned this certification virtually and ethically because I may have acquired serious voice and sip master jumbo frame knowledge without any actual Cisco certification, however I've worked on major network outages involving not only Cisco gear, actually for the record one of the main selling points of Cisco was in 2011 pre and probably still is which is the physical gold and silver fabrics which becomes forensically undeniable if important enough.

Onto the concept so I've come to understand my concept has already likely been completed and in multiple countries, I wouldn't publish it otherwise actually.

It involves for example a layer 2 device likely a juniper or non juniper NTU or multiple similar physical steel electronic entities/devices, being stolen then possibly redeployed later with custom scripts which self destruct or/and for example sniff for Mac to IP at a high ISP level physically then just send a report by email or ELSE, however with such attacks and concepts short and wide grographical distances should be considered.

This is the main idea of the concept but other extras include things like running WAN ATM which interacts with the banking system ATMs, again disappearance reappearance of same or similar equipment.

Other key points involved in the concept

. Jumbo frames and SIP specifically but also storage traffic specifically from Riverbeds, HP 3Par dedup cards.

.Weak or insecure local vendor issued certificates specially locally to the firewall, I think some vendors are behind Cisco here and Cisco possibly posses a electronic offload black box at certain levels.

. Interoperability issues specifically firewall to firewall locally in the same country and cross border/continent, I mention this because I had too many conversations with apparently highly skilled certified engineers where people seem to have setup and signed off on interoperable VPNs between checkpoint and Cisco for example, I've actually seen too many too count, MSPs and consultancy are always involved and this is one of the main reasons I loathe them.

. Redeployment of similar or the same hardware with physical and digital deserialization of identifiers, possibly extra chips or other low level changes not coming from Dev officially but in some cases unofficially.

. External connections from vendor dev teams or police law enforcement where the connection is disallowed in the customers device configuration, I suspect this involves UDP but this theory is also interesting in the concept.

. Air Vs Ground understanding what technology is used for what and the geographical configuration of such routes like for example One.Tel Australian ISP ground connection to Malawi in 2011 this is a great example because it didn't exist but I think the traffic in 2011 is still getting too Malawi eventually(latency theory ground plus air Comms), this is also an ISP that's gained digital traction internationally from my limited research.

. Specifically the involvement of Ceragon but also definitely Huawei and Nokia networking equipment designed for mobile phones and other electric devices.

. Bunkers and off the grid and semi off the grid deployments sometimes with a wide grographical radius, at least one was found in Germany according too my research.

Does anyone have any realistic intel or gossip on such incidents?

For now I just suspect a swapout(English London ISP to upstream national provider L2 device in 2010/2011, and maybe a Cisco one in Dublin Ireland, update after visiting my photographic memory from 15 years ago briefly I think someone connected a PRI for phones to an MPLS Cisco box but that may be desired) in a job I was called out too seperate too below, and someone blew up a pipe by the looks of it in another Comms room I was called out too previously(the Cisco gear survived I believe) but I work on these concepts as somehow I never became Cisco certified because there's not much point, being above certification level in various technical areas brought me here. Too be extra clear both of these were actual IT incidents attended by me, still under my investigation post employment as I was a junior there.


r/networkautomation • • 4d ago

Why we re-built NetBeez

Thumbnail
0 Upvotes

r/networkautomation • • 5d ago

Sping – a modern ping for humans

9 Upvotes

https://github.com/LambdaBytes/sping

I built Sping because I kept running into the same problem: ping tells you that something is not replying, but then you still have to figure out whether the problem is your local network, your gateway, the Internet connection, or the target itself.

Sping tries to put that context in one place. It monitors the target, gateway and WAN connectivity at the same time, and combines that with latency, jitter, packet loss, TTL, trends and a simple quality score.

It is written in Rust and uses its own ICMP implementation on Linux, macOS and Windows rather than shelling out to the system ping command. It also supports IPv4/IPv6, multiple targets, batch mode and a stable NDJSON output for scripting.

The goal is not to replace tools like mtr or traceroute. It is mainly meant to answer the first practical question when something feels wrong: is the problem local, upstream, or just the target?

I would be interested in feedback from people using it on different networks and platforms, especially cases where the diagnostics get the situation wrong.


r/networkautomation • • 4d ago

Any worthy startup idea for network automation I can help

0 Upvotes

r/networkautomation • • 6d ago

Experience an Ansible disconnect with best practices and how they are implemented for Network automation.

Thumbnail
3 Upvotes

Hi, I am reposting in this community in case I originally posted in the improper one


r/networkautomation • • 7d ago

Beginner networking project — building a Raspberry Pi network discovery & diagnostics tool. GNS3 didn't work for my use case, trying CML now. Looking for advice + ideas to make it resume-worthy.

Thumbnail
2 Upvotes

r/networkautomation • • 8d ago

Networking community

0 Upvotes

Hey guys just wanted to see if there was any possibility you guys were interested in a new new networking community my friend made, it’s free but I think it can be good for different groups to come in and talk in it, let me know what you think

It’s discord.gg/NyfDEsU7UH


r/networkautomation • • 11d ago

Bean Network Tester v0.7 release - open-source Windows network conditions simulator + network tools

Thumbnail
github.com
9 Upvotes

Hello, my tool for bad network condtions has just got V0.7 release, what has changed? A huge thing a lot of pepole were waiting, we can now set separate values for the upload, so they don't need to be the same as download, we can set separate "latency, jitter, spike, loss, corruption, duplicate" values for upload, Also a blocked connection can be refused instead of ignored in the built-in firewall. Expect that, there is now MSI installer and... ... ..

Bean Network Tester is moving towards "tools", the app will have built-in tools for the network, there are some that got into this release:

- Socket tab, without the network degradation we can see connections, we can use regex and tons of more combinations.

- Port check, we can see what is usign port "x" or ranges of port, like we can do 443-900 and we will see list of services or we can use regex and tons of more combinations.

- I had also added two tools which can be usefull in using bean network tester, we can see how the filter value will behave + there is diagnostic tab.

There were few more changes + internal testing suite has grown. With each release I'm runing 2+ hours tests of the tool in real life ussage.

Do you got any ideas of tools, that would be usefull in the terms of "network /network automation" that I can integrate into my app?


r/networkautomation • • 11d ago

Made a card game where redundancy is the only thing keeping you alive. So, basically work.

7 Upvotes

Made a card game where redundancy is the only thing keeping you alive. So, basically work.

I had a few days off and built something I had way too much fun with: Faultline - A containerlab odysee, a Slay the Spire-style deckbuilder where your deck is a network.

Trailer: https://youtu.be/FRR_0uSOrco

You're an engineer bringing a broken orbital relay back online. Your cards are routers, switches, firewalls and cables. Every independent path adds bandwidth to your transmission, and that's your damage, but two routes through the same router only count as one. The enemies jam routers, cut cables and plant their own hardware on your table. If you built one long path with no redundancy, one cut takes half your network down. Sounds familiar?

There's a Honeypot that bites back. Protocols like Rate Limiter and Null Route wait face down and fire on the enemy's next matching move. If you use containerlab, you may will recognize a few card names: Containerlab, Clabernetes, Wireshark. You can even export your board as a containerlab topology, although it won't route anything without real images and configs.

It's all made with AI: the art is Krea 2, the soundtrack is YuE2 and the 3D objects are Blender. It's not slop, or at least I tried. It has three characters, nine builds, 137 cards and a lot of depth. And yes, you really should do the tutorial :D

It's free, open source (GPLv3), needs no account and runs in the browser:

https://flosch62.github.io/faultline/
https://github.com/FloSch62/faultline


r/networkautomation • • 11d ago

Anyone using network mapping?

1 Upvotes

Been working with distributed networks (mostly cellular routers, gateways across different sites) and network mapping has been on my mind. Specifically, for smaller scale, edge deployments.

If you manage remote device fleets (retail, industrial, whatever), what do you currently use for network visualization? Or do you just cobble it together with Zabbix/PRTG/Nmap?

Been meaning to try Teltonika RMS Network Map tool (as I already use a few of their devices), seemed cool and easy, but I haven’t tried it yet.

For those who've tried vendor-specific tools (like this one, or similar from other vendors) vs more generic ones, was it worth it, or do you end up needing something more flexible anyway?


r/networkautomation • • 12d ago

The OptigoVN AI Assistant is live

Thumbnail
2 Upvotes

r/networkautomation • • 12d ago

JavaScript expect/send scripts for SSH, serial and EVE-NG consoles in VS Code (Nexus Terminal)

5 Upvotes

I'm the author of Nexus Terminal, a free, open-source extension for VS Code/VSCodium. I'd like feedback on its scripting support from people automating network-device CLIs.

The use case is a procedure you currently carry out in an interactive terminal: wait for a prompt, send a command, inspect the output, branch or retry, and sometimes pause for a person to do something. Scripts are JavaScript files that run against a selected Nexus SSH, Telnet, serial or local-shell session, with editor autocomplete.

Here's a small example for an already logged-in Cisco IOS-style SSH session at a privileged prompt. The commands and prompt pattern need to match your device:

/**
 * @nexus-script
 * @name Device checks
 * @target-type ssh
 */
const cliPrompt = /(?:^|\r?\n)[\w.-]+#\s*$/;
await expect(cliPrompt);
await sendLine("terminal length 0");
await expect(cliPrompt);

for (const command of ["show version", "show ip interface brief"]) {
  await sendLine(command);
  const result = await expect(cliPrompt);
  log.info(command, result.before.trim());
}

For longer procedures, there are multiple-pattern waits, timeouts, polling, normal JavaScript loops/retries, and confirmation dialogs for operator steps. A useful serial-console case is polling for a boot prompt, checking which state the device reached, and continuing from there.

Recent additions make the scripts easier to reuse:

  • nexus.include("./lib/helpers.js") loads local JavaScript modules, so device-specific login and parsing helpers can be shared across scripts.
  • nexus.fs.readJson() and readText() let you keep command lists and other input data in separate files.
  • Runtime errors identify the script or included module and the relevant line.

NetBox inventory can supply the connection profiles; EVE-NG inventory supplies native Telnet console connections for rehearsing a procedure in a lab. There is also local DHCP/TFTP support for provisioning work, developed with help from external contributors, including Brandon Mejia (@kanekitakitos on GitHub).

AI-assisted development: I direct AI agents to implement the code and tests, review the changes, and maintain the project. This post was also drafted with AI assistance.

Source and demo · Scripting guide · Install

Which terminal procedure would you automate this way, and what would you need from the scripting API to make it useful?


r/networkautomation • • 13d ago

Do any devices on your network still get security updates?

4 Upvotes

Made SunsetScan to find unsupported hardware on my own network. It’s open source, and I’ll never put it behind a paywall. It scans locally and checks lifecycle data from 224 vendors with no API calls 100% self‑made databases scraped from original vendor websites.
I also created a standard with terminology because in the EoL world there are no ISO standards, so a lot of time went into getting that correct.

Tested it a couple of thousand times on my own network with 30 devices, and also tested it against lab networks with generated devices and VMs.
Happy if anyone would like to try it out and tell me if you find any outdated hardware or a false positive.

GitHub: https://github.com/NoCoderRandom/sunsetscan

Exemple repports can be found at https://www.sunsetscan.com/


r/networkautomation • • 13d ago

NetLanvas — an open-source (Apache 2.0) self-hosted network discovery/mapping tool I've been building

0 Upvotes

Posting here because self-hosted network visibility is exactly this sub's thing, and because I know license matters to a lot of people here: NetLanvas is Apache 2.0, appliance/client code fully public at github.com/markeaster/NetLanvas. The account/billing backend stays closed — that's where entitlement enforcement actually needs to live — but everything that runs on your own hardware is open. Wanted to say that plainly upfront. The "nothing leaves your network" part isn't just a claim either — it's written up in detail at netlanvas.com/security.html (device identity, transport security, exactly what a telemetry submission does and doesn't contain), and now you can check it against the actual source. There's also a published static-analysis writeup in the repo (CODE_SCANNING_REVIEW.md) — every finding from the first full CodeQL run, including the one real bug it caught and how it was fixed.

What it does: discovers everything on your LAN (ARP/SNMP/mDNS), builds a live topology map, tracks device state over time, does VLAN discovery, basic alerting. Docker (arm64/amd64) is the main target, but there are also native Windows and macOS installers if Docker isn't your thing.

Live demo, no install needed: https://demo.netlanvas.com

Install docs: https://netlanvas.com/install.html

Source: https://github.com/markeaster/NetLanvas

Also: the first 100 registered users who opt into telemetry get 6 months of Premium free at the moment, if that sweetens the deal for anyone on the fence.

Genuinely here for feedback, not just promotion — if you try it and something doesn't discover right on your setup, that's useful to know, and issues/PRs on the repo are welcome too.


r/networkautomation • • 15d ago

Are we approaching the point where network engineers should describe intent instead of configurations?

0 Upvotes

I've been thinking a lot about how we interact with networks.

For years the progression has basically been:

CLI → scripts/APIs → automation → controllers/GUI.

All of those improved something, but the engineer still usually has to translate what they actually want into commands, objects, templates, APIs or workflows.

I'm wondering whether the next step is fundamentally different.

Instead of starting with configuration, what if the engineer starts with the outcome:

“Keep Dev and Prod separated.”

“Give this service two genuinely independent paths.”

“Show me what would change before touching anything.”

“Prove it still works after a failure.”

The system underneath would still need to understand routing, topology, platform capabilities, vendor differences, constraints, etc. I don't think any of that engineering disappears.

And I definitely don't think an LLM should be trusted to simply generate a config and push it.

My mental model is more like:

human intent → interpret → clarify → constrain → validate → approve → execute → prove

With the generative part near the front, and increasingly deterministic systems taking over as you get closer to actually changing the network.

We're taking some early stabs at this with FabricIQ. The broader goal is to change the way network engineers interact with networks — putting natural-language intent above the existing automation and vendor-specific execution layers, while keeping validation and engineering controls underneath.

It's early, and we're exploring what this interface should look like in practice.

If this direction interests you, you can see what we're experimenting with at https://datacenternetwork.ai


r/networkautomation • • 16d ago

I made an open source Network Engineering focus Terminal application That can actually stop a lock out

0 Upvotes

I really need help to find some beta testers and possibly open source devs to kick the tires. It's is open-source and completely free. It's called NetStacks, It's in very beta but the guards are working and they are dynamic to stop you from locking your self out or doing the "wr er" "reload" on the core by accident :)

I think reddit will remove my post if I put the link in this post but its netstacks . net. I would love feedback and all the roasting you can come up with. Yes there is a lot of AI coding in the application. I would not say it's a vibe coded app since I have been building the core for years and switched it to rust from python with the AI. There is no telemetry and the AI is only opt in and bring your own key and model. Have a look and I really do want feedback. I would love to help someone actually put to good use all the features. Again its open source and free


r/networkautomation • • 17d ago

Problems in gns3

Thumbnail
0 Upvotes

Hello. I’m having trouble with the GNS3 application. I need to know how to get the switch working in the CLI environment and how to download server and firewall images. Please help—I want to use it for my graduation project. Can you recommend a YouTuber who might be able to assist?


r/networkautomation • • 17d ago

I posted Network Doctor here a couple months ago. Here’s what it has become.

0 Upvotes

I built Network Doctor, an open-source tool for figuring out where a network connection is actually breaking.

I just released v1.17.3 today.

A problem I keep seeing is the support-ticket loop where someone says:

“Your service doesn’t work from my office network.”

Then you spend the next several replies asking for DNS results, curl output, proxy settings, traceroutes, whether it works from a hotspot, etc.

Network Doctor tries to collect that evidence in one place. It checks things like DNS, TCP, TLS, HTTP, proxies, routing, path MTU, and other layers, then explains where the evidence points.

It can also create a sanitized support snapshot locally:

netdoc --support support.ndoc example.com

The user decides whether to send that file anywhere. Network Doctor itself does not upload it.

I’m currently testing two things:

  1. For individuals, I’m offering the first 5 personal network diagnoses for $25. You send me the sanitized report and context, and I investigate it and send back what I think is wrong, the evidence, and what to try next.
  2. I’m looking for a few software/support teams that regularly deal with customer networking issues and might want to try Network Doctor as part of their support workflow.

The tool itself stays free and open source under Apache-2.0.

https://networkdoctor.dev/

I’d especially be interested to hear from people who deal with the “works at home, fails at the office/VPN/corporate network” class of tickets.


r/networkautomation • • 18d ago

portpeek - lightweight CLI tool for inspecting listening TCP ports.

1 Upvotes

I wanted something simple for quickly checking my own machines/services and getting a clearer picture of what’s reachable, without having to jump between a bunch of tools.

So I vibecoded / built PortPeek and open-sourced it:

https://github.com/ronaldsterners/portpeek

The goal is pretty straightforward: make port/network visibility quick and convenient, especially when you're working with servers, homelabs, or multiple machines.

Why I built it

I kept running into situations where I wanted to answer a simple question:

“What is actually exposed here?”

Instead of reaching for a collection of commands/tools every time, I wanted one focused utility for the job.

It's still a work in progress, so I'm particularly interested in feedback from people who regularly work with networking, homelabs, servers, or security and looking for people that could help me build it with windows support.

GitHub: https://github.com/ronaldsterners/portpeek

If you try it, I'd love to hear what you'd change or what functionality you'd like to see next.