v1.0 · built by A. Wassim
A small, interactive Python toolkit for network administrators. Run one launcher, pick a module, answer a few prompts, review a preview, and apply.
███╗ ██╗███████╗████████╗███████╗ ██████╗ ██████╗ ██████╗ ███████╗
████╗ ██║██╔════╝╚══██╔══╝██╔════╝██╔═══██╗██╔══██╗██╔════╝ ██╔════╝
██╔██╗ ██║█████╗ ██║ █████╗ ██║ ██║██████╔╝██║ ███╗█████╗
██║╚██╗██║██╔══╝ ██║ ██╔══╝ ██║ ██║██╔══██╗██║ ██║██╔══╝
██║ ╚████║███████╗ ██║ ██║ ╚██████╔╝██║ ██║╚██████╔╝███████╗
╚═╝ ╚═══╝╚══════╝ ╚═╝ ╚═╝ ╚═════╝ ╚═╝ ╚═╝ ╚═════╝ ╚══════╝
Verified against live Cisco IOS XE (Catalyst 8000V) via Cisco DevNet Sandbox — all five core modules tested end-to-end over SSH against real hardware.
| # | Module | Status |
|---|---|---|
| 1 | First-Touch Config (Simulation) | ready |
| 2 | ConfigForge — Bulk Config Push (SSH + Simulation) | ready |
| 3 | NetDoctor — AI Troubleshooter (SSH + Simulation) | ready |
| 4 | NetAudit — Compliance Checker (SSH + Simulation) | ready |
| 5 | NetBackup — Config Backup Manager (SSH + Simulation) | ready |
| 6 | NetScan — Network Discovery | ready |
All five core modules have been tested end-to-end against a live Cisco Catalyst 8000V (IOS XE) running in the Cisco DevNet Sandbox, connected over VPN:
- NetDoctor — ran read-only show commands over SSH, parsed interface and protocol state, and produced an AI-generated diagnostic report that correctly distinguished physical-layer issues from configuration issues.
- ConfigForge — pushed a baseline configuration (no ip domain-lookup, service password-encryption, banner motd) over SSH and confirmed the changes landed via show running-config.
- NetBackup — pulled the full running configuration over SSH and saved a timestamped backup file.
- NetAudit — audited the live running config against baseline.json and produced an accurate compliance score with per-rule pass/fail and fix commands.
- NetScan — swept the sandbox subnet, discovered all live hosts, checked SSH availability, and identified the Cisco IOS XE devices by hostname and platform.
Two real-world bugs surfaced and were fixed during this testing: a Netmiko read-timeout on large configs over higher-latency links, and a Paramiko traceback leak on devices with incompatible SSH host keys.
(First-Touch Config is designed for bootstrapping factory-default devices via console and is validated in Simulation mode.)
pip install -r requirements.txtDependencies: netmiko>=4.0, rich>=13.0, pyfiglet>=1.0, google-genai>=1.0
NetForge uses Rich for colored tables, panels, and section headers, and pyfiglet for the ASCII banner. Both render correctly on Windows Terminal, macOS Terminal, and Linux without any extra configuration.
python netforge.pyPushes a full CCNA-style configuration to one device or a named series
(SW1-FLOOR1 … SWn-FLOOR1) over SSH, or use Simulation / Dry-run mode
to export paste-ready IOS config blocks to output/<hostname>.txt — no device needed.
Select a device type at startup (Switch / Router / Both) and only the sections that apply to that device are offered.
15 configuration sections (v2.0):
| Section | Scope |
|---|---|
| A — Device Baseline | All |
| B — VLANs | Switch / Both |
| C — Access Ports | Switch / Both |
| D — Trunking | Switch / Both |
| E — STP | Switch / Both |
| F — EtherChannel | Switch / Both |
| G — CDP / LLDP | All |
| H — Router Interfaces & IP | Router / Both |
| I — Static Routing | Router / Both |
| J — OSPF | Router / Both |
| K — DHCP Server | Router / Both |
| L — NAT | Router / Both |
| M — ACLs | All |
| N — QoS | All |
| O — Security Hardening | All |
Passwords are read with getpass (never echoed) and masked in the on-screen preview.
Simulation mode writes plaintext passwords to file — output/ is in .gitignore.
Nothing is sent to a device until you type yes at the confirmation step.
Connects to one device or a series over SSH (read-only — never modifies config),
or reads from saved show output files in Simulation mode. Runs a curated set of
show commands, parses the output deterministically, and sends structured findings
to the Gemini 2.5 Flash API to produce a plain-language diagnostic report saved
to output/<hostname>_report.txt.
Requires a free Gemini API key (no credit card needed):
- Go to aistudio.google.com → Get API key → Create API key
- Set it before running:
Windows PowerShell : $env:GEMINI_API_KEY="your-key-here" Permanent : setx GEMINI_API_KEY "your-key-here"
What it checks (deterministic parser):
| Check | Scope |
|---|---|
| Interface up/down, up/up, err-disabled | Both |
| Input errors and CRC counters | Both |
| OSPF neighbor states | Router |
| Routing table / missing default route | Router |
| STP blocked ports | Switch |
| Port security violations | Switch |
| EtherChannel suspended members | Switch |
| DHCP conflicts | Router |
Simulation mode: create sim_input/<hostname>/ folder automatically on first
run, paste show output into the generated .txt files, re-run for a full AI report —
no device needed.
NetDoctor is strictly read-only. It will never send a configure terminal command
to any device.
Bootstraps a factory-default Cisco device from zero to SSH-ready in one pass. No existing credentials needed — this is the very first thing you run on a new device.
Configures in order:
- Hostname and
no ip domain-lookup service password-encryption,enable secret,banner motd- Local user (privilege 15) for SSH login
ip domain-name,crypto key generate rsa modulus 2048,ip ssh version 2line vty 0 15:login local,transport input sshline console 0: password, login, exec-timeout- Management IP: SVI + default-gateway (switch) or physical interface (router)
write memory
Simulation mode exports a paste-ready IOS block to output/first_touch_<hostname>.txt — works with Packet Tracer. Console cable mode (Coming Soon) will push directly via pyserial over USB-to-RJ45.
Checks a device's running configuration against a user-defined compliance baseline stored in baseline.json. Connects over SSH (read-only) or reads from a saved running-config file in Simulation mode.
Default baseline (auto-generated on first run): 10 CCNA security hardening rules covering enable secret, service password-encryption, SSH v2, HTTP server disabled, banner motd, console exec-timeout, VTY SSH-only, VTY login local, no ip domain-lookup, and no telnet.
Customizing the baseline:
Edit baseline.json to add, remove, or change rules. Each rule specifies an id, description, check type (must_contain / must_not_contain / must_match_regex), value, severity (critical/high/medium/low), and the exact IOS fix command. The baseline is version-controlled alongside your code so compliance requirements are tracked over time.
Output: output/<hostname>_audit.txt with score, failed rules with fix commands, and passed rules.
Connects to one device or a series over SSH and saves each device's running configuration to a timestamped backup file. Strictly read-only.
Backups are saved to:
backups/<hostname>/<hostname>_<YYYY-MM-DD_HH-MM>.txt
Each backup file includes a 5-line header with device name, IP, timestamp, and NetBackup attribution, followed by the raw running-config output. The backups/ folder is excluded from git (.gitignore) since running configs contain sensitive network topology information.
Simulation mode generates a template file you can fill with real show running-config output for testing backup workflows without a live device.
Discovers live hosts on a subnet using a parallel ping sweep, checks SSH port 22 availability on each live host, and optionally identifies Cisco devices by connecting via Netmiko.
Three-phase scan:
- Phase 1 — Ping sweep: pings all hosts in parallel (up to 50 concurrent threads) with a Rich progress bar showing real-time results
- Phase 2 — SSH port check: checks port 22 on all live hosts
- Phase 3 — Cisco identification (optional): connects via Netmiko to pull hostname and IOS platform from each SSH-reachable host
Output: output/netscan_<subnet>_<timestamp>.txt with per-host results (alive, SSH open/closed, hostname, platform).
Strictly read-only — never modifies any device.
Note: Ping uses Windows syntax by default (ping -n 1 -w 500). Linux/macOS users should change _ping_host() to use -c 1 -W 1.
Host-side Python cannot reach Cisco Packet Tracer devices (PT doesn't bridge to the host network stack), so ConfigForge is tested against GNS3:
- Add an IOSv / IOSvL2 device to your topology.
- Give it a management IP and enable SSH:
hostname,ip domain-name,crypto key generate rsa, a localusername … privilege 15 secret …, andtransport input sshon the vty lines. - Bridge the topology to your host with a Cloud or NAT node so your laptop can reach the management IP.
- First-Touch Config: console-cable mode (needs USB-to-RJ45 cable + pyserial)
- ConfigForge: console-cable connection method
- ConfigForge: configurable SSH port (currently port 22)
- NetDoctor: console-cable connection method
- NetDoctor: TextFSM/Genie structured parsing
- Cross-platform ping support in NetScan (currently Windows only)
- Logging system: audit trail for all module runs
- Input validation: IP/subnet format checking
- Config file (netforge.ini): save default preferences
python netforge.py — interactive menu
python netforge.py --version — print version and exit
All module runs are logged to logs/netforge.log:
2026-06-29 21:49:47 | ConfigForge | SSH | SW1-FLOOR1 | SUCCESS
The logs/ folder is excluded from git.
User preferences (SSH username, timeout) are saved to netforge.ini automatically. Edit it to set defaults. The file is excluded from git.
Edit baseline.json to customize NetAudit rules. The file is version-controlled so compliance requirements are tracked over time.
A. Wassim GitHub: https://github.com/wassimsmt LinkedIn: https://www.linkedin.com/in/wassim-abelghouch/
MIT — see LICENSE.