This series shows how to build a practical open-source network-automation workflow using Ubuntu Server, rsyslog, MySQL, Bash, Ansible, and Jinja2. It was created from a solution that reduced repetitive switchport work during a large network refresh.
How it works: Cisco switches send selected syslog events to Ubuntu. Rsyslog stores actionable events in MySQL. A local worker validates and parses each event, then calls an Ansible playbook that renders the appropriate interface configuration.
Network Automation Series
- Part 1: Open-Source Network Automation: Ubuntu Server Setup
In Part 1, we prepare and harden the Ubuntu Server that will host the network-automation workflow. The goal is a patched, recoverable server that accepts management and syslog traffic only from approved networks. - Part 2: Collect Cisco Syslog with Rsyslog and MySQL
In Part 2, we create a local MySQL queue and configure rsyslog to retain only the Cisco events that can trigger an automation workflow. - Part 3: Automate Cisco Switchports with Ansible and Jinja2
In Part 3, we build the Ansible playbooks and Jinja2 templates that translate an approved MAC-address match into a Cisco access-port, wireless trunk, 802.1X reset, or BPDU Guard response. - Part 4: Trigger Ansible Playbooks from Cisco Syslog Events
In Part 4, we connect the event queue to Ansible. A Bash worker extracts the switch address, MAC address, and interface, selects the appropriate playbook, records the result, and runs continuously as a systemd service. - Part 5: Test and Deploy Network Automation Safely
In Part 5, we validate the complete workflow in a lab, confirm that only approved devices trigger changes, document rollback, and establish the safeguards required before a production pilot.
Who This Is For
This guide is intended for network and systems administrators—including K–12 technology teams—who manage Cisco switching and want a transparent, customizable alternative to repetitive manual port configuration.
Important Safety Guidance
- Treat every configuration and address as an example until it has been reviewed for your environment.
- Build the entire workflow in a lab before connecting it to production switches.
- Use least-privileged service accounts and a secrets manager such as Ansible Vault.
- Keep configuration backups and working console or out-of-band access.
- Start with reporting and rendered-command review before enabling automatic changes.
What You Will Build
After completing the series, you will have a server that receives selected network events, stores them in a local queue, matches approved MAC addresses, renders Cisco interface templates, records the result, and can be stopped immediately through systemd if unexpected behavior occurs.
Leave a Reply