Skip to main content
PacketMentor logo
Open menu
← All topics
Automation & Programmability Foundational

Automation Tools: Ansible, Terraform, Cisco NSO

The three automation tools the v1.1 CCNAAUTO 200-901 5.6 blueprint names: Ansible (agentless, imperative-ish, YAML), Terraform (declarative, cloud + Cisco providers), Cisco NSO (model-driven, cross-vendor services).

Quick summary
  • Ansible = agentless; YAML playbooks; SSH or API; strong network support (ios_, nxos_ modules). Great for config of servers and devices.
  • Terraform = fully declarative; .tf files; providers for AWS/Azure/GCP/Cisco. Excellent for cloud resources and (increasingly) network devices.
  • Cisco NSO = model-driven service orchestration; speaks NETCONF/RESTCONF natively; cross-vendor. For MPLS L3VPNs, service chains, change-safe commits.

Mental model

Cisco objective 5.6 (v1.1) says “Describe the capabilities of automation tools such as Ansible, Terraform, and Cisco NSO”. The v1.0 blueprint also mentioned Puppet and Chef; v1.1 dropped them. Three tools now.

Each solves a slightly different problem.

ToolShapeBest for
AnsibleImperative-ish; task list in YAML; agentlessConfig of servers and network devices; smaller teams; SSH everywhere
TerraformDeclarative; HCL config files; providersCloud resources; one source of truth for mixed-stack infra
Cisco NSODeclarative, model-driven; speaks YANG nativelyMulti-vendor network service orchestration; strict change control

Ansible

How it works

  • A playbook is YAML listing tasks (per-step actions).
  • An inventory lists hosts (sw1 ansible_host=10.0.0.1).
  • Ansible SSHes to each host (or hits an API for cloud / network devices) and runs each task.
  • Each task calls a module (ios_config, copy, apt, template).
  • Modules are built to be idempotent: same task, no change if the system already matches.

What a playbook looks like

- hosts: switches
  gather_facts: no
  tasks:
    - name: Set NTP server
      cisco.ios.ios_ntp:
        server: 10.0.0.1
        state: present

See reading an Ansible playbook.

Pros + cons

ProsCons
Agentless — no software to install on managed hostsSlower than parallel API calls at huge scale
YAML is accessible to non-codersYAML gotchas (indentation, yes as bool)
Big module ecosystem (Cisco, Juniper, Palo, cloud)Imperative-ish ordering can hide intent
Checks mode (--check) for dry runNeeds Python on controller (not target)

Terraform

How it works

  • Write declarative .tf files describing resources.
  • terraform init fetches providers (plugins for AWS, Azure, Cisco DNA Center, Catalyst SD-WAN, NSO).
  • terraform plan shows the diff vs current state.
  • terraform apply reconciles live state to match configuration.
  • A state file records what Terraform knows exists (usually in S3 / blob storage with locking).

What a config looks like

resource "aws_instance" "web" {
  ami           = "ami-0abc12345"
  instance_type = "t3.small"
}

resource "ciscodnacenter_site" "nyc" {
  name = "nyc-dc1"
  type = "building"
}

Pros + cons

ProsCons
Fully declarative; plan vs apply loopLearning curve (HCL + state)
Huge provider ecosystemState file needs careful handling (lock, backup)
Dry run is first-classNot great for day-2 operational tasks (reboots, show commands)
Deep cloud supportStill catching up on network device coverage vs Ansible

Cisco NSO (Network Services Orchestrator)

How it works

  • Service models describe network services (MPLS L3VPN, QoS profile, firewall rule set) once.
  • Device models describe each vendor’s config via YANG.
  • Operator maps a service to devices; NSO figures out the vendor-specific config and pushes atomically.
  • Change can be committed, dry-run, rolled back cleanly.
  • Speaks NETCONF / RESTCONF natively, Netmiko / Expect for legacy CLI.

Why NSO is different

  • Cross-vendor by design. One service, Cisco + Juniper + Arista rendering.
  • Transactional. Half-applied changes get rolled back; no partial-config problems.
  • State-aware. Knows what config IT has pushed vs what the device actually has.

When to reach for it

  • Managed service provider that pushes MPLS L3VPN services to hundreds of PE devices across vendors.
  • Change-sensitive enterprise where “half the fabric got the change, half didn’t” is unacceptable.
  • Service abstraction so operators pick from a menu instead of writing per-vendor CLI.

Comparison table

AttributeAnsibleTerraformCisco NSO
ParadigmImperative-ish declarativeFully declarativeModel-driven declarative
Config languageYAMLHCL (.tf)YANG + templates
AgentNone (SSH / API)None (API)None (NETCONF / API)
Primary audienceServer & network adminsInfra engineersService providers, large enterprise
Dry run--checkplancommit dry-run
StateNot requiredState fileTransaction log + CDB
Open sourceYesYes (BSL)No (commercial)
Cross-vendorVia modulesVia providersNative goal

What dropped from the v1.1 blueprint

  • Puppet and Chef — still in use at some sites but Cisco removed them from the exam. If you see them in older study material, note the change.
  • Terraform was added (previously not called out explicitly).

FAQ

Which should I learn first? Ansible — easiest to install, YAML is accessible, works against existing SSH-only gear.

Can I use all three on the same network? Yes. Common pattern: Terraform for cloud + Catalyst Center templates; Ansible for day-2 config and ad-hoc tasks; NSO for the carrier-grade service layer. They coexist.

Does NSO really need a license? Yes. There is a free developer edition for learning (NSO Learning License). Production use is paid, typically by number of managed devices.

Is Ansible going agent-based? No. Agentless is a core design choice. Ansible Automation Platform (RedHat) adds a central controller, but managed nodes still have no agent.

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA Automation® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on Automation Tools: Ansible, Terraform, Cisco NSO. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where Automation Tools: Ansible, Terraform, Cisco NSO fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.