Mental model
Cisco objective 5.3 says “Describe the use and roles of network simulation and test tools (such as Cisco Modeling Labs and pyATS)”. Two tools, one answers “where do I get a Cisco network to test against”, the other answers “how do I automate tests against it”.
Note: the v1.1 blueprint replaced “VIRL” with “Cisco Modeling Labs (CML)”. Same product family; VIRL was the old marketing name.
CML (Cisco Modeling Labs)
A virtual environment that runs real Cisco OS images.
- Nodes = devices (IOS XE router, NX-OS switch, ASA firewall, external connector, Ubuntu VM).
- Links = virtual cables between node interfaces.
- Launch a topology; CML boots each node (takes seconds-minutes); you SSH / console into them and configure them like real gear.
- Export / import topologies as YAML or XML.
- API: REST, so you can
terraform applyto spin up a topology, run tests, tear it down.
Why you use it
- Learn / practice without buying hardware.
- Reproduce bugs reported by prod.
- CI pipeline: spin up a mini topology, apply the config change, run smoke tests, tear down.
- Design validation before buying real gear.
Flavours
- CML Personal — $199/year, free for CCNA/CCNP/DevNet certified. Up to 20 nodes.
- CML Enterprise — larger (up to 160 nodes) and runs on a server.
- DevNet Sandbox has free always-on CML topologies.
pyATS (Python Automated Test System)
Cisco’s open-source Python framework for network testing. Pronounced “py-ATS” or sometimes “py-A-T-S”.
What a pyATS test looks like
from pyats import aetest
class VerifyIntfs(aetest.Testcase):
@aetest.setup
def connect(self, testbed):
self.device = testbed.devices["sw1"]
self.device.connect()
@aetest.test
def ge0_0_is_up(self):
out = self.device.parse("show ip interface brief")
assert out["interface"]["GigabitEthernet0/0"]["status"] == "up"
- Describes test cases with decorators (
@aetest.setup,@aetest.test,@aetest.cleanup). - Uses a testbed (YAML inventory) to know how to connect to devices.
device.parse("show ...")returns a dict, powered by Genie parsers — pre-written parsers for hundreds of Cisco show commands.pyats run job myjob.pyruns the suite, generates HTML report.
Why you use it
- Automated regression tests: “every day, confirm OSPF has these 50 neighbors, no interface errors are counting up, STP root is sw-core-1”.
- Pre/post change verification in CI: “before this change, these 500 facts were true; apply the change; are they still true?”.
- Load / scale tests on CML topologies.
CML + pyATS in a CI pipeline
Common pattern:
- Developer opens PR with new network config.
- CI pipeline uses CML API to spin up a topology.
- Apply the proposed config to the virtual devices.
- Run pyATS against them: convergence, reachability, counters.
- If all tests pass, promote; otherwise fail the PR.
- Tear down the CML topology.
Alternative tools (good to know but not on 200-901)
- GNS3 — open-source, similar concept, supports more images (including some non-Cisco).
- EVE-NG — community favourite for mixed-vendor labs.
- Containerlab — recent, container-based (nokia SR Linux, Cisco XRd, Arista cEOS), fast to spin up.
- Batfish — static analysis of configs; catches issues without actually booting anything.
FAQ
Do I need CML to pass 200-901? No. The exam tests understanding. For practice, you can rely on DevNet Sandbox free topologies.
Does CML run real Cisco software? Yes — real IOS XE, NX-OS, ASA, IOS XRv images. That is the whole point vs cheaper mocks.
What is Genie? A pyATS add-on that turns show-command output into structured Python dicts. Covers hundreds of commands across IOS XE, NX-OS, Junos, more. Hugely reduces the “parse free text” grief.
Is pyATS only for test? Can I run config too? Yes to both. pyATS exposes device.configure() and device.execute(). Many teams use it as both test runner AND lightweight automation driver.
