Mental model
Cisco objective 3.6 says “Describe the device level APIs and dynamic interfaces for IOS XE and NX-OS”. Both platforms converged on a common model-driven stack.
| Interface | Transport | Payload | Purpose |
|---|---|---|---|
| NETCONF | SSH | XML | Standards-based config / state over SSH |
| RESTCONF | HTTPS | JSON (or XML) | REST transformation of NETCONF; easiest to script |
| gNMI | gRPC | Protocol Buffers | Streaming telemetry (subscribe to metrics) |
| NX-API (NX-OS only) | HTTPS | JSON-RPC or REST | Older NX-OS management API, pre-RESTCONF |
The semantics (what you can get and set) are the same across NETCONF / RESTCONF / gNMI, because they all use the same YANG models. See YANG + RESTCONF in practice.
Enabling the APIs on IOS XE
Router(config)# netconf-yang
Router(config)# restconf
Router(config)# ip http secure-server # RESTCONF needs HTTPS enabled
Router(config)# aaa new-model
Router(config)# aaa authentication login default local
Router(config)# username admin privilege 15 secret cisco123
After commit, port 830 (NETCONF) and port 443 (RESTCONF) are listening.
RESTCONF first touch
curl -k -u admin:cisco123 \
-H "Accept: application/yang-data+json" \
https://10.0.0.1/restconf/data/ietf-interfaces:interfaces
Returns JSON of every interface, modelled by the IETF ietf-interfaces YANG module.
Three fixed parts:
/restconf/data/is the root for configuration + state data./restconf/operations/is the root for RPCs (e.g., reload).module:top-container[/path/to/leaf]identifies which YANG module and node.
RESTCONF edit example
# Shutdown GigabitEthernet0/0
curl -k -u admin:cisco123 -X PATCH \
-H "Content-Type: application/yang-data+json" \
-d '{"ietf-interfaces:interface": {"name":"GigabitEthernet0/0","enabled":false}}' \
https://10.0.0.1/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet0%2F0
Note: path segments must be URL-encoded (GigabitEthernet0/0 → GigabitEthernet0%2F0).
NETCONF first touch
NETCONF uses SSH on port 830. The payload is XML.
ssh -s admin@10.0.0.1 -p 830 netconf
Then send a <get-config> or <edit-config> RPC. Most people use the Python ncclient library instead of typing XML by hand:
from ncclient import manager
with manager.connect(host="10.0.0.1", port=830, username="admin",
password="cisco123", hostkey_verify=False) as m:
print(m.get_config(source="running"))
gNMI (streaming telemetry)
Instead of polling for metrics, the device pushes on-change or on-interval. Uses gRPC over port 50051 by default.
Pick gNMI when you want:
- CPU / memory / interface counters every second instead of every 30 seconds.
- Low server-side cost (no repeated polling).
Use gnmic or the pygnmi Python library.
NX-API
NX-OS only. Pre-dates RESTCONF; still supported for compatibility. Two flavours:
- NX-API REST — REST paths that mirror the DME (Data Management Engine) object model.
- NX-API CLI — send any
showorconf tcommand via JSON-RPC and get the output back as JSON.
Enable with feature nxapi on NX-OS. For new NX-OS automation, prefer RESTCONF / gNMI.
RESTCONF: read interface status from an IOS XE router
9 steps. curl against /restconf/data/ietf-interfaces:interfaces, filter to one interface, read oper-status, then flip it with a PATCH.
Open the lab →FAQ
Which should I learn first for the exam? RESTCONF. Easiest HTTP shape; works with curl you already know.
Is NETCONF going away? No. NETCONF is the IETF standard for model-driven config. Many Cisco controllers (NSO) and third-party tools (Ansible network modules) still prefer it. Both coexist.
What is the difference between NX-API and RESTCONF on NX-OS? NX-API is Cisco-proprietary; it mirrors the NX-OS internal data model. RESTCONF is standards-based (IETF) and uses standard YANG. New scripts: RESTCONF.
Why does RESTCONF need application/yang-data+json instead of plain application/json? It is the RESTCONF-specific content type. The server uses it to tell “this JSON is a YANG-structured payload” apart from a plain JSON body.
