Skip to main content
PacketMentor logo
Open menu
← All topics
Automation & Programmability Foundational

IOS XE and NX-OS Device APIs

The programmable interfaces on Cisco Catalyst (IOS XE) and Nexus (NX-OS) switches. NETCONF and RESTCONF on both. gNMI for streaming telemetry. NX-API as the NX-OS legacy.

Quick summary
  • IOS XE and NX-OS both ship with NETCONF (XML/SSH), RESTCONF (JSON/HTTPS), and gNMI (streaming telemetry over gRPC). Enable them per device.
  • NX-OS also has NX-API (older JSON-RPC or REST over HTTP) kept for backward compatibility.
  • RESTCONF is the easiest first touch: curl + Basic auth + Accept: application/yang-data+json.

Mental model

Cisco objective 3.6 says “Describe the device level APIs and dynamic interfaces for IOS XE and NX-OS”. Both platforms converged on a common model-driven stack.

InterfaceTransportPayloadPurpose
NETCONFSSHXMLStandards-based config / state over SSH
RESTCONFHTTPSJSON (or XML)REST transformation of NETCONF; easiest to script
gNMIgRPCProtocol BuffersStreaming telemetry (subscribe to metrics)
NX-API (NX-OS only)HTTPSJSON-RPC or RESTOlder NX-OS management API, pre-RESTCONF

The semantics (what you can get and set) are the same across NETCONF / RESTCONF / gNMI, because they all use the same YANG models. See YANG + RESTCONF in practice.

Enabling the APIs on IOS XE

Router(config)# netconf-yang
Router(config)# restconf
Router(config)# ip http secure-server       # RESTCONF needs HTTPS enabled
Router(config)# aaa new-model
Router(config)# aaa authentication login default local
Router(config)# username admin privilege 15 secret cisco123

After commit, port 830 (NETCONF) and port 443 (RESTCONF) are listening.

RESTCONF first touch

curl -k -u admin:cisco123 \
  -H "Accept: application/yang-data+json" \
  https://10.0.0.1/restconf/data/ietf-interfaces:interfaces

Returns JSON of every interface, modelled by the IETF ietf-interfaces YANG module.

Three fixed parts:

  • /restconf/data/ is the root for configuration + state data.
  • /restconf/operations/ is the root for RPCs (e.g., reload).
  • module:top-container[/path/to/leaf] identifies which YANG module and node.

RESTCONF edit example

# Shutdown GigabitEthernet0/0
curl -k -u admin:cisco123 -X PATCH \
  -H "Content-Type: application/yang-data+json" \
  -d '{"ietf-interfaces:interface": {"name":"GigabitEthernet0/0","enabled":false}}' \
  https://10.0.0.1/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet0%2F0

Note: path segments must be URL-encoded (GigabitEthernet0/0 → GigabitEthernet0%2F0).

NETCONF first touch

NETCONF uses SSH on port 830. The payload is XML.

ssh -s admin@10.0.0.1 -p 830 netconf

Then send a <get-config> or <edit-config> RPC. Most people use the Python ncclient library instead of typing XML by hand:

from ncclient import manager
with manager.connect(host="10.0.0.1", port=830, username="admin",
                     password="cisco123", hostkey_verify=False) as m:
    print(m.get_config(source="running"))

gNMI (streaming telemetry)

Instead of polling for metrics, the device pushes on-change or on-interval. Uses gRPC over port 50051 by default.

Pick gNMI when you want:

  • CPU / memory / interface counters every second instead of every 30 seconds.
  • Low server-side cost (no repeated polling).

Use gnmic or the pygnmi Python library.

NX-API

NX-OS only. Pre-dates RESTCONF; still supported for compatibility. Two flavours:

  • NX-API REST — REST paths that mirror the DME (Data Management Engine) object model.
  • NX-API CLI — send any show or conf t command via JSON-RPC and get the output back as JSON.

Enable with feature nxapi on NX-OS. For new NX-OS automation, prefer RESTCONF / gNMI.

Hands-on lab · 5 minute walkthrough

RESTCONF: read interface status from an IOS XE router

9 steps. curl against /restconf/data/ietf-interfaces:interfaces, filter to one interface, read oper-status, then flip it with a PATCH.

Open the lab →
restconf-interface · lab
you@laptop:~$ curl -u admin:cisco -H "Accept: application/yang-data+json" ...
{"ietf-interfaces:interfaces":{"interface":[...]}}
you@laptop:~$

FAQ

Which should I learn first for the exam? RESTCONF. Easiest HTTP shape; works with curl you already know.

Is NETCONF going away? No. NETCONF is the IETF standard for model-driven config. Many Cisco controllers (NSO) and third-party tools (Ansible network modules) still prefer it. Both coexist.

What is the difference between NX-API and RESTCONF on NX-OS? NX-API is Cisco-proprietary; it mirrors the NX-OS internal data model. RESTCONF is standards-based (IETF) and uses standard YANG. New scripts: RESTCONF.

Why does RESTCONF need application/yang-data+json instead of plain application/json? It is the RESTCONF-specific content type. The server uses it to tell “this JSON is a YANG-structured payload” apart from a plain JSON body.

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA Automation® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on IOS XE and NX-OS Device APIs. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where IOS XE and NX-OS Device APIs fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.