# Network Automation and Orchestration

**URL:** https://forum.networklessons.com/t/network-automation-and-orchestration/6319
**Category:** Lessons Discussion
**Created:** [February 21, 2019, 12:40pm UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319 "2019-02-21T12:40:42Z")
**Posts on this page:** 19
**Page:** 1

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [February 21, 2019, 12:40pm UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/1 "2019-02-21T12:40:42Z")

</div>

This topic is to discuss the following lesson:

> **[Network Automation and Orchestration](https://networklessons.com/cisco/evolving-technologies/network-automation-and-orchestration)**
>
> This lesson explains the basics of network automation and orchestration with examples such as ansible, docker, kubernetes.

---

<div class="post-metadata">

### Author: ![michmoor](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/michmoor/32/3557_2.png) [@michmoor](https://forum.networklessons.com/u/michmoor)
#### Post date: [March 3, 2019, 7:24pm UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/2 "2019-03-03T19:24:49Z")

</div>

Hi Rene. Its been a very long time since we spoke. Still a huge fan of your website. You helped me through my CCNP/CCIE(written) studies. I will always be eternally grateful  
That being said I am entering the phase in my career will automation through Python is a great interest. Will you write an article about Python for Network Engs? Im thinking about Python + REST apis + Postman. If the article can be written like this network automation and orchestration article I think it will greatly help alot of people. No in depth knowledge of Python or REST is even needed. What do you think?

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [March 4, 2019, 8:41pm UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/3 "2019-03-04T20:41:59Z")

</div>

Hi Michael,

You are very welcome, it’s good to hear my work has been so useful to you. I’m definitely going to add some python material in the future. The “evolving technologies” blueprint also has REST APIs so I’m going to write some articles what REST APIs are and how to play around with postman or python.

It doesn’t take too long to learn python and use it to talk with APIs or manage network devices. It’s a lot of fun too.

Rene

---

<div class="post-metadata">

### Author: ![ankisang](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/a/94ad74/32.png) [@ankisang](https://forum.networklessons.com/u/ankisang)
#### Post date: [October 4, 2019, 6:56pm UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/4 "2019-10-04T18:56:35Z")

</div>

Seems like the Network Automation and Orchestration link is broken. getting 403 error message.  
Did the topic link has moved to other location.

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [October 7, 2019, 11:22am UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/5 "2019-10-07T11:22:22Z")

</div>

Hi Ankit

I tried it out now and it seems to work. Can you tell me from which page you are trying to link? The page may be up but the link may be incorrect. Let us know and we’ll fix it.

Thanks!

Laz

---

<div class="post-metadata">

### Author: ![ankisang](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/a/94ad74/32.png) [@ankisang](https://forum.networklessons.com/u/ankisang)
#### Post date: [October 9, 2019, 5:24pm UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/6 "2019-10-09T17:24:54Z")

</div>

page timed out error was related to my vpn connection..thanks.

---

<div class="post-metadata">

### Author: ![coolcomfort22](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/c/f04885/32.png) [@coolcomfort22](https://forum.networklessons.com/u/coolcomfort22)
#### Post date: [April 13, 2020, 4:11am UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/7 "2020-04-13T04:11:30Z")

</div>

Hello, I am having some trouble understanding the Kubernetes section. I understand how Master Components and Node Components are separated, correct? I am trying to match your definitions to the diagram.

 ![image](https://cdn-forum.networklessons.com/uploads/default/original/2X/8/8c30b9f21086db849c7b0c2c86ae601ec74d0270.png)  
Master Components = Master Node  
Node Components = Worker Node

But you describe the Node Components as “[running] on all master and worker nodes”. Does this mean kubelet, kube-proxy, and container runtime also exist on Master Components? Or does this mean Node Components is a general term that refers to both Master Node and Worker Node?

---

<div class="post-metadata">

### Author: ![Giovanni](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/g/7ea924/32.png) [@Giovanni](https://forum.networklessons.com/u/Giovanni)
#### Post date: [July 15, 2021, 2:12pm UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/8 "2021-07-15T14:12:39Z")

</div>

Hi,

I know that it is an old topic but I’m tryng to replicate the ansible lab without success.

ansible give me this error.

```
TASK [Configure credentials] *************************************************************************************************************************************************************************************
ok: [R1]
ok: [R2]
ok: [R3]

TASK [Backup Configuration] **************************************************************************************************************************************************************************************
fatal: [R3]: FAILED! => {"ansible_facts": {"discovered_interpreter_python": "/usr/bin/python3"}, "changed": false, "msg": "operation requires privilege escalation"}
fatal: [R2]: FAILED! => {"ansible_facts": {"discovered_interpreter_python": "/usr/bin/python3"}, "changed": false, "msg": "operation requires privilege escalation"}
fatal: [R1]: FAILED! => {"ansible_facts": {"discovered_interpreter_python": "/usr/bin/python3"}, "changed": false, "msg": "operation requires privilege escalation"}

PLAY RECAP *******************************************************************************************************************************************************************************************************
R1 : ok=1 changed=0 unreachable=0 failed=1 skipped=0 rescued=0 ignored=0   
R2 : ok=1 changed=0 unreachable=0 failed=1 skipped=0 rescued=0 ignored=0   
R3 : ok=1 changed=0 unreachable=0 failed=1 skipped=0 rescued=0 ignored=0  

```

What I’m missing? the yaml file is the same of this lesson.

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [July 17, 2021, 5:54am UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/9 "2021-07-17T05:54:27Z")

</div>

Hello Giovanni

The message “operate requires privilege escalation” initially gave me the impression that the credentials being used are not provided with privilege level 15 on the Cisco IOS. I’m sure that’s something that you’ve checked however… 🙂

Looking a litter deeper I have found that others have had similar problems and it may be a result of a strange combination of Ansible version and IOS version. In particular, you can take a look at this GIT bug report for Ansible.

> <https://github.com/ansible/ansible/issues/40884>
>
> \##### SUMMARY
> 
> On some devices, ios\_config will create a traceback when runnin…g the ios\_config module. Nothing obviously different between devices that work and devices that do not, same model and some firmware. Sometimes running a play multiple times will result in it working, but usually they continue to fail. Attempted to change the tmp file location via remote\_tmp and local\_tmp, but still looks to be putting the tmp files into /tmp.
> 
> All the devices are configured to auto-enable into priv 15, and confirmed that the credentials do in fact work. The ios\_facts module works with no problems on this device, only the ios\_config module seems to be having issues.
> \##### ISSUE TYPE
> - Bug Report
> 
> \##### COMPONENT NAME
> 
> ios\_config
> 
> \##### ANSIBLE VERSION
> 
> \`\`\`
> ansible 2.5.3
> config file = /home/pffs/ansible-scripts/ansible.cfg
> configured module search path = \[u'/home/pffs/.ansible/plugins/modules', u'/usr/share/ansible/plugins/modules'\]
> ansible python module location = /usr/lib/python2.7/dist-packages/ansible
> executable location = /usr/bin/ansible
> python version = 2.7.12 (default, Dec 4 2017, 14:50:18) \[GCC 5.4.0 20160609\]
> \`\`\`
> 
> \##### CONFIGURATION
> 
> \`\`\`
> ANSIBLE\_PIPELINING(/home/pffs/ansible-scripts/ansible.cfg) = True
> DEFAULT\_CALLBACK\_WHITELIST(/home/pffs/ansible-scripts/ansible.cfg) = \['profile\_tasks', 'timer', 'json\_result'\]
> DEFAULT\_FORKS(/home/pffs/ansible-scripts/ansible.cfg) = 15
> DEFAULT\_HOST\_LIST(/home/pffs/ansible-scripts/ansible.cfg) = \[u'/home/pffs/ansible-scripts/inventory'\]
> DEFAULT\_LOCAL\_TMP(/home/pffs/ansible-scripts/ansible.cfg) = /home/pffs/.ansible/tmp/ansible-local-8904QiZGq4
> DEFAULT\_LOG\_PATH(/home/pffs/ansible-scripts/ansible.cfg) = /home/pffs/ansible-scripts/log
> HOST\_KEY\_CHECKING(/home/pffs/ansible-scripts/ansible.cfg) = False
> PERSISTENT\_COMMAND\_TIMEOUT(/home/pffs/ansible-scripts/ansible.cfg) = 45
> PERSISTENT\_CONNECT\_TIMEOUT(/home/pffs/ansible-scripts/ansible.cfg) = 90
> \`\`\`
> \##### OS / ENVIRONMENT
> 
> Ubuntu 16.04 connecting to Cisco 891FW running 15.4(3)M5
> \##### STEPS TO REPRODUCE
> 
> 
> 
> main playbook:
> \`\`\`yaml
> \---
> \- hosts: all
> gather\_facts: no
> vars\_files:
> - ../../tacacs.yaml
> 
> tasks:
> - ios\_config:
> lines:
> - logging monitor
> \`\`\`
> group\_vars/all.yaml:
> \`\`\`yaml
> \---
> ansible\_connection: network\_cli
> ansible\_network\_os: ios
> ansible\_become: yes
> ansible\_become\_method: enable
> ansible\_ssh\_common\_args: '-o ProxyCommand="ssh -W %h:%p -q bastion"'
> \`\`\`
> 
> 
> \##### EXPECTED RESULTS
> 
> Completes with change
> \##### ACTUAL RESULTS
> 
> Traces back:
> 
> \`\`\`
> ansible-playbook 2.5.3
> config file = /home/pffs/ansible-scripts/ansible.cfg
> configured module search path = \[u'/home/pffs/.ansible/plugins/modules', u'/usr/share/ansible/plugins/modules'\]
> ansible python module location = /usr/lib/python2.7/dist-packages/ansible
> executable location = /usr/bin/ansible-playbook
> python version = 2.7.12 (default, Dec 4 2017, 14:50:18) \[GCC 5.4.0 20160609\]
> Using /home/pffs/ansible-scripts/ansible.cfg as config file
> setting up inventory plugins
> Parsed /home/pffs/ansible-scripts/inventory inventory source with ini plugin
> Loading callback plugin default of type stdout, v2.0 from /usr/lib/python2.7/dist-packages/ansible/plugins/callback/default.pyc
> Loading callback plugin json\_result of type aggregate, v1.1 from /home/pffs/.ansible/plugins/callback/json\_result.pyc
> Loading callback plugin profile\_tasks of type aggregate, v2.0 from /usr/lib/python2.7/dist-packages/ansible/plugins/callback/profile\_tasks.pyc
> Loading callback plugin timer of type aggregate, v2.0 from /usr/lib/python2.7/dist-packages/ansible/plugins/callback/timer.pyc
> 
> PLAYBOOK: test.yaml \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*
> 1 plays in test.yaml
> Read vars\_file '../../tacacs.yaml'
> Read vars\_file '../../tacacs.yaml'
> 
> PLAY \[all\] \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*
> META: ran handlers
> Read vars\_file '../../tacacs.yaml'
> 
> TASK \[ios\_config\] \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*
> task path: /home/pffs/ansible-scripts/test.yaml:8
> Wednesday 30 May 2018 10:31:12 -0400 (0:00:00.714) 0:00:00.714 \*\*\*\*\*\*\*\*\*
> \<10.0.0.1\> attempting to start connection
> \<10.0.0.1\> using connection plugin network\_cli
> \<10.0.0.1\> local domain socket does not exist, starting it
> \<10.0.0.1\> control socket path is /home/pffs/.ansible/pc/1ac44613c3
> \<10.0.0.1\> \<10.0.0.1\> ESTABLISH CONNECTION FOR USER: scripts on PORT 22 TO 10.0.0.1
> \<10.0.0.1\> \<10.0.0.1\> CONFIGURE PROXY COMMAND FOR CONNECTION: ssh -W 10.0.0.1:22 -q bastion
> \<10.0.0.1\> \<10.0.0.1\> ssh connection done, setting terminal
> \<10.0.0.1\> \<10.0.0.1\> loaded terminal plugin for network\_os ios
> \<10.0.0.1\> \<10.0.0.1\> loaded cliconf plugin for network\_os ios
> \<10.0.0.1\> \<10.0.0.1\> firing event: on\_open\_shell()
> \<10.0.0.1\> \<10.0.0.1\> firing event: on\_become
> \<10.0.0.1\> \<10.0.0.1\> ssh connection has completed successfully
> \<10.0.0.1\> connection to remote device started successfully
> \<10.0.0.1\> local domain socket listeners started successfully
> \<10.0.0.1\>
> \<10.0.0.1\> local domain socket path is /home/pffs/.ansible/pc/1ac44613c3
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/network/\_\_init\_\_.py
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/network/common/parsing.py
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/six/\_\_init\_\_.py
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/basic.py
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/network/common/config.py
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/network/common/\_\_init\_\_.py
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/network/ios/ios.py
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/network/ios/\_\_init\_\_.py
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/parsing/convert\_bool.py
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/parsing/\_\_init\_\_.py
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/\_text.py
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/pycompat24.py
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/network/common/utils.py
> Using module\_utils file /usr/lib/python2.7/dist-packages/ansible/module\_utils/connection.py
> Using module file /usr/lib/python2.7/dist-packages/ansible/modules/network/ios/ios\_config.py
> \<10.0.0.1\> ESTABLISH LOCAL CONNECTION FOR USER: pffs
> \<10.0.0.1\> EXEC /bin/sh -c '/usr/bin/python && sleep 0'
> The full traceback is:
> Traceback (most recent call last):
> File "/tmp/ansible\_b\_9Rr0/ansible\_module\_ios\_config.py", line 583, in \<module\>
> main()
> File "/tmp/ansible\_b\_9Rr0/ansible\_module\_ios\_config.py", line 512, in main
> load\_config(module, commands)
> File "/tmp/ansible\_b\_9Rr0/ansible\_modlib.zip/ansible/module\_utils/network/ios/ios.py", line 168, in load\_config
> File "/tmp/ansible\_b\_9Rr0/ansible\_modlib.zip/ansible/module\_utils/connection.py", line 149, in \_\_rpc\_\_
> ansible.module\_utils.connection.ConnectionError: operation requires privilege escalation
> 
> fatal: \[dmvpn-1\]: FAILED! =\> {
> "changed": false,
> "module\_stderr": "Traceback (most recent call last):\\n File \\"/tmp/ansible\_b\_9Rr0/ansible\_module\_ios\_config.py\\", line 583, in \<module\>\\n main()\\n File \\"/tmp/ansible\_b\_9Rr0/ansible\_module\_ios\_config.py\\", line 512, in main\\n load\_config(module, command
> s)\\n File \\"/tmp/ansible\_b\_9Rr0/ansible\_modlib.zip/ansible/module\_utils/network/ios/ios.py\\", line 168, in load\_config\\n File \\"/tmp/ansible\_b\_9Rr0/ansible\_modlib.zip/ansible/module\_utils/connection.py\\", line 149, in \_\_rpc\_\_\\nansible.module\_utils.connection.Conn
> ectionError: operation requires privilege escalation\\n",
> "module\_stdout": "",
> "msg": "MODULE FAILURE",
> "rc": 1
> }
> to retry, use: --limit @/home/pffs/ansible-scripts/test.retry
> 
> PLAY RECAP \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*
> dmvpn-1 : ok=0 changed=0 unreachable=0 failed=1
> \`\`\`

If you do a search for that error, you’ll find more resources. Some have solved it by downgrading their Ansible version, while others have done so by adjusting other parameters.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![ruben.trazanet](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/ruben.trazanet/32/3913_2.png) [@ruben.trazanet](https://forum.networklessons.com/u/ruben.trazanet)
#### Post date: [November 28, 2021, 8:40pm UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/10 "2021-11-28T20:40:59Z")

</div>

Hi Team,  
Great lesson!! I tried to run a playbook connecting from a Centos 8 (ansible 2.9.27) to a cisco Cisco IOS XE Software, Version 16.06.07 by using ssh keys. I followed the lesson where ssh key connectivity is explained and I am able to connect with success. Despite all the changes I tried I always receive: fatal: [Cisco1941]: FAILED! =\> {“ansible\_facts”: {“discovered\_interpreter\_python”: “/usr/libexec/platform-python”}, “changed”: false, “msg”: “not a valid RSA private key file”}.

I uncommented this to disable SSH key host checking in ansible.cfg  
host\_key\_checking = False  
the key has 2048 module  
I also tried  
ansible-playbook --private-key=/root/.ssh/id\_rsa -u root playbooks/show\_version.yml

Any suggestions

Thanks in advanced for your support

Ruben

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 7, 2021, 12:17pm UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/11 "2021-12-07T12:17:01Z")

</div>

Hello Ruben,

What kind of SSH key do you have? Does it show up as OPENSSH or RSA?

```auto
[root@localhost test-ansible]# cat ~/.ssh/id_rsa | grep "KEY"
-----BEGIN OPENSSH PRIVATE KEY-----
-----END OPENSSH PRIVATE KEY-----

```

I think it has to do with the key format. The output above is from a CentOS 8 test machine.

Rene

---

<div class="post-metadata">

### Author: ![ruben.trazanet](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/ruben.trazanet/32/3913_2.png) [@ruben.trazanet](https://forum.networklessons.com/u/ruben.trazanet)
#### Post date: [December 7, 2021, 7:10pm UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/12 "2021-12-07T19:10:41Z")

</div>

> [@ReneMolenaar](#):
>
> `cat ~/.ssh/id_rsa | grep "KEY"`

Hi Rene,  
I am using a centos8 and the outpout of the command indicates openssh:

```auto
[root@centos8-ansible ssh]# cat ~/.ssh/id_rsa | grep "KEY"
-----BEGIN OPENSSH PRIVATE KEY-----
-----END OPENSSH PRIVATE KEY-----

```

I can however connect to the router from centos with no issues:

```auto
[root@centos8-ansible ssh]# ssh root@10.100.50.29
Cisco1941#

```

It is failing when using ansible playbook. Is there anyway to address this or should I use Ubuntu instead of Centos8?  
I will in any case deploy Ubuntu and give it a go. I will keep you posted.

Thanks

Ruben Sanchez  
Hi Rene,

I found out the root cause. Paramiko doesn’t support openssh. The workaround is PEM:

```auto
 sudo ssh-keygen -p -m PEM -f ~/.ssh/id_rsa. Now I get 
ruben@Ubuntu-20:~$ cat ~/.ssh/id_rsa | grep "KEY"
-----BEGIN RSA PRIVATE KEY-----
-----END RSA PRIVATE KEY-----

```

and playbooks are running with no issues. You put me in the right direction.  
Thank you  
Ruben Sanchez

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [December 9, 2021, 7:10am UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/13 "2021-12-09T07:10:27Z")

</div>

Hello Ruben

It’s great to hear that you found the root cause and resolved the issue! It’s helpful to have this information on the forum.

Thanks for updating your post!

Laz

---

<div class="post-metadata">

### Author: ![lennarnoc2020](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/l/5f8ce5/32.png) [@lennarnoc2020](https://forum.networklessons.com/u/lennarnoc2020)
#### Post date: [December 28, 2021, 4:07pm UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/14 "2021-12-28T16:07:52Z")

</div>

Hi Rene, while following the steps, the ssh connection was refused. I’m getting a Connection refused error when trying to ssh into the host IP.

---

<div class="post-metadata">

### Author: ![rod.deluhery](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/r/919ad9/32.png) [@rod.deluhery](https://forum.networklessons.com/u/rod.deluhery)
#### Post date: [December 29, 2021, 2:35pm UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/15 "2021-12-29T14:35:27Z")

</div>

in the ansible lab, copying a html file to the web root directory. question on this topic. is there a way to do this so the html file in on the ansible server itself, or another server? so doing a network copy (scp copy) from one host to another?  
thanks!

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [January 3, 2022, 7:06am UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/16 "2022-01-03T07:06:39Z")

</div>

Hello Michel

The SSH connectivity can sometimes be tricky, and it occasionally depends upon the versions you are using. The best way to troubleshoot this would be to debug SSH on the Cisco device to see the reason behind the refused connection so that you can further correct the problem. Take a look at this NetworkLessons note on [SSH connectivity troubleshooting](https://notes.networklessons.com/ssh-connectivity-troubleshooting) for some additional info.

Let us know how you get along and if you require any additional help.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [January 3, 2022, 7:12am UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/17 "2022-01-03T07:12:41Z")

</div>

Hello Rod

Anything you can do with the CLI can be automated. So if you are able to copy the HTML file to another server, either the ansible server or another server, using the CLI, then you can automate it using automation.

Before creating a playbook, the first thing that you should do is determine what you want to achieve, and how this can be achieved using the CLI. You then automate those CLI commands using the process described in the lesson.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![AZEAHMED](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/a/9fc348/32.png) [@AZEAHMED](https://forum.networklessons.com/u/AZEAHMED)
#### Post date: [April 16, 2023, 5:54am UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/18 "2023-04-16T05:54:16Z")

</div>

Hello Rene,

chef, puppet and ansible are config management tool. Are there any tools available to upgrade the router/server operating system . Any insight will appreciated.

P.S\> Found paid product below wanted to know about open source tool.

> **[Automating Software Upgrades | Itential Network Automation](https://www.itential.com/solutions/network-configuration-management/software-upgrades/)**
>
> Network teams need to modernize the way they accomplish software upgrades, leveraging automation to finally bring every device in their network up to current versions.

Thanks,  
Mu

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [April 19, 2023, 4:25am UTC](https://forum.networklessons.com/t/network-automation-and-orchestration/6319/19 "2023-04-19T04:25:14Z")

</div>

Hello Muhammad

Take a look at this answer here:

> [@Tools to upgrade the OS of routers or servers](https://forum.networklessons.com/t/tools-to-upgrade-the-os-of-routers-or-servers/35998/2):
>
> Hello Muhammad There are several tools available that can be used to automate the upgrading of router and server operating systems. First of all, Chef, Ansible as well as Puppet are all not only configuration management tools, but all three can be used for the purpose of upgrading server OS or router firmware. Specifically: Ansible: It is not only a configuration management tool, but it can also be used to automate software upgrades and manage patches for servers. Chef: It provides tools fo…

I hope this has been helpful!

Laz
