Skip to content
Back to skills

Cisco Ios Xe

ASecurity

Expert coverage of Cisco IOS-XE across all versions: Catalyst campus switches, ISR/ASR routers, SD-Access, NETCONF/RESTCONF, STP design, HSRP/VRRP, StackWise, and security hardening. Use for \"IOS-XE\", \"Catalyst 9000\", \"ISR\", \"ASR\", \"SD-Access\", \"Catalyst Center\", \"StackWise\", \"NETCONF\", \"RESTCONF\", \"HSRP\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- use the `routing-switching` skill.

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
devopspythongoshellbashreactnodegitapisecurityperformance

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 8 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill cisco-ios-xe --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cisco Ios Xe?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cisco Ios Xe
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-cisco-ios-xe/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-cisco-ios-xe)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cisco-ios-xe
description: "Expert coverage of Cisco IOS-XE across all versions: Catalyst campus switches, ISR/ASR routers, SD-Access, NETCONF/RESTCONF, STP design, HSRP/VRRP, StackWise, and security hardening. Use for \"IOS-XE\", \"Catalyst 9000\", \"ISR\", \"ASR\", \"SD-Access\", \"Catalyst Center\", \"StackWise\", \"NETCONF\", \"RESTCONF\", \"HSRP\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- use the `routing-switching` skill."
license: MIT
---

# Cisco IOS-XE

This skill covers Cisco IOS-XE across all supported versions (17.x). Areas of expertise include:

- Linux-based architecture with IOSd process, YANG models, and model-driven programmability
- Catalyst 9000 campus switches (9200, 9300, 9400, 9500, 9600)
- ISR and ASR branch/WAN routers
- SD-Access (LISP/VXLAN/CTS) and Catalyst Center integration
- NETCONF, RESTCONF, gNMI, and model-driven telemetry
- StackWise and StackWise Virtual
- Campus network design, STP, FHRP (HSRP/VRRP), and security hardening
- EEM (Embedded Event Manager) and Guest Shell automation
- Zero-Touch Provisioning (ZTP) and Plug and Play (PnP)

This skill's guidance spans IOS-XE holistically. When a question is version-specific, consult the matching `references/versions/` file.

## How to Approach Tasks

1. **Classify** the request:
   - **Troubleshooting** -- Load `references/diagnostics.md` for show commands and debug workflows
   - **Design / Architecture** -- Load `references/architecture.md` for YANG, NETCONF, SD-Access, ZTP
   - **Best practices / Hardening** -- Load `references/best-practices.md`
   - **Configuration** -- Apply IOS-XE expertise directly
   - **Automation** -- Focus on NETCONF/RESTCONF/gNMI and Guest Shell

2. **Identify version** -- Determine which IOS-XE version the user is running. If unclear, ask. Version matters for feature availability and supported platforms.

3. **Identify platform** -- Catalyst 9300 vs 9500 vs ISR matters for capabilities like StackWise, UADP ASIC features, throughput, and PoE.

4. **Load context** -- Read the relevant reference file for deep knowledge.

5. **Recommend** -- Provide actionable, platform-specific guidance with IOS-XE CLI examples.

6. **Verify** -- Suggest validation steps with specific show commands.

## Core Architecture

### Linux-Based Design

IOS-XE runs on a hardened Linux kernel. IOSd (the main IOS daemon) implements all routing, switching, and protocol logic as a single large process. Other services run as separate Linux processes:

- **IOSd**: Core routing/switching protocols, CLI, configuration management
- **NETCONF/YANG agent**: Separate process handling NETCONF (port 830) and RESTCONF (HTTPS)
- **gNMI agent**: gRPC-based telemetry and configuration
- **Guest Shell**: LXC container with Python 3, accessible via `guestshell run bash`
- **EEM**: Event-driven automation reacting to syslog, SNMP, CLI, timers

Crashes in auxiliary processes do not bring down IOSd. The Linux scheduler dynamically allocates CPU to IOSd and hosted applications.

### YANG Data Models

IOS-XE supports three families of YANG models:

| Family | Coverage | Use Case |
|---|---|---|
| Cisco Native (`Cisco-IOS-XE-*`) | Most complete; 1:1 with CLI | Full feature coverage |
| OpenConfig | Vendor-neutral subset | Multi-vendor environments |
| IETF | Standards-based minimal | Basic interface/routing state |

Models are published per-release at `github.com/YangModels/yang/tree/master/vendor/cisco/xe`.

### Programmability Interfaces

| Interface | Transport | Port | Format | Use Case |
|---|---|---|---|---|
| NETCONF | SSH | 830 | XML | Full config/operational CRUD; candidate datastore |
| RESTCONF | HTTPS | 443 | JSON/XML | Stateless HTTP API; integration-friendly |
| gNMI | gRPC | 9339 | Protobuf | Streaming telemetry; high-performance config |
| CLI | SSH | 22 | Text | Manual operations; legacy scripts |

### StackWise and StackWise Virtual

| Feature | StackWise | StackWise Virtual |
|---|---|---|
| Platforms | Cat 9200/9300 | Cat 9400/9500/9600 |
| Physical link | Dedicated ring cables | Standard 40/100G |
| Max members | 8 | 2 |
| Single IP | Yes | Yes |
| Upgrade | Rolling ISSU | SSO + ISSU |

### SD-Access Architecture

SD-Access uses LISP (control plane), VXLAN (data plane), and CTS/SGT (policy plane) with Catalyst Center as the management plane:

- **Control plane nodes**: LISP Map Server/Resolver -- maintain EID-to-RLOC mapping
- **Border nodes**: Connect fabric to non-fabric networks (default, external, internal)
- **Edge nodes**: Access layer VTEPs with SGT enforcement
- **Catalyst Center**: Intent-based provisioning, assurance, PnP

## Campus Design Patterns

### Three-Tier Traditional

```
Core (L3 routing, OSPF/BGP)
  └── Distribution (L3 SVIs, HSRP/VRRP, STP root, ACLs)
       └── Access (L2 VLANs, PortFast, BPDU Guard, 802.1X)
```

- Use Rapid PVST+ or MST with distribution as root
- Deploy HSRP/VRRP at distribution for gateway redundancy
- Keep STP domains bounded at each distribution block
- Layer 3 at distribution terminates VLANs -- no VLAN spanning multiple blocks

### SD-Access Fabric

```
Catalyst Center (management plane)
  └── LISP Control Plane Nodes
       ├── Border Nodes (external/default/internal)
       └── Edge Nodes (VTEPs + SGT enforcement)
```

Best for: greenfield Catalyst 9000 deployments, SGT micro-segmentation, centralized automation.

## Spanning Tree Best Practices

- Use **Rapid PVST+** for most campus deployments; **MST** for >100 VLANs
- Set explicit root priorities: primary 4096, secondary 8192
- Enable **PortFast** + **BPDU Guard** globally on all access ports
- Enable **Root Guard** on distribution uplinks to core
- Enable **Loop Guard** on all non-edge trunk ports
- Never rely on default STP priority (32768)

## FHRP Best Practices

- Use **HSRPv2** (supports IPv6, millisecond timers)
- Load-balance by making Dist-1 active for even VLANs, Dist-2 for odd
- Enable preempt with delay (`preempt delay minimum 30`)
- Use object tracking to decrement priority on uplink failure
- Authenticate HSRP with `authentication md5`

## Security Hardening

- Disable Telnet; SSH only with `transport input ssh` and `ip ssh version 2`
- Disable unused services: `no ip http server`, `no service pad`, `no ip bootp server`
- Configure AAA with TACACS+ and local fallback
- Apply management ACL on VTY lines
- Enable CoPP (auto-applied on Catalyst 9000, verify with `show policy-map control-plane`)
- DHCP Snooping + Dynamic ARP Inspection + IP Source Guard on access VLANs
- Shut down unused ports, assign to parking VLAN (999)

## Common Pitfalls

1. **Running features without licensing** -- DNA Advantage vs Essentials determines SD-Access, security features. Verify with `show license summary`.
2. **StackWise Virtual without DAD** -- Always configure Dual Active Detection to prevent split-brain after SVL link failure.
3. **VLAN 1 as native** -- Change native VLAN on all trunks to a dedicated unused VLAN (e.g., 999) to prevent VLAN hopping attacks.
4. **Ignoring TCAM** -- SDM template determines TCAM allocation for ACLs, routes, MAC entries. Check with `show sdm prefer` and adjust for your use case.
5. **Telnet still enabled** -- IOS-XE 17.18+ warns on insecure protocols. Disable Telnet proactively.
6. **No config archive** -- Configure `archive` for automatic configuration backups on every write.

## Version-Specific Guidance

| Version | Reference | What's version-specific |
|---|---|---|
| 17.12 | `references/versions/17.12.md` | Dublin LTS release; campus EVPN, MACsec, gNMI ON_CHANGE |
| 17.18 | `references/versions/17.18.md` | Fuentes LTS; SSHv1 removal, SRv6, Wi-Fi 7, legacy protocol deprecation |

## Reference Files

Load these when you need deep knowledge for a specific area:

- `references/architecture.md` -- Linux/IOSd layers, YANG models, NETCONF/RESTCONF/gNMI, SD-Access LISP/VXLAN/CTS, Catalyst Center API, ZTP/PnP, Guest Shell, EEM, StackWise
- `references/diagnostics.md` -- Show command reference for routing, interfaces, L2, security, platform/hardware, FHRP, NETCONF/RESTCONF examples, cross-platform CLI comparison
- `references/best-practices.md` -- Campus design (traditional vs SD-Access), STP configuration, FHRP setup, security hardening, AAA, CoPP, upgrade procedures, ISSU

## Diagnostic Scripts

Ready-made SSH show-command bundles (read-only) in `scripts/`.

- `scripts/01-device-health.sh` -- Version/uptime, CPU/memory, environment, recent logs
- `scripts/02-interface-errors.sh` -- Error/drop counters, err-disabled ports, flap detection (run twice for deltas)

Files in this skill

  • SKILL.md8.4 KB
  • references/architecture.md5.7 KB
  • references/best-practices.md2.7 KB
  • references/diagnostics.md4.8 KB
  • references/versions/17.12.md3.2 KB
  • references/versions/17.18.md4.5 KB
  • scripts/01-device-health.sh1.1 KB
  • scripts/02-interface-errors.sh1.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…