Network Plumber

Network Plumber

13 Cisco Routers. Zero Manual Configuration

How I used Nautobot Golden Config to deploy and verify a complete MPLS VPN control plane.

Byrn Baker's avatar
Byrn Baker
Aug 20, 2026
∙ Paid

TLDR: Part 3 of 10. We configure Nautobot credentials, Nornir, compliance features, and Golden Config Plans, then deploy generated intent to 13 Cisco IOS-XE routers in CML. We finish by verifying IS-IS, MPLS LDP, VPNv4 and VPNv6 route reflection, and PE-to-CE BGP.

Where we left off

Part 2 rendered intended configurations for the full topology from Nautobot Source of Truth data. This walkthrough narrows the deployment to the 13 Cisco routers that make up the service-provider network:

  • Four P routers running IS-IS and MPLS

  • Two VPNv4 and VPNv6 route reflectors

  • One border router

  • Three service-provider edge routers

  • Three customer edge routers

The intended files are stored in Git, but nothing should reach a router until we can answer four questions:

  1. Can the worker authenticate to every device?

  2. Does compliance extract the right configuration sections?

  3. Will those sections be sent in a dependency-safe order?

  4. Can we prove that running configuration matches intent after deployment?

This walkthrough sets up each layer in that order.

Deployment workflow

Golden Config deployment depends on fresh output from every earlier stage:

Credentials + primary IP + network reachability
    -> intended configuration
    -> running-config backup
    -> compliance rules
    -> compliance results
    -> Config Plan
    -> review and approval
    -> deployment
    -> new backup and compliance run

A Config Plan stores command text when it is created. If intent, backups, rules, or source-of-truth data change, generate a new plan.

User's avatar

Continue reading this post for free, courtesy of Byrn Baker.

Or purchase a paid subscription.
© 2026 Byrn Baker · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture