<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>NETCONF</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/NETCONF"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-NETCONF rootpage-NETCONF skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">NETCONF</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1305433154">
/* start https://en.wikipedia.org/ */
.mw-parser-output .ambox{border:1px solid #a2a9b1;border-left:10px solid #36c;background-color:#fbfbfb;box-sizing:border-box}.mw-parser-output .ambox+link+.ambox,.mw-parser-output .ambox+link+style+.ambox,.mw-parser-output .ambox+link+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+style+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+link+.ambox{margin-top:-1px}html body.mediawiki .mw-parser-output .ambox.mbox-small-left{margin:4px 1em 4px 0;overflow:hidden;width:238px;border-collapse:collapse;font-size:88%;line-height:1.25em}.mw-parser-output .ambox-speedy{border-left:10px solid #b32424;background-color:#fee7e6}.mw-parser-output .ambox-delete{border-left:10px solid #b32424}.mw-parser-output .ambox-content{border-left:10px solid #f28500}.mw-parser-output .ambox-style{border-left:10px solid #fc3}.mw-parser-output .ambox-move{border-left:10px solid #9932cc}.mw-parser-output .ambox-protection{border-left:10px solid #a2a9b1}.mw-parser-output .ambox .mbox-text{border:none;padding:0.25em 0.5em;width:100%}.mw-parser-output .ambox .mbox-image{border:none;padding:2px 0 2px 0.5em;text-align:center}.mw-parser-output .ambox .mbox-imageright{border:none;padding:2px 0.5em 2px 0;text-align:center}.mw-parser-output .ambox .mbox-empty-cell{border:none;padding:0;width:1px}.mw-parser-output .ambox .mbox-image-div{width:52px}@media(min-width:720px){.mw-parser-output .ambox{margin:0 10%}}@media print{body.ns-0 .mw-parser-output .ambox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1248332772">
/* start https://en.wikipedia.org/ */
.mw-parser-output .multiple-issues-text{width:95%;margin:0.2em 0}.mw-parser-output .multiple-issues-text>.mw-collapsible-content{margin-top:0.3em}.mw-parser-output .compact-ambox .ambox{border:none;border-collapse:collapse;background-color:transparent;margin:0 0 0 1.6em!important;padding:0!important;width:auto;display:block}body.mediawiki .mw-parser-output .compact-ambox .ambox.mbox-small-left{font-size:100%;width:auto;margin:0}.mw-parser-output .compact-ambox .ambox .mbox-text{padding:0!important;margin:0!important}.mw-parser-output .compact-ambox .ambox .mbox-text-span{display:list-item;line-height:1.5em;list-style-type:disc}body.skin-minerva .mw-parser-output .multiple-issues-text>.mw-collapsible-toggle,.mw-parser-output .compact-ambox .ambox .mbox-image,.mw-parser-output .compact-ambox .ambox .mbox-imageright,.mw-parser-output .compact-ambox .ambox .mbox-empty-cell,.mw-parser-output .compact-ambox .hide-when-compact{display:none}
/* end https://en.wikipedia.org/ */
</style>
<p>The <b>Network Configuration Protocol</b> (<b>NETCONF</b>) is a <a href="Network_management" title="Network management">network management</a> protocol developed and standardized by the <a href="Internet_Engineering_Task_Force" title="Internet Engineering Task Force">IETF</a>. It was developed in the NETCONF working group<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> and published in December 2006 as RFC 4741<sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> and later revised in June 2011 and published as RFC 6241.<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> The NETCONF protocol specification is an Internet Standards Track document.
</p><p>NETCONF provides mechanisms to install, manipulate, and delete the configuration of network devices. Its operations are realized on top of a simple <a href="Remote_Procedure_Call" class="mw-redirect" title="Remote Procedure Call">Remote Procedure Call</a> (RPC) layer. The NETCONF protocol uses an <a href="Extensible_Markup_Language" class="mw-redirect" title="Extensible Markup Language">Extensible Markup Language</a> (XML) based data encoding for the configuration data as well as the protocol messages. The protocol messages are exchanged on top of a secure transport protocol.
</p><p>The NETCONF protocol can be conceptually partitioned into four layers:
</p>
<ol><li>The Content layer consists of configuration data and notification data.</li>
<li>The Operations layer defines a set of base protocol operations to retrieve and edit the configuration data.</li>
<li>The Messages layer provides a mechanism for encoding remote procedure calls (RPCs) and notifications.</li>
<li>The Secure Transport layer provides a secure and reliable transport of messages between a client and a server.</li></ol>
<p>The NETCONF protocol has been implemented in network devices such as routers and switches by some major equipment vendors. One particular strength of NETCONF is its support for robust configuration change using transactions involving a number of devices.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="History">History</h2></div>
<p>The IETF developed the <a href="Simple_Network_Management_Protocol" title="Simple Network Management Protocol">Simple Network Management Protocol</a> (SNMP) in the late 1980s and it proved to be a very popular <a href="Network_management" title="Network management">network management</a> <a href="Communications_protocol" class="mw-redirect" title="Communications protocol">protocol</a>. In the early part of the 21st century it became apparent that in spite of what was originally intended, SNMP was not being used to configure network equipment, but was mainly being used for <a href="Network_monitoring" title="Network monitoring">network monitoring</a>. In June 2002, the <a href="Internet_Architecture_Board" title="Internet Architecture Board">Internet Architecture Board</a> and key members of the IETF's network management community got together with network operators to discuss the situation. The results of this meeting are documented in RFC 3535. It turned out that each network operator was primarily using a different proprietary <a href="Command-line_interface" title="Command-line interface">command-line interface</a> (CLI) to configure their devices. This had a number of features that the operators liked, including the fact that it was text-based, as opposed to the <a href="Basic_Encoding_Rules" class="mw-redirect" title="Basic Encoding Rules">BER-encoded</a> SNMP. In addition, many equipment vendors did not provide the option to completely configure their devices via SNMP. As operators generally liked to write scripts to help manage their boxes, they found the SNMP CLI lacking in a number of ways. Most notably was the unpredictable nature of the output. The content and formatting of output was prone to change in unpredictable ways.
</p><p>Around this same time, <a href="Juniper_Networks" title="Juniper Networks">Juniper Networks</a> had been using an XML-based network management approach. This was brought to the IETF and shared with the broader community. Collectively, these two events led the IETF in May 2003 to the creation of the NETCONF working group. This working group was chartered to work on a network configuration protocol, which would better align with the needs of network operators and equipment vendors. The first version of the base NETCONF protocol was published as RFC 4741 in December 2006. Several extensions were published in subsequent years (notifications in RFC 5277 in July 2008, partial locks in RFC 5717 in December 2009, with-defaults in RFC 6243 in June 2011, system notifications in RFC 6470 in February 2012, access control in RFC 6536 in March 2012). A revised version of the base NETCONF protocol was published as RFC 6241 in June 2011.
</p>
<div class="mw-heading mw-heading2"><h2 id="Protocol_layers">Protocol layers</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Content">Content</h3></div>
<p>The content of NETCONF operations is well-formed XML. Most content is related to <a href="Network_management" title="Network management">network management</a>. Subsequently, support for encoding in <a href="JavaScript_Object_Notation" class="mw-redirect" title="JavaScript Object Notation">JavaScript Object Notation</a> (JSON) was also added.
</p><p>The NETMOD working group has completed work to define a "human-friendly" modeling language for defining the semantics of operational data, configuration data, notifications, and operations, called <a href="YANG" title="YANG">YANG</a>. YANG is defined in RFC 6020 (version 1) and RFC 7950 (version 1.1), and is accompanied by the "Common YANG Data Types" found in RFC 6991.
</p><p>During the summer of 2010, the NETMOD working group was re-chartered to work on core configuration models (system, interface, and routing) as well as work on compatibility with the <a href="SNMP" class="mw-redirect" title="SNMP">SNMP</a> modeling language.
</p>
<div class="mw-heading mw-heading3"><h3 id="Operations">Operations</h3></div>
<p>The base protocol defines the following protocol operations:
</p>
<table class="wikitable">
<tbody><tr>
<th>Operation</th>
<th>Description
</th></tr>
<tr>
<td><get></td>
<td>Retrieve running configuration and device state information
</td></tr>
<tr>
<td><get-config></td>
<td>Retrieve all or part of a specified configuration datastore
</td></tr>
<tr>
<td><edit-config></td>
<td>Edit a configuration datastore by creating, deleting, merging or replacing content
</td></tr>
<tr>
<td><copy-config></td>
<td>Copy an entire configuration datastore to another configuration datastore
</td></tr>
<tr>
<td><delete-config></td>
<td>Delete a configuration datastore
</td></tr>
<tr>
<td><lock></td>
<td>Lock an entire configuration datastore of a device
</td></tr>
<tr>
<td><unlock></td>
<td>Release a configuration datastore lock previously obtained with the <lock> operation
</td></tr>
<tr>
<td><close-session></td>
<td>Request graceful termination of a NETCONF session
</td></tr>
<tr>
<td><kill-session></td>
<td>Force the termination of a NETCONF session
</td></tr>
</tbody></table>
<p>Basic NETCONF functionality can be extended by the definition of NETCONF capabilities. The set of additional protocol features that an implementation supports is communicated between the server and the client during the capability exchange portion of session setup. Mandatory protocol features are not included in the capability exchange since they are assumed. RFC 4741 defines a number of optional capabilities including :xpath and :validate. Note that <a rel="nofollow" class="external text" href="http://tools.ietf.org/html/rfc6241">RFC 6241</a> obsoletes RFC 4741.
</p><p>A capability to support subscribing and receiving asynchronous event notifications is published in RFC 5277. This document defines the <create-subscription> operation, which enables creating real-time and replay subscriptions. Notifications are then sent asynchronously using the <notification> construct. It also defines the :interleave capability, which when supported with the basic :notification capability facilitates the processing of other NETCONF operations while the subscription is active.
</p><p>A capability to support partial locking of the running configuration is defined in RFC 5717. This allows
multiple sessions to edit non-overlapping sub-trees within the running configuration. Without this capability, the only lock available is for the entire configuration.
</p><p>A capability to monitor the NETCONF protocol is defined in RFC 6022. This document contains a data model including information about NETCONF datastores, sessions, locks, and statistics that facilitates the management of a NETCONF server. It also defines methods for NETCONF clients to discover data models supported by a NETCONF server and defines the <get-schema> operation to retrieve them.
</p>
<div class="mw-heading mw-heading3"><h3 id="Messages">Messages</h3></div>
<p>The NETCONF messages layer provides a simple, transport-independent framing mechanism for encoding
</p>
<ul><li>RPC invocations (<rpc> messages),</li>
<li>RPC results (<rpc-reply> messages), and</li>
<li>event notifications (<notification> messages).</li></ul>
<p>Every NETCONF message is a well-formed XML document. An RPC result is linked to an RPC invocation by a message-id attribute. NETCONF messages can be pipelined, i.e., a client can invoke multiple RPCs without having to wait for RPC result messages first. RPC messages are defined in RFC 6241 and notification messages are defined in RFC 5277.
</p>
<div class="mw-heading mw-heading3"><h3 id="Transport">Transport</h3></div>
<ul><li>NETCONF Protocol over Secure Shell (SSH): rfc:6242</li>
<li>NETCONF Protocol over Transport Layer Security (TLS) with Mutual X.509 Authentication: rfc:7589</li></ul>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="YANG" title="YANG">YANG</a></li>
<li>RESTCONF</li>
<li><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><cite class="citation audio-visual cs1">Stefan Wallin (2014-10-18). <a rel="nofollow" class="external text" href="https://www.youtube.com/watch?v=xoPZO1N-x38"><i>NETCONF Tutorial</i></a> (YouTube). Stockholm: tail-f. <a rel="nofollow" class="external text" href="https://ghostarchive.org/varchive/youtube/20211221/xoPZO1N-x38">Archived</a> from the original on 2021-12-21.</cite></li>
<li><a href="Network_management" title="Network management">Network management</a></li>
<li><a href="Configuration_management" title="Configuration management">Configuration management</a></li>
<li><a href="Network_monitoring" title="Network monitoring">Network monitoring</a></li>
<li><a href="XML_Schema_(W3C)" title="XML Schema (W3C)">XML Schema</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://tools.ietf.org/wg/netconf/">"Network Configuration Working Group"</a>. IETF.</cite></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><cite id="CITEREFEnns2006" class="citation techreport cs1">Enns, Rob (2006). <a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc4741"><i>NETCONF Configuration Protocol</i></a> (Technical report). IETF. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC4741">10.17487/RFC4741</a></span>. RFC4741.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite id="CITEREFEnnsBjörklundSchönwälderBierman2011" class="citation techreport cs1">Enns, Rob; Björklund, Martin; Schönwälder, Jürgen; Bierman, Andy (2011). <a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc6241"><i>Network Configuration Protocol (NETCONF)</i></a> (Technical report). IETF. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC6241">10.17487/RFC6241</a></span>. RFC6241.</cite></span>
</li>
</ol></div></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2024-12-22" href="https://en.wikipedia.org/wiki/?title=NETCONF&oldid=1264651640">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>