Ansible控制节点无法连接Cisco交换机,请求技术支持
问题:Ansible无法连接Cisco交换机(SSH/Ping正常但Ansible操作失败)
问题详情
能通过ping/ssh正常连通目标Cisco交换机,但使用Ansible临时命令操作时失败。
执行的命令
ansible cisco_node -m ping
错误信息
[WARNING]: sftp transfer mechanism failed on [11.11.11.203]. Use ANSIBLE_DEBUG=1 to see detailed information [WARNING]: scp transfer mechanism failed on [11.11.11.203]. Use ANSIBLE_DEBUG=1 to see detailed information cisco_node | FAILED! => { "changed": false, "module_stderr": "Shared connection to 11.11.11.203 closed.\r\n", "module_stdout": "\r\n", "msg": "MODULE FAILURE\nSee stdout/stderr for the exact error", "rc": 0 }
环境信息
ansible version: core 2.15.4 which python:/usr/bin/python
已尝试操作
指定Python路径为/usr/bin/python3,问题仍存在。
解决方案建议
1. 修改文件传输方式
Cisco IOS设备通常不支持SFTP/SCP,需调整Ansible的连接参数:
- 在inventory文件中添加配置:
cisco_node ansible_host=11.11.11.203 ansible_connection=paramiko ansible_scp_if_ssh=False - 或临时在命令行指定:
ansible cisco_node -m ping -e "ansible_connection=paramiko ansible_scp_if_ssh=False"
2. 使用Cisco专用ping模块
通用ping模块依赖目标设备的Python环境,而Cisco IOS默认无Python,需使用专用模块:
- 先安装对应集合:
ansible-galaxy collection install community.network - 执行专用ping命令:
ansible cisco_node -m community.network.ios_ping -a "dest=127.0.0.1"
3. 开启调试模式排查细节
执行命令时添加调试参数,获取更详细的错误日志:
ANSIBLE_DEBUG=1 ansible cisco_node -m ping
4. 确认目标设备的Python支持(仅适用于部分型号)
如果你的交换机型号支持Python(如IOS XE),可在inventory中明确指定Python路径:
cisco_node ansible_python_interpreter=/usr/bin/python3
内容的提问来源于stack exchange,提问作者Mr A
相关产品推荐
相关产品推荐

