如何用正则表达式高效分析Cisco交换机端口信息?
Great question—parsing Cisco switch port output can be such a headache because CLI formats shift depending on which command you run (think show ip interface brief vs show interfaces). Let’s walk through this with real-world examples and the most reliable approaches.
First, let’s anchor this to typical Cisco output you might see:
Sample lines from
show ip interface brief:FastEthernet0/1 192.168.1.1 YES NVRAM up up GigabitEthernet1/0/2 unassigned YES unset down down Vlan1 192.168.0.1 YES NVRAM up upSample lines from
show interfaces:FastEthernet0/1 is up, line protocol is up (connected) Hardware is Fast Ethernet, address is 001a.2f55.6789 (bia 001a.2f55.6789) GigabitEthernet1/0/2 is down, line protocol is down (notconnect) Hardware is Gigabit Ethernet, address is 001a.2f55.678a (bia 001a.2f55.678a)
1. Start by Defining Your Exact Targets
Before writing any regex or picking a tool, be crystal clear on what data you need to extract. For example:
- Port name (e.g.,
FastEthernet0/1,GigabitEthernet1/0/2) - Administrative status (
up/down) - Operational status (
up/down) - IP address (if applicable)
- MAC address
2. Regex: Tailor It to Your Specific Command Output
Regex works well if you’re dealing with consistent output formatting. Here are tested examples for common commands:
For show ip interface brief
This tabular output has fixed columns, so regex can target them directly. Use this pattern to capture port name, IP, admin status, and operational status:
^(\S+)\s+(\S+)\s+\S+\s+\S+\s+(\S+)\s+(\S+)$
- Group 1: Port name
- Group 2: IP address (or
unassigned) - Group 3: Admin status (
up/down) - Group 4: Operational status (
up/down)
For show interfaces
The main status line is straightforward. Use this regex to pull core port details:
^(\S+) is (\S+), line protocol is (\S+) \((\S+)\)$
- Group 1: Port name
- Group 2: Admin status (
up/down) - Group 3: Operational status (
up/down) - Group 4: Connection state (
connected/notconnect)
To grab MAC addresses from the hardware line:
^ Hardware is .+, address is (\S+) \(bia (\S+)\)$
- Group 1: Current MAC address
- Group 2: Burned-in MAC address
3. Better Than Regex: Use Purpose-Built Parsers
Regex breaks easily if Cisco tweaks output formatting (like adding new columns or adjusting spacing). For production-grade work, use tools built for network CLI parsing:
TextFSM
TextFSM uses templates to match output structures, returning clean structured data (dictionaries/lists). Here’s a template for show ip interface brief:
Value PORT (\S+) Value IP (\S+) Value ADMIN_STATUS (\S+) Value OPER_STATUS (\S+) Start ^${PORT}\s+${IP}\s+\S+\s+\S+\s+${ADMIN_STATUS}\s+${OPER_STATUS} -> Record
Netmiko + NTC Templates (Python)
If you’re automating, Netmiko connects to switches, runs commands, and uses pre-built NTC templates to parse output in one go:
from netmiko import ConnectHandler from ntc_templates.parse import parse_output device = { 'device_type': 'cisco_ios', 'ip': '192.168.1.1', 'username': 'admin', 'password': 'secret', } connection = ConnectHandler(**device) output = connection.send_command('show ip interface brief') parsed_data = parse_output(platform='cisco_ios', command='show ip interface brief', data=output) connection.disconnect() # parsed_data will look like: # [{'port': 'FastEthernet0/1', 'ip': '192.168.1.1', 'admin_status': 'up', 'oper_status': 'up'}, ...]
4. Pro Tips for Success
- Test against your actual switch output—generic examples might not account for model-specific variations.
- For multi-line output (like
show interfaces), ensure your tool handles line breaks (TextFSM and Netmiko do this automatically). - If stuck, print a sample output and break down its structure: note fixed strings, variable data, and where your target info sits relative to fixed text.
内容的提问来源于stack exchange,提问作者Razdom

