GNS3 notes
Practical notes for running GNS3 clients, servers, and lab integrations.
Tips
Cisco L2
When setting up a trunk port, use:
spanning-tree portfast trunkFortiGate
When creating VLAN interfaces, avoid assigning vlan1 as a production interface.
Install client (Ubuntu/Debian)
sudo add-apt-repository ppa:gns3/ppa
sudo dpkg --add-architecture i386
sudo apt update
sudo apt install gns3-iou gns3-guiInstall GNS3 server
cd /tmp
curl -fsSL https://raw.githubusercontent.com/GNS3/gns3-server/master/scripts/remote-install.sh -o gns3-remote-install.sh
bash gns3-remote-install.sh --with-openvpn --with-iou --with-i386-repositoryDefault API/service port is 3080.
Fix server binding to wrong interface
If the server binds to a Docker bridge interface instead of the VM NIC, edit:
sudo nano /etc/gns3/gns3_server.confSet:
[Server]
host = 0.0.0.0
port = 3080Then restart:
sudo systemctl restart gns3server
sudo systemctl status gns3serverStart services on boot
sudo systemctl enable gns3server
sudo systemctl start gns3serverIf 32-bit support is missing (IOU)
sudo dpkg --add-architecture i386
sudo apt-get update
sudo apt-get install gns3-iouCreate a Docker management network
sudo docker network create \
--driver=bridge \
--subnet=100.64.1.0/29 \
--ip-range=100.64.1.0/29 \
--gateway=100.64.1.1 \
--opt com.docker.network.bridge.name=br-wan2 \
ISP2Check Docker network details
docker network ls
docker network inspect <network_name_or_id>Troubleshooting: iptables blocking lab traffic
If GNS3 nodes cannot reach each other or external networks, host firewall rules may be dropping forwarded traffic.
Temporary flush (for troubleshooting only):
sudo iptables -F
sudo iptables -t nat -F
sudo iptables -t mangle -F
sudo iptables -XIf needed, stop firewall services temporarily:
sudo systemctl stop netfilter-persistent
sudo systemctl stop ufwAfter testing, re-enable your firewall and apply proper allow rules for GNS3 instead of leaving filtering disabled.
FortiGate VM image
Download VM_64-KVM from Fortinet, extract it, and use fortios.qcow2 in GNS3.
IOU setup
Generate IOU license with keygen script
wget http://www.ipvanquish.com/download/CiscoIOUKeygen3f.py
python3 CiscoIOUKeygen3f.pyYou should get output similar to:
[license]
gns3vm = 73635fd3b0a13ah0;Add this under GNS3 preferences: Edit -> Preferences -> IOS on UNIX.
Keep the trailing semicolon (;).
Alternative IOU script
#!/usr/bin/python3
import hashlib
import os
import socket
import struct
print("*********************************************************************")
print("Cisco IOU License Generator - Kal 2011, python port of 2006 C version")
# Get host ID and host name to calculate host key.
hostid = os.popen("hostid").read().strip()
hostname = socket.gethostname()
ioukey = int(hostid, 16)
for char in hostname:
ioukey += ord(char)
print(f"hostid={hostid}, hostname={hostname}, ioukey={hex(ioukey)[2:]}")
iou_pad1 = b"\x4B\x58\x21\x81\x56\x7B\x0D\xF3\x21\x43\x9B\x7E\xAC\x1D\xE6\x8A"
iou_pad2 = b"\x80" + 39 * b"\0"
md5_input = iou_pad1 + iou_pad2 + struct.pack("!i", ioukey) + iou_pad1
iou_license = hashlib.md5(md5_input).hexdigest()[:16]
print("\nAdd the following text to ~/.iourc:")
print(f"[license]\n{hostname} = {iou_license};\n")
with open("iourc.txt", "w", encoding="utf-8") as out_file:
out_file.write(f"[license]\n{hostname} = {iou_license};\n")
print("^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^")
print("Already copied to iourc.txt\n")
print("You can disable phone-home with:")
print("echo '127.0.0.127 xml.cisco.com' | sudo tee -a /etc/hosts")