GNS3 notes

Practical notes for running GNS3 clients, servers, and lab integrations.

Tips

Cisco L2

When setting up a trunk port, use:

spanning-tree portfast trunk

FortiGate

When creating VLAN interfaces, avoid assigning vlan1 as a production interface.

Install client (Ubuntu/Debian)

sudo add-apt-repository ppa:gns3/ppa
sudo dpkg --add-architecture i386
sudo apt update
sudo apt install gns3-iou gns3-gui

Install GNS3 server

cd /tmp
curl -fsSL https://raw.githubusercontent.com/GNS3/gns3-server/master/scripts/remote-install.sh -o gns3-remote-install.sh
bash gns3-remote-install.sh --with-openvpn --with-iou --with-i386-repository

Default API/service port is 3080.

Fix server binding to wrong interface

If the server binds to a Docker bridge interface instead of the VM NIC, edit:

sudo nano /etc/gns3/gns3_server.conf

Set:

[Server]
host = 0.0.0.0
port = 3080

Then restart:

sudo systemctl restart gns3server
sudo systemctl status gns3server

Start services on boot

sudo systemctl enable gns3server
sudo systemctl start gns3server

If 32-bit support is missing (IOU)

sudo dpkg --add-architecture i386
sudo apt-get update
sudo apt-get install gns3-iou

Create a Docker management network

sudo docker network create \
  --driver=bridge \
  --subnet=100.64.1.0/29 \
  --ip-range=100.64.1.0/29 \
  --gateway=100.64.1.1 \
  --opt com.docker.network.bridge.name=br-wan2 \
  ISP2

Check Docker network details

docker network ls
docker network inspect <network_name_or_id>

Troubleshooting: iptables blocking lab traffic

If GNS3 nodes cannot reach each other or external networks, host firewall rules may be dropping forwarded traffic.

Temporary flush (for troubleshooting only):

sudo iptables -F
sudo iptables -t nat -F
sudo iptables -t mangle -F
sudo iptables -X

If needed, stop firewall services temporarily:

sudo systemctl stop netfilter-persistent
sudo systemctl stop ufw

After testing, re-enable your firewall and apply proper allow rules for GNS3 instead of leaving filtering disabled.

FortiGate VM image

Download VM_64-KVM from Fortinet, extract it, and use fortios.qcow2 in GNS3.

IOU setup

Generate IOU license with keygen script

wget http://www.ipvanquish.com/download/CiscoIOUKeygen3f.py
python3 CiscoIOUKeygen3f.py

You should get output similar to:

[license]
gns3vm = 73635fd3b0a13ah0;

Add this under GNS3 preferences: Edit -> Preferences -> IOS on UNIX. Keep the trailing semicolon (;).

Alternative IOU script

#!/usr/bin/python3
 
import hashlib
import os
import socket
import struct
 
print("*********************************************************************")
print("Cisco IOU License Generator - Kal 2011, python port of 2006 C version")
 
# Get host ID and host name to calculate host key.
hostid = os.popen("hostid").read().strip()
hostname = socket.gethostname()
ioukey = int(hostid, 16)
 
for char in hostname:
    ioukey += ord(char)
 
print(f"hostid={hostid}, hostname={hostname}, ioukey={hex(ioukey)[2:]}")
 
iou_pad1 = b"\x4B\x58\x21\x81\x56\x7B\x0D\xF3\x21\x43\x9B\x7E\xAC\x1D\xE6\x8A"
iou_pad2 = b"\x80" + 39 * b"\0"
md5_input = iou_pad1 + iou_pad2 + struct.pack("!i", ioukey) + iou_pad1
iou_license = hashlib.md5(md5_input).hexdigest()[:16]
 
print("\nAdd the following text to ~/.iourc:")
print(f"[license]\n{hostname} = {iou_license};\n")
 
with open("iourc.txt", "w", encoding="utf-8") as out_file:
    out_file.write(f"[license]\n{hostname} = {iou_license};\n")
 
print("^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^")
print("Already copied to iourc.txt\n")
print("You can disable phone-home with:")
print("echo '127.0.0.127 xml.cisco.com' | sudo tee -a /etc/hosts")