> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.itential.com/itential-gateway/4/openconfig-integration/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.itential.com/_mcp/server. # OpenConfig integration > Configure and use OpenConfig (gRPC) in Itential Gateway for device connections using gNMI and gNOI. Beginning in the 2023.2 release, Itential Gateway works with `OpenConfig` (previously referred to as gRPC) for connecting devices. OpenConfig is a cross-platform, open source framework for implementing RPC (Remote Procedure Call) APIs in any environment. As a framework, OpenConfig offers pluggable support for load balancing, tracing, health checking and authentication with a lower processing complexity. > **Info** > > For related reading, see [gRPC documentation](https://grpc.io/docs/). ## Install OpenConfig To get started, install `pip` in the virtual environment. Restart Gateway. ```bash pip install grpcio==1.53.0 pip install pygnmi ``` ## Verify OpenConfig is enabled Go to **Configuration** in Gateway using the left side navigation and click OpenConfig (e.g. `gRPC`) to verify the setting has been enabled. Select the checkbox and click the **Save** icon. ![](/_fern-img/03a43186baff024e38dd759c569fe2a95c4f9654727a79b08fe844ecd6926ff5.webp) ## Configure OpenConfig Use the side-navigation menus in Gateway to open the subheading options. In this example, `gRPC` contains nested subheadings (menus) for: * Inventory * gNMI * gNOI ### Inventory The **Inventory** list contains devices created to run and use OpenConfig. The device will appear in the left side navigation bar. Clicking on the device will display parameters (i.e., host, port, username, etc.) and values specific to the device. Click the pencil icon to edit the parameters. ![](/_fern-img/f9f98db9002493845feb745a76e4f4c59e77fd2cdb09ff6f29aded120f46bdde.webp) ### gNMI Use **gNMI** to configure `get` and `set` for OpenConfig. The `gnmi_get` mechanism is used to pull in or acquire data. ![](/_fern-img/95d967bcef96b22f15c749fb461194b9060b6b9b19adc4005df43961888fbacc.webp) The `gnmi_set` mechanism is used to execute a command. ![](/_fern-img/081f32199f0ecb20513180505e8a9f152bfc12c721183b2f85a38cfd9c1b438a.webp) ### gNOI Use **gNOI** for operational commands on a device such as ping, trace route, and reboot. ![](/_fern-img/2a59f662adddf7b3bfa0c09e14621da1fc94d51c2e8886256b43158e0e1e1df0.webp) ## Create devices in OpenConfig To create an OpenConfig device, click the **+** sign in the top toolbar above the left side navigation. A **Create** dialog opens. Use the dropdown to make your selection (e.g., `GRPC Device`). Input a device name and configure the variables needed to create the device. Once all the device variables are set, click the **Create** button. ![](/_fern-img/14a613c272fee2695c3ab2a8e9019a5187127da35c40132312c2ed385d808f09.webp) ### OpenConfig device variables Variable datatypes can be found in the OpenAPI v3 specification in the help section of the Gateway UI. | Variable | Description | Required | | -------------------- | -------------------------------------------------------------------- | -------- | | host | The hostname or IP address of the OpenConfig device. | Yes | | port | The OpenConfig TCP port to use. | Yes | | username | OpenConfig username. | Yes | | password | OpenConfig password. | Yes | | insecure | Used to support (or not support) a non-TLS connection to the device. | Yes | | debug | Debug OpenConfig operations (advanced). | Yes | | path\_cert | Path to the TLS root certificate store. | No | | path\_key | Path to the OpenConfig client certificate key. | No | | path\_root | Path to the TLS root certificate store. | No | | openconfig\_override | OpenConfig override parameters (advanced). | No | | skip\_verify | Skip verification of the TLS server certificate that is presented. | No | | openconfig\_timeout | Timeout for OpenConfig connection and channel operations. | No | | openconfig\_options | Additional OpenConfig channel options (advanced). | No | | show\_diff | Show device gNMI differences (advanced, untested). | No | | token | OpenConfig access token (advanced). | No | ## Send a JSON POST to create devices A JSON POST can be sent to `/api/v2.0/inventories/grpc/default/devices` to create a device. Example post request: ```json { "name": "iosxr-cloud", "variables": { "host": "sandbox-iosxr-1.cisco.com", "password": "C1sco12345", "username": "admin", "insecure": true, "port": 57777 } } ``` ## Use TLS with OpenConfig devices Before connecting securely to OpenConfig devices, an appropriately configured system PKI infrastructure is required (trusted root certificates and client certificates). Consult your system administrator to ensure these requirements are in place before proceeding with a secure OpenConfig device setup. To use secure TLS certificates with OpenConfig, configure the device and set **insecure** to `false`. A simple device example (JSON POST) that skips server verification is shown below. **Example: TLS secured OpenConfig device without server certificate validation** ```json { "name": "iosxr-cloud", "variables": { "host": "sandbox-iosxr-1.cisco.com", "password": "C1sco12345", "username": "admin", "insecure": false, "skip_verify": true, "port": 57777 } } ``` > Configure and use OpenConfig (gRPC) in Itential Gateway for device connections using gNMI and gNOI.