Skip to main content

netbox-nsm

NetBox plugin for security policy documentation (zones, rulebooks, object links).
No firewall push — inventory and policy only.

⚠️ Work in progress — Not recommended for production use yet. Breaking changes possible (e.g. 0.4.5 permission migration).

Status: NetBox: 4.5–4.6 · Plugin: 0.4.17 · Requires: netbox-custom-objects

Features

  • Security Panel on prefix, IP, device, VM, custom objects — + Assign for zones, addresses, …
  • Bundles — deploy NSM schema and demo data from JSON bundles (Security → Configuration → Bundles)
  • Type Metadata — per-COT settings (nsm_config in type comments): role, display template, sort order
  • Rulebooks with flexible columns (zones, addresses, labels, …)
  • Rules — table, row grouping, grouped columns, zone matrix; Export JSON (bundle-compatible, re-import via Bundles)
  • IP Analyzer — address resolution via the IP Analyzer applet on rule pages (loupe icon)
  • Object Analyzer — graph from any NetBox object
  • Object Report — daily background audit of NSM addresses/groups; TOML export

Navigation

Group Items
Configuration Bundles, Type Metadata, Object Report
Rulebooks Rulebooks (+ Add)
Analysis Object Analyzer

Screenshots

Bundles — apply nsm_schema first, then optional demo bundles:

Bundles

Type Metadata — nsm_config per COT type (role, display template, sort order):

Type Metadata

Object Report — daily address/group audit with TOML export:

Object Report

Rulebooks — list and detail (fields, enforcement targets):

Rulebooks

Rulebook detail

Rules — row grouping, grouped columns, Export JSON:

Rules by zone

Zone matrix — permit/deny between zones:

Zone matrix

IP Analyzer — destination tree with merge/diff:

IP Analyzer

Installation

pip install netbox-nsm
PLUGINS = ["netbox_custom_objects", "netbox_nsm"]

PLUGINS_CONFIG = {
    "netbox_nsm": {
        "menu_label": "Security",
        "panel_label": "Security",
        "top_level_menu": True,
        "bundles_menu": True,  # False hides Configuration → Bundles
        "setup_allow_destructive_actions": True,  # destructive preview/apply + demos; disable in prod
        "bundle_paths": [],
        "builtin_bundles": True,
        # Optional Jinja2 address naming — see docs/address_name_templates.md
        # "address_name_templates": [
        #     {"template": "h-{ipam>ip}", "match": "host"},
        # ],
    },
}
./manage.py migrate netbox_custom_objects --no-input
./manage.py migrate netbox_nsm --no-input

First run

  1. Security → Configuration → Bundles — Apply nsm_schema (required; imports built-in nsm_* COT types and writes nsm_config into each type's comments).
  2. Optional demo bundles: RB Demo Zone Matrix, RB Demo Zone/Address (Preview → Apply).
  3. Open a prefix → Security tab → + Assign → zone.
  4. Rulebooks under Security → Rulebooks.

Details: docs/using_netbox_nsm.md

Rules export / import

On a rulebook Rules tab, Export JSON downloads all rules matching the current filters (not just the visible page) as a bundle-compatible JSON document (objects[].records[] with portable refs like nsm_zone/zone_01). Import the file via Security → Configuration → Bundles (objects seeding).

API

/api/plugins/netbox-nsm/ — Type Metadata via nsm-configs/<slug>/, plus object-links/, ip-analyzer/
Rules and policy objects: netbox-custom-objects API.

Demos

Demo Where Notes
NSM Schema Bundles → nsm_schema Required base import (types, choice sets, seed objects, metadata)
RB Demo Zone Matrix Bundles → nsm_demo_zone_matrix 30×30 zone matrix, 900 rules
RB Demo Zone/Address Bundles → nsm_demo_zone_address_adressgroup Zones, addresses, groups, 500 rules

Documentation

File Topic
docs/using_netbox_nsm.md Operations
docs/DATABASE.md PostgreSQL tables
docs/RULE_DATA_STORAGE.md UI vs DB data model
docs/object_report.md Daily object report: job, checks, scaling
ARCHITECTURE.md Code (developers)
CHANGELOG.md Versions

License

LICENSE

Release files for netbox-nsm 0.4.32

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for netbox-nsm 0.4.32
File Size Uploaded
netbox_nsm-0.4.32.tar.gz 594.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for netbox-nsm 0.4.32
File Interpreter ABI Platform
netbox_nsm-0.4.32-py3-none-any.whl Python 3 none any Details

Total release size: 1.4 MB

Release files / netbox_nsm-0.4.32.tar.gz

Download URL netbox_nsm-0.4.32.tar.gz
Size 594.5 kB
Tags Source
SHA-256 checksum
How to use checksums
d1531d20c17eda1ca69d8a5b8b12e65dae8b0fd9797355f2b4e3090bc3d0d011
BLAKE2b-256 checksum
How to use checksums
6962cb33cb82ebdce453fcda4fadc7c7837cec3acbe95739ae7cb65bbcaa565b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.

Transparency log

Release files / netbox_nsm-0.4.32-py3-none-any.whl

Download URL netbox_nsm-0.4.32-py3-none-any.whl
Size 763.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
742d4c5301932d75abc32070f73d0620163d965c3e38bce6fd8ae677ea18241b
BLAKE2b-256 checksum
How to use checksums
573c387d1f97a3cd2a88a82b21c788a97b1e201bbe0ec6f08b86bddc05b4896e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page