netbox-nsm
NetBox plugin for security policy documentation (zones, rulebooks, object links).
No firewall push — inventory and policy only.
⚠️ Work in progress — Not recommended for production use yet. Breaking changes possible (e.g. 0.4.5 permission migration).
Status: NetBox: 4.5–4.6 · Plugin: 0.4.17 · Requires: netbox-custom-objects
Features
- Security Panel on prefix, IP, device, VM, custom objects —
+ Assignfor zones, addresses, … - Bundles — deploy NSM schema and demo data from JSON bundles (
Security → Configuration → Bundles) - Type Metadata — per-COT settings (
nsm_configin type comments): role, display template, sort order - Rulebooks with flexible columns (zones, addresses, labels, …)
- Rules — table, row grouping, grouped columns, zone matrix; Export JSON (bundle-compatible, re-import via Bundles)
- IP Analyzer — address resolution via the IP Analyzer applet on rule pages (loupe icon)
- Object Analyzer — graph from any NetBox object
- Object Report — daily background audit of NSM addresses/groups; TOML export
Navigation
| Group | Items |
|---|---|
| Configuration | Bundles, Type Metadata, Object Report |
| Rulebooks | Rulebooks (+ Add) |
| Analysis | Object Analyzer |
Screenshots
Bundles — apply nsm_schema first, then optional demo bundles:
Type Metadata — nsm_config per COT type (role, display template, sort order):
Object Report — daily address/group audit with TOML export:
Rulebooks — list and detail (fields, enforcement targets):
Rules — row grouping, grouped columns, Export JSON:
Zone matrix — permit/deny between zones:
IP Analyzer — destination tree with merge/diff:
Installation
pip install netbox-nsm
PLUGINS = ["netbox_custom_objects", "netbox_nsm"]
PLUGINS_CONFIG = {
"netbox_nsm": {
"menu_label": "Security",
"panel_label": "Security",
"top_level_menu": True,
"bundles_menu": True, # False hides Configuration → Bundles
"setup_allow_destructive_actions": True, # destructive preview/apply + demos; disable in prod
"bundle_paths": [],
"builtin_bundles": True,
# Optional Jinja2 address naming — see docs/address_name_templates.md
# "address_name_templates": [
# {"template": "h-{ipam>ip}", "match": "host"},
# ],
},
}
./manage.py migrate netbox_custom_objects --no-input
./manage.py migrate netbox_nsm --no-input
First run
- Security → Configuration → Bundles — Apply
nsm_schema(required; imports built-innsm_*COT types and writesnsm_configinto each type's comments). - Optional demo bundles: RB Demo Zone Matrix, RB Demo Zone/Address (Preview → Apply).
- Open a prefix → Security tab →
+ Assign→ zone. - Rulebooks under Security → Rulebooks.
Details: docs/using_netbox_nsm.md
Rules export / import
On a rulebook Rules tab, Export JSON downloads all rules matching the current filters (not just the visible page) as a bundle-compatible JSON document (objects[].records[] with portable refs like nsm_zone/zone_01). Import the file via Security → Configuration → Bundles (objects seeding).
API
/api/plugins/netbox-nsm/ — Type Metadata via nsm-configs/<slug>/, plus object-links/, ip-analyzer/
Rules and policy objects: netbox-custom-objects API.
Demos
| Demo | Where | Notes |
|---|---|---|
| NSM Schema | Bundles → nsm_schema |
Required base import (types, choice sets, seed objects, metadata) |
| RB Demo Zone Matrix | Bundles → nsm_demo_zone_matrix |
30×30 zone matrix, 900 rules |
| RB Demo Zone/Address | Bundles → nsm_demo_zone_address_adressgroup |
Zones, addresses, groups, 500 rules |
Documentation
| File | Topic |
|---|---|
| docs/using_netbox_nsm.md | Operations |
| docs/DATABASE.md | PostgreSQL tables |
| docs/RULE_DATA_STORAGE.md | UI vs DB data model |
| docs/object_report.md | Daily object report: job, checks, scaling |
| ARCHITECTURE.md | Code (developers) |
| CHANGELOG.md | Versions |
License
Release files for netbox-nsm 0.4.32
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| netbox_nsm-0.4.32.tar.gz | 594.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| netbox_nsm-0.4.32-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.4 MB
Release files / netbox_nsm-0.4.32.tar.gz
| Download URL | netbox_nsm-0.4.32.tar.gz |
|---|---|
| Size | 594.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d1531d20c17eda1ca69d8a5b8b12e65dae8b0fd9797355f2b4e3090bc3d0d011
|
|
BLAKE2b-256 checksum How to use checksums |
6962cb33cb82ebdce453fcda4fadc7c7837cec3acbe95739ae7cb65bbcaa565b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.
Transparency logRelease files / netbox_nsm-0.4.32-py3-none-any.whl
| Download URL | netbox_nsm-0.4.32-py3-none-any.whl |
|---|---|
| Size | 763.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
742d4c5301932d75abc32070f73d0620163d965c3e38bce6fd8ae677ea18241b
|
|
BLAKE2b-256 checksum How to use checksums |
573c387d1f97a3cd2a88a82b21c788a97b1e201bbe0ec6f08b86bddc05b4896e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.
Transparency log