Recently I started to play a little bit with GNS3. I managed quite easy to create a virtual cisco router on GNS3 and connect from console to that router and do the initial basic setup of the router. And then it hit me! Is there any way to make the virtual cisco router inside GNS to connect to the internet? YES. Of course.

My configuration is like this:
– internet router (ADSL) which has a public IP address (WAN)
– DHCP for the local network (both cable & wireless)
– a macbook pro laptop which runs Mac OSX Yosemite, latest version
– a cisco operating system image (in my case I am using Cisco 3725 image) from here
TunTap for Mac OSX (you need to create a virtual tap device in order to communicate with the cisco router on your local network)

I will summarize quickly how to do it:
– download and install TunTap for Mac OSX (you wont be able to see the tap0 device until you start GNS and connect the router with the cloud)
– install GNS3 for Mac OSX; open Terminal and issue the following command (to start GNS3 as root): sudo /Applications/; minimize Terminal window
– in GNS, go to Preferences, Dynamips, IOS Routers, Add New (select the downloaded cisco image). Then drag your new router in the GNS
– browse End Devices and drag a Cloud on GNS; Right click on Cloud icon and select Configure; Select the cloud, go to NIO:Tap and add manually /dev/tap0
– add a link between your cisco router (interface fa0/0 or FastEthernet 0/0) and your cloud (interface tap0)
– select cisco router and click start in order to make the router boot

So connect to your router by console (right click on router, Console). Do the basic setting of your router. After that, do enable, enter your enable password

x.x.x.x – is your public internet IP (from the internet router). is my internet router local ip address and is the ip that we will assign to the tap0 interface.

Now we go to the mac part. Since Yosemite lacks natd binary and ipfw is no longer supported, we have to use pfctl instead for forwarding and NAT.
Open Terminal on Mac, issue sudo su, enter your password and become root.

create the following file (pfrule)
sh-3.2# cat > pfrule

Save the file. en1 is my wireless adapter interface (the one I am using to connect). tap0 is the interface used by the Cloud inside GNS to connect with the virtual cisco router.

Now create another file (
sh-3.2# cat >

sh-3.2# sh (to execute the above script)

We assing the tap0 interface the ip netmask (remember, your cisco router has At this point we are able to ping the router from your mac and vice versa. Then we enable forwading on your MacBook making it to act as a router. Then we disable all pfctl rules and then load the rules from the pfrule file we have created earlier and enable pfctl.

And that’s it! Now you can ping google from your cisco router!


About Author

I am a linux passionate and currently working as a Linux Senior System Administrator. I also am a freelancer and help people to complete different jobs. You can hire me on