Godwit AI Labs Talk to us

Home › Free tools › Switch config check

Could someone take over your switches?

Paste a Cisco switch’s running configuration. Every password, key and SNMP string is stripped out first, then it is checked for Telnet, Smart Install, default SNMP, reversible passwords, VLAN 1 and the rest, here in your browser.

Or paste the running configuration
  • Secrets stripped before reading
  • The file never leaves this browser
  • Try it offline: it still works
HOW TO GET THE FILE

Your configuration, exported

One command on the switch. Paste the output, or save it to a text file.

  1. Log in to the switchOver SSH or the console, and enter privileged mode with enable.
  2. Show the whole configurationRun terminal length 0, then show running-config. The first stops the output pausing every screen.
  3. Paste itInto “Or paste the running configuration” above. Long output is fine.

What is removed before reading: enable and user passwords and their hashes, line passwords, SNMP community strings and users, TACACS+ and RADIUS keys, VPN and wireless keys, and certificates. The report states what it found in plain words, and never quotes your configuration.

QUESTIONS

Asked often

The questions people search for before they run the check.

How do I check a Cisco switch configuration for security?

Run show running-config on the switch and paste the output above. The check removes every password, key and SNMP string first, then looks for Telnet, SSH version 1, Smart Install, the IOS XE web interface, default or read-write SNMP, reversible passwords, missing logging and time sync, management on VLAN 1, and ports open to VLAN hopping.

Is Cisco type 7 password encryption safe?

No. Type 7 is a reversible code, not encryption: free tools turn it back into the password in a second. Use secrets hashed as type 8 (SHA-256) or type 9 (scrypt), for example enable algorithm-type scrypt secret, and the same for each username.

What is Cisco Smart Install and should I disable it?

A zero-touch set-up protocol on Catalyst switches that accepts commands without a password on TCP 4786. Attackers have used it to rewrite configurations and replace software (CVE-2018-0171, on CISA's list of exploited flaws). Unless the switch is a Smart Install director, run no vstack.

Should I turn off the web interface on IOS XE?

Unless you use it, yes. In October 2023 tens of thousands of IOS XE devices were compromised through the web UI (CVE-2023-20198 and CVE-2023-20273). Run no ip http server and no ip http secure-server, and upgrade to a fixed release either way.

Is it safe to paste my switch configuration here?

The configuration is read in your browser and is not uploaded or stored. Passwords, hashes, SNMP strings, TACACS+ and RADIUS keys and certificates are removed before anything is read, and the report never quotes a line, an address or a name. You can disconnect from the internet before you run it.

Rather we went through it with you?

Every switch and its exact release, management access, VLANs and unused ports, then the changes applied in one maintenance window, each with a way back.