# Pull switch/router config with SSH flow

**URL:** <https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997>\
**Category:** General\
**Created:** [13 July 2020 12:24 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997 "2020-07-13T12:24:14Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dane84](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dane84/32/25643_2.png) [@Dane84](https://discourse.nodered.org/u/Dane84)\
**Post date:** [13 July 2020 12:24 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/1 "2020-07-13T12:24:14Z")

</div>

Hi,

I'm trying to find a, in my opinion, very simple flow to do the following.

- Connect via SSH to an IP address
- Login with username/password
- Run the commands:  
_no page_

- show system\*
- show version\*
- show vlans\*
- show trunks\*
- show mac-address\*
- show spanning-tree\*
- show running-config\*
- page\*

- save all the output to a .txt file
- Disconnect the SSH session

I want to get the whole running config from a router of switch automated by Node Red.  
If this is working I would like to make a dashboard where you can enter an IP address and the credentials and hit the button to save the config.

I googled for a couple of hours but can't find anything usefull.  
Anybody here that did this trick before?

Thanks  
Dane

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [13 July 2020 13:14 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/2 "2020-07-13T13:14:31Z")

</div>

This is not going to be so simple as it looks, mainly because Cisco IOS does not have a interactive commandline and ssh also adds some complexity. I would recommend ansible for these types of tasks instead, or there might some python scripts out there that could do it as well.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [13 July 2020 13:27 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/3 "2020-07-13T13:27:44Z")

</div>

You could try snmp

[https://flows.nodered.org/search?term=snmp](https://flows.nodered.org/search?term=snmp)

> **[How To Copy Configurations To and From Cisco Devices Using SNMP](https://www.cisco.com/c/en/us/support/docs/ip/simple-network-management-protocol-snmp/15217-copy-configs-snmp.html)**
>
> This document shows how to copy a configuration file to and from a Cisco device with the CISCO-CONFIG-COPY-MIB. If you start from Cisco IOS? software release 12.0, or on some devices as early as release 11.2P, Cisco has implemented a new means of...

EDIT...  
PS, if you get this to work I would be very interested 🙂

---

<div class="post-metadata">

**Author:** ![edje11](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/edje11/32/572_2.png) [@edje11](https://discourse.nodered.org/u/edje11)\
**Post date:** [13 July 2020 14:36 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/4 "2020-07-13T14:36:06Z")

</div>

Maybe you can do something with exec node and ssh remote commands

> **[SSH: Execute Remote Command or Script - Linux - ShellHacks](https://www.shellhacks.com/ssh-execute-remote-command-script-linux/)**
>
> How to execute remote command, multiple commands or shell (Bash) script over SSH (Secure Shell). Examples of SSH command in Linux terminal. How to use SSH.

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [13 July 2020 15:47 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/5 "2020-07-13T15:47:14Z")

</div>

> Maybe you can do something with exec node and ssh remote commands

You can't, it is not a linux box. To script IOS, you need python and TCL, TCL is the only languague IOS understands.

> You could try snmp

snpm should work, if you can configure it on the device. There are snpm nodes available too.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [13 July 2020 15:52 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/6 "2020-07-13T15:52:12Z")

</div>

> [@bakman2](#):
>
> snpm

_(not being pedantic)_  
Is this a typo or something different to SNMP and the nodes i linked to?

Assuming its a typo and you meant SNMP, would you know how to do this?  
I find SNMP to be quite obtuse.

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [13 July 2020 15:57 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/7 "2020-07-13T15:57:39Z")

</div>

Typo yes sorry 😉

I will report back once I understand how to interpret the MIBs for my ubiquity router. For my synology based NAS (xpenology) I know how to get data out of it, but it never reports what I request (ie. specified incorrect MIB).

---

<div class="post-metadata">

**Author:** ![edje11](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/edje11/32/572_2.png) [@edje11](https://discourse.nodered.org/u/edje11)\
**Post date:** [13 July 2020 16:41 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/8 "2020-07-13T16:41:16Z")

</div>

> [@bakman2](#):
>
> You can't, it is not a linux box. To script IOS

TS never mentioned the brand of his switch/router so I don't have a clue where you see Cisco or IOS.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [13 July 2020 16:46 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/9 "2020-07-13T16:46:26Z")

</div>

> [@edje11](#):
>
> TS never mentioned the brand of his switch/router so I don't have a clue where you see Cisco or IOS.

At a guess - leap of faith - the clues are in the commands the OP wants to execute...

> [@Dane84](#):
>
> - show system\*
> - show version\*
> - show vlans\*
> - show trunks\*
> - show mac-address\*
> - show spanning-tree\*
> - show running-config\*

They are all valid Cisco IOS commands

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [13 July 2020 16:55 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/10 "2020-07-13T16:55:17Z")

</div>

The node i am using: [node-red-contrib-snmp](https://flows.nodered.org/node/node-red-node-snmp)

Example interfaces from my ubiquiti erx

IOD `1.3.6.1.2.1.2.2.1.2` per RFC (should be standard accross devices) - outputs the interfaces and names in buffers (example flow translates them to UTF8 string)

IOD `1.3.6.1.2.1.2.2.1.8` (RFC) outputs all interfaces status value 0 (down) 1 (up)

Example output

 ![Screenshot 2020-07-13 at 18.53.33](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/2/c211d86cef1e2cdc7c290b7f9930da56e140134f.jpeg)

Example flow

```auto
[{"id":"7320c129.7639f8","type":"inject","z":"838f476f.2b6cd","name":"","props":[{"p":"payload"},{"p":"topic","vt":"str"}],"repeat":"","crontab":"","once":false,"onceDelay":0.1,"topic":"","payload":"","payloadType":"date","x":204,"y":408,"wires":[["5a17a576.80a3bc","fdafbd8b.0520a"]]},{"id":"c5077427.3b3a3","type":"debug","z":"838f476f.2b6cd","name":"","active":true,"tosidebar":true,"console":false,"tostatus":false,"complete":"true","targetType":"full","statusVal":"","statusType":"auto","x":698,"y":408,"wires":[]},{"id":"5a17a576.80a3bc","type":"snmp subtree","z":"838f476f.2b6cd","host":"10.0.0.1","community":"public","version":"2c","oids":"1.3.6.1.2.1.2.2.1.2","timeout":5,"name":"","x":388,"y":384,"wires":[["121a7d16.7513db"]]},{"id":"121a7d16.7513db","type":"function","z":"838f476f.2b6cd","name":"","func":"m = msg.payload\no = []\nfor(x=0;x<m.length;x++){\n \n let i = m[x].value.toString('utf8');\n o.push({oid:m[x].oid,interface:i})\n \n}\n\nreturn {payload:o}","outputs":1,"noerr":0,"initialize":"","finalize":"","x":564,"y":384,"wires":[["c5077427.3b3a3"]]},{"id":"fdafbd8b.0520a","type":"snmp subtree","z":"838f476f.2b6cd","host":"10.0.0.1","community":"public","version":"2c","oids":"1.3.6.1.2.1.2.2.1.8","timeout":5,"name":"","x":388,"y":432,"wires":[["c5077427.3b3a3"]]}]

```

Really essential is a MIB browser to understand the values and their context, i am using [iReasoning MIB browser](https://www.ireasoning.com/mibbrowser.shtml), it's free and you can load MIB's in it.

---

<div class="post-metadata">

**Author:** ![Dane84](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dane84/32/25643_2.png) [@Dane84](https://discourse.nodered.org/u/Dane84)\
**Post date:** [13 July 2020 20:14 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/11 "2020-07-13T20:14:29Z")

</div>

Thanks people for your reply’s!  
From reading your reply’s it’s harder than I thought.  
I’m not sure if SNMP will do the trick but I will look into that.  
In this case I’m using Aruba switches, now doing this by hand one by one to make a backup.  
Should be very helpful if I can automate this.  
I know there are ways of using sftp where the switch drop their running config but I’m not going to use that.

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [13 July 2020 20:33 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/12 "2020-07-13T20:33:49Z")

</div>

Interesting, looks exactly like cisco, very creative 😉 But looking on google, depending on the OS [they have a rest api available](https://arubaos-switch-rest-guide.readthedocs.io/en/latest/), which will make this relatively easy with a http request or exec node

---

<div class="post-metadata">

**Author:** ![craigcurtin](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@craigcurtin](https://discourse.nodered.org/u/craigcurtin)\
**Post date:** [14 July 2020 00:32 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/13 "2020-07-14T00:32:41Z")

</div>

I believe that Aruba (depending on OS version) support TCL in the console.

This is the easiest way to do this - although really i would just use a TFTP dump of the file and then use Node-red to manage them

Should be simple in TCL (been a while since i did anything on IOS with it) to do a once a day dump of running config to a local TFTP server

Here is almost a working TCL version for you in this thread

> **[How to backup Aruba 8400 series switch with IMC 7.3 (E0703)](https://community.hpe.com/t5/imc/how-to-backup-aruba-8400-series-switch-with-imc-7-3-e0703/td-p/7070101)**
>
> Added an Aruba 8400 series switch to IMC version 7.3 (E0703). Switch is running 10.03.0040. When IMC attempts to backup I see the following in the switch log: |Error while copying configs. Error: error in remote file transfer...

Craig

---

<div class="post-metadata">

**Author:** ![craigcurtin](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@craigcurtin](https://discourse.nodered.org/u/craigcurtin)\
**Post date:** [14 July 2020 00:47 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/14 "2020-07-14T00:47:53Z")

</div>

Another update - not sure what Aruba supports but on Cisco we have Kron and Archive - have a read of the below

You could either:

Use Cisco's Kron functionality for command scheduling. This will allow you to execute predefined commands on a scheduled basis. As you pointed out, copy run tftp requires file prompt confirmation. (Unless you've turned off file prompt confirmation, however I don't recommend it as a normal setting.) Redirecting does not require confirmation. So the command used in the scheduler is show run | redirect tftp://$SERVERIP/$PATH/$FILE

Use Cisco's Archive functionality for configuration management. Archive is a way to store multiple copies of the config in a sequential fashion and roll back configs if needed to a previous version. Copying out with Kron overwrites the previous config, while Archive allows you to keep up to 14 different config versions in the specified location. See this link on the Cisco Learning network for more useful info on Archive. Specifically how to dynamically set the filename with the $h and $t tags.

In either of the below samples, you can adjust the times to your needs, these are just what I quickly pulled out of some production gear.

Sample config to have Kron write config and back it up to a tftp server once a week:

kron occurrence SaveConfig at 23:50 Mon recurring  
policy-list SaveConfig  
!  
kron occurrence BackupRunningConfig at 23:55 Mon recurring  
policy-list BackupRunningConfig  
!  
kron policy-list SaveConfig  
cli write  
!  
kron policy-list BackupRunningConfig  
cli show running-config | redirect tftp://10.10.10.10/configs/testswitch.txt  
Sample config to have Archive back up your config to a tftp server daily:

archive  
path tftp://10.10.10.10/configs/$h-$t  
time-period 1440  
maximum 14

---

<div class="post-metadata">

**Author:** ![Dane84](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dane84/32/25643_2.png) [@Dane84](https://discourse.nodered.org/u/Dane84)\
**Post date:** [14 July 2020 10:04 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/15 "2020-07-14T10:04:57Z")

</div>

I was not aware of the rest API, thanks!  
I checked my switches and they support rest API, I will try to lookin to that if it's possible to pull the running config via a rest API command.

---

<div class="post-metadata">

**Author:** ![Dane84](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dane84/32/25643_2.png) [@Dane84](https://discourse.nodered.org/u/Dane84)\
**Post date:** [14 July 2020 10:07 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/16 "2020-07-14T10:07:14Z")

</div>

Thanks, I know this is possible.  
But I want to connect my laptop to the network select the IP addresses of the switches hit the button and collect the switch config files. Not schedule anything yet, If I get this to work in Node-Red then it would be very easy to schedule something and archive files.

---

<div class="post-metadata">

**Author:** ![craigcurtin](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@craigcurtin](https://discourse.nodered.org/u/craigcurtin)\
**Post date:** [14 July 2020 16:33 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/17 "2020-07-14T16:33:48Z")

</div>

OK - not sure why you would prefer that to an automated job though - the right tools for the job and all.

You could then have NR go out and grab all the config files from each of the servers where they have been dropped and centralize them all

Craig

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [12 September 2020 16:33 UTC](https://discourse.nodered.org/t/pull-switch-router-config-with-ssh-flow/29997/18 "2020-09-12T16:33:58Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
