NetPulse24network utilities, reviewed

How-to

Saved PuTTY sessions and SSH keys for your switches and routers

Build a sane PuTTY baseline, save one session per switch, move to key-based logins with PuTTYgen and Pageant, and back the lot up in one command.

If opening a console on a core switch still means typing its IP from memory, re-entering the username, and scrolling back into a void because the window only kept 2,000 lines, PuTTY is set up the way it ships rather than the way a network admin needs it. Ten minutes of configuration fixes that for every device you manage: sensible defaults, one named session per box, key-based logins, and a registry export you can carry to the next laptop.

Everything here uses PuTTY 0.85 (current at the time of writing), which you should get only from the author’s site — see where to get it. The same steps work on older 0.7x/0.8x builds, with minor label differences.

Step 1 — Fix “Default Settings” first

New sessions copy whatever Default Settings holds at the moment you create them, so tune that entry before saving anything else.

  1. Launch PuTTY, click Default Settings in the Saved Sessions list, and press Load.

  2. Window → Lines of scrollback: raise it to something like 20000. A show running-config on a chassis switch blows through the default quickly.

  3. Connection → Seconds between keepalives: set 30. Stateful firewalls between you and the management VLAN will otherwise drop idle sessions mid-change.

  4. Connection → Data → Auto-login username: your device login, e.g. netadmin.

  5. Session → Logging: choose All session output and a file name using PuTTY’s placeholders, so every session writes its own log:

    C:\Logs\putty\&H-&Y&M&D-&T.log

    &H is the host, &Y&M&D the date and &T the time. When someone asks “what did you change on that switch on Tuesday?”, this is your answer.

  6. Go back to Session, click Default Settings again, and press Save.

Step 2 — Save one session per device

  1. Type the management IP or DNS name into Host Name, port 22, connection type SSH.
  2. In Saved Sessions, give it a name you can sort and search: site-role-name, for example hq-core-sw01, hq-acc-sw03, br2-edge-rtr01.
  3. Press Save. Repeat for each device — it’s quick once the defaults are right.

For console-cable work, save serial sessions the same way: connection type Serial, line COM3, speed 9600 (the usual console default on many switches). On the command line that is:

putty.exe -serial COM3 -sercfg 9600,8,n,1,N

Step 3 — Generate a key pair with PuTTYgen

  1. Open PuTTYgen. Choose the key type your fleet accepts:
    • EdDSA (Ed25519) for Linux-based network OSes, firewalls and servers that support it.
    • RSA, 3072 bits or more for older platforms. Many classic IOS/IOS-XE releases only accept RSA in their public-key chain — check your platform’s documentation.
  2. Click Generate and move the mouse to feed randomness.
  3. Set a Key comment (netadmin@admin-laptop) and a strong Key passphrase.
  4. Save private key as a .ppk. PuTTYgen writes PPK version 3 by default, with Argon2 protecting the passphrase; only choose version 2 if something older than PuTTY 0.75 must read the file.
  5. Copy the text from the box labelled Public key for pasting into OpenSSH authorized_keys file. That single line is what devices need.

Step 4 — Install the public key on the device

On a Linux-based appliance, append the line to ~/.ssh/authorized_keys of the login user. On Cisco IOS/IOS-XE the key goes into the SSH public-key chain:

conf t
 ip ssh pubkey-chain
  username netadmin
   key-string
    AAAAB3NzaC1yc2EAAAADAQABAAABgQC...rest-of-base64...
    exit
   exit
  exit
end
write memory

Paste only the base64 body (not the ssh-rsa prefix or the comment); if the paste gets mangled, split it into lines of about 70 characters. Keep password login working until you’ve confirmed key login on every device.

Step 5 — Point sessions at the key, or use Pageant

Two options:

Step 6 — Launch fast and back up

Open a saved session without touching the dialog:

putty.exe -load "hq-core-sw01"

Put a few of those in a folder of shortcuts, or in your launcher of choice. Sessions live in the registry under HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\Sessions, so a backup is one line:

reg export "HKCU\Software\SimonTatham\PuTTY\Sessions" "%USERPROFILE%\putty-sessions.reg" /y

Double-click the .reg on a new machine to import. Keep the .ppk separately and securely — it’s not in that export, and it shouldn’t be.

Common mistakes

Moving config backups off those switches? PuTTY vs WinSCP explains which tool does which half of the job, and WinSCP can import these very sessions. The PuTTY review covers the rest of the suite, and more tools of this kind live in SSH, Telnet & File Transfer.

Tool used in this how-to