If opening a console on a core switch still means typing its IP from memory, re-entering the username, and scrolling back into a void because the window only kept 2,000 lines, PuTTY is set up the way it ships rather than the way a network admin needs it. Ten minutes of configuration fixes that for every device you manage: sensible defaults, one named session per box, key-based logins, and a registry export you can carry to the next laptop.
Everything here uses PuTTY 0.85 (current at the time of writing), which you should get only from the author’s site — see where to get it. The same steps work on older 0.7x/0.8x builds, with minor label differences.
Step 1 — Fix “Default Settings” first
New sessions copy whatever Default Settings holds at the moment you create them, so tune that entry before saving anything else.
-
Launch PuTTY, click Default Settings in the Saved Sessions list, and press Load.
-
Window → Lines of scrollback: raise it to something like
20000. Ashow running-configon a chassis switch blows through the default quickly. -
Connection → Seconds between keepalives: set
30. Stateful firewalls between you and the management VLAN will otherwise drop idle sessions mid-change. -
Connection → Data → Auto-login username: your device login, e.g.
netadmin. -
Session → Logging: choose All session output and a file name using PuTTY’s placeholders, so every session writes its own log:
C:\Logs\putty\&H-&Y&M&D-&T.log&His the host,&Y&M&Dthe date and&Tthe time. When someone asks “what did you change on that switch on Tuesday?”, this is your answer. -
Go back to Session, click Default Settings again, and press Save.
Step 2 — Save one session per device
- Type the management IP or DNS name into Host Name, port
22, connection type SSH. - In Saved Sessions, give it a name you can sort and search:
site-role-name, for examplehq-core-sw01,hq-acc-sw03,br2-edge-rtr01. - Press Save. Repeat for each device — it’s quick once the defaults are right.
For console-cable work, save serial sessions the same way: connection type Serial, line COM3, speed 9600 (the usual console default on many switches). On the command line that is:
putty.exe -serial COM3 -sercfg 9600,8,n,1,N
Step 3 — Generate a key pair with PuTTYgen
- Open PuTTYgen. Choose the key type your fleet accepts:
- EdDSA (Ed25519) for Linux-based network OSes, firewalls and servers that support it.
- RSA, 3072 bits or more for older platforms. Many classic IOS/IOS-XE releases only accept RSA in their public-key chain — check your platform’s documentation.
- Click Generate and move the mouse to feed randomness.
- Set a Key comment (
netadmin@admin-laptop) and a strong Key passphrase. - Save private key as a
.ppk. PuTTYgen writes PPK version 3 by default, with Argon2 protecting the passphrase; only choose version 2 if something older than PuTTY 0.75 must read the file. - Copy the text from the box labelled Public key for pasting into OpenSSH authorized_keys file. That single line is what devices need.
Step 4 — Install the public key on the device
On a Linux-based appliance, append the line to ~/.ssh/authorized_keys of the login user. On Cisco IOS/IOS-XE the key goes into the SSH public-key chain:
conf t
ip ssh pubkey-chain
username netadmin
key-string
AAAAB3NzaC1yc2EAAAADAQABAAABgQC...rest-of-base64...
exit
exit
exit
end
write memory
Paste only the base64 body (not the ssh-rsa prefix or the comment); if the paste gets mangled, split it into lines of about 70 characters. Keep password login working until you’ve confirmed key login on every device.
Step 5 — Point sessions at the key, or use Pageant
Two options:
-
Per session: load a session, go to Connection → SSH → Auth → Credentials, set Private key file for authentication to your
.ppk, return to Session and Save. Doing this in Default Settings before Step 2 saves repetition. -
Pageant (recommended): start Pageant, add the
.ppk, enter the passphrase once. Every PuTTY, PSCP, Plink and WinSCP session then authenticates silently until you log off. A startup shortcut helps:"C:\Program Files\PuTTY\pageant.exe" "C:\Keys\netadmin.ppk"
Step 6 — Launch fast and back up
Open a saved session without touching the dialog:
putty.exe -load "hq-core-sw01"
Put a few of those in a folder of shortcuts, or in your launcher of choice. Sessions live in the registry under HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\Sessions, so a backup is one line:
reg export "HKCU\Software\SimonTatham\PuTTY\Sessions" "%USERPROFILE%\putty-sessions.reg" /y
Double-click the .reg on a new machine to import. Keep the .ppk separately and securely — it’s not in that export, and it shouldn’t be.
Common mistakes
- Editing without saving. Changing a setting and connecting doesn’t persist it. Load → change → click the name → Save.
- Assuming defaults propagate. Changing Default Settings later doesn’t touch sessions already saved.
- Clicking through host-key warnings. A changed key after an RMA is expected; a changed key on a switch nobody touched is not. Verify the fingerprint on the console before accepting.
- Enabling weak algorithms globally. Old kit may only offer legacy key exchange or ciphers. If you must, adjust the algorithm order only in that device’s saved session, not in Default Settings.
- No passphrase on the key. An unprotected
.ppkon a laptop is a skeleton key to the network.
Related
Moving config backups off those switches? PuTTY vs WinSCP explains which tool does which half of the job, and WinSCP can import these very sessions. The PuTTY review covers the rest of the suite, and more tools of this kind live in SSH, Telnet & File Transfer.