Switch management that asks before it acts.
Switch Manager Pro backs up every AOS-S and AOS-CX switch each night, tells you when a config changed behind your back, and runs a change only after a person has read the exact commands.
No CLI to type.
Nothing sent you haven’t read.
A small agent on your network does the talking to your switches. The portal never builds commands and never reaches in — it asks, and the agent answers.
Ask
Pick the switches and the change — a VLAN, a port, PoE, a description. No CLI to type.
Plan
The agent on your network builds the exact commands for each switch’s OS, without connecting to it.
Approve
A person reads the commands and approves them. What you approve is what runs — nothing is rebuilt afterwards.
Apply & back up
The agent applies, saves only if the switch rejected nothing, and takes a fresh backup of the result.
The jobs you used to do in PuTTY,
with a record of every one.
Nightly config backups
Every switch backed up every night, encrypted at rest. Open any version, or compare it with any earlier one — not just last night’s.
Changed outside Switch Manager Pro
When a backup shows a change nobody made through the portal, you get an email naming the switch and the window. Someone consoled in on Friday? You’ll know on Saturday.
Bulk changes, one switch at a time
One change across a whole rack, released switch by switch. Each waits for the last to finish, and the run stops itself if too many fail.
Scheduled & recurring
Approve at lunchtime, run at 17:30. Or “PoE off every weekday at 18:00”, bound to the exact commands you approved — if they ever differ, it doesn’t run and it tells you.
Ports & PoE
Every port’s status, speed, VLAN and PoE draw in one table. Select ports, enable, disable, set PoE or describe them — all through the same approval.
Find a MAC address
Which port is this device on? The agent searches the MAC tables on site and returns only the line you asked for — the table itself never leaves your network.
Search every config
Find which switches still carry an old VLAN or SNMP setting, across the backups you already hold. No switch is contacted.
Discover by subnet
Sweep a subnet from the agent, identify the switches that answer — model, OS, hostname — and add them in one go.
Open in PuTTY, logged in
With our installer on your PC, one click in the portal opens a session already logged in. The password never appears on a command line, and the switch’s host key is pinned.
Also included
- A command guide showing every operation’s exact commands
- Day-zero profiles kept with your organisation
- Switch reports with CSV export
- Runs alongside WiFiAnchor on the same agent
Made by people who’ve locked themselves out of a switch.
A network change at 10am is somebody’s lesson. So the defaults are the cautious ones, and the tool says no when it isn’t sure.
School hours are protected
Anything that can interrupt the network needs a recorded reason to run between 08:00 and 16:00 on a weekday. Scheduled runs are checked again at the moment they fire.
Late means cancelled, never “sent anyway”
A scheduled change that misses its slot by more than 30 minutes is cancelled with the reason recorded — it never lands in the middle of the next school day.
Refuses what hasn’t been proven
Every operation is reviewed per OS. Anything not yet verified on real hardware is marked for a lab check, and the agent refuses to send it.
Passwords stay out of logs
Switch logins and secret values are stored encrypted and fetched by the agent once, for one command. They never sit in the command history.
The switch is the one you know
Each switch’s SSH host key is pinned on first contact. A different key is refused and flagged — not quietly trusted.
Every action is recorded
Who asked, who approved, what was sent and what the switch replied — kept against the change and in the audit log.
New switches on site, configured before you leave.
Works offline on site
Plug a laptop into new switches, find them, and give them a first-time configuration from a saved site profile — no internet needed.
Checks its own work
After configuring each switch it logs in again with the new admin password, so nothing is left with a login nobody can use.
Licensed by approval, not keys
Someone in your organisation approves the laptop from the portal. No licence key to share, and a leaver’s laptop is revoked in a click.
The things IT teams ask first.
Something not here? Ask us — we’re a small UK team and we reply ourselves.
Not available yet — listed so you know what isn’t there today.
Which switches does it support?
HPE Aruba Networking switches running AOS-S or AOS-CX. Each switch’s OS is identified automatically, and the commands are built for it.
Do we need to open a port on our firewall?
No. A small agent runs on a Windows machine on your network and connects out over HTTPS, so nothing on the internet needs to reach in. It talks to your switches over SSH from inside your network.
Where is our data?
In the UK and EU — the database and servers are in London. Switch configs are encrypted before they are stored. We never store MAC or ARP tables, logs, or SNMP output.
Can it change something without us knowing?
No. Every change is previewed as the exact commands and approved by a person before it runs, and recorded afterwards. The only unattended runs are schedules you approved, and they are refused if the commands ever differ.
We already use WiFiAnchor. Is this separate?
It’s a separate product that lives in the same portal and uses the same agent. Buy either or both.
Questions about your switches? Ask us.
Tell us what you run and what you need. We’re a small UK team and reply ourselves, usually the same day.