Skip to content

Software

ConfigAudit

Version 1.1 · 21/09/2026
Windows no runtime required works offline
Check your download: file names and SHA-256 checksums published 22/09/2026

Compare the checksum of the file you downloaded with the one listed here. If they differ, the file is not the one published on this page - delete it and download it again.

  • ConfigAudit-1.1.exe5085e8cf53caba221acdaa3217189f6b2360b0db3fdcfe06156667608ddba073

Windows (PowerShell): Get-FileHash <file>   Linux: sha256sum <file>   macOS: shasum -a 256 <file>

How to install and use it

Windows 10 or 11
  1. Double-click ConfigAudit-1.1.exe. There is nothing to install, and it never connects to the network.
  2. If Windows SmartScreen says the program is unrecognised, choose More info, then Run anyway. The program is not code-signed; the checksum above is how you know it is the published file.
  3. Put one configuration file per device in a folder: Cisco show running-config, MikroTik /export, Juniper show configuration | display set.
  4. Drag the folder onto the window, or press Browse... and choose it.
  5. Work down the findings from the top. Click one to see what it means and which devices and interfaces it names.

A question about installing or using it? Ask in the comments below, or through the contact page.

Problem

A network that grew by accident hides its problems in the differences between devices: two sites that chose the same range, a community string nobody changed, telnet open by default, a redistribution with no filter. Across thirty devices in three vendors, reading by eye is how the quiet ones get missed.

Solution

A single-file Windows application that reads a folder of Cisco IOS, MikroTik RouterOS and Junos configurations, compares every device with its neighbours, and reports overlaps, drift, defaults and single paths with the evidence for each, rated by severity and entirely offline.

Result

The variations are catalogued before a change instead of discovered during one, every finding arrives with the lines that caused it, and the exit code can hold a change until the high-severity findings are dealt with.

Thirty devices, three vendors, eight years of changes made under pressure by people who have since moved on. Nobody can say for certain which sites use which address ranges, which routers still have the community string they shipped with, or where a static route is being redistributed into everything. The network works. It is the next change that will find out what it has been hiding.

Why I built it

Because the first deliverable on a network that has grown by accident is never a design. It is an audit: every running configuration collected and compared with its neighbours, so the variations are catalogued rather than discovered halfway through a migration at two in the morning. That comparison is mechanical, tedious, and exactly the kind of work where attention fails — not on the dramatic faults, but on the quiet ones.

The constraint that shaped it is trust. Nobody should have to send their live running configurations to an outside party to have them checked, and a careful client will not. So it reads files from disk, writes its report to disk, and opens no network connection at all. That is not a missing feature; it is the product.

The problem

The faults that hurt in a grown network are rarely inside any single device. They are in the differences between devices:

  • Two sites that both chose the same range, which works until the day they need to reach each other.
  • A community string nobody changed, or SNMP v2c with no v3 anywhere, on equipment reachable from half the estate.
  • A vty line with no transport input statement, which on most IOS versions means telnet is open and nobody decided that.
  • A redistribute static with no route-map, which is how a mistake at one site reaches every other site.
  • Time, name and logging servers that drift from device to device, so the logs from an incident cannot be lined up.

Each is easy to see in one file and easy to miss across thirty. Reading by eye catches the dramatic problems; the quiet ones surface during the change.

How ConfigAudit reads a folder of configurations and reports what disagreesCisco, MikroTik and Junos configurations read from disk and compared device against device, each finding rated and shown with its evidence, and an exit code that can hold a change — with no network connection at any point.
Cisco, MikroTik and Junos configurations read from disk and compared device against device, each finding rated and shown with its evidence, and an exit code that can hold a change — with no network connection at any point.

What I did

  • Three vendors, as they are exported. Cisco IOS and IOS-XE show running-config, MikroTik RouterOS /export in both of its forms, and Junos display set. A Junos file in curly-brace format is refused with advice to re-export it, because a parser that quietly understands two thirds of a file is worse than one that says it cannot read it.
  • Every device compared with its neighbours. Duplicate and overlapping addresses, NTP, DNS and syslog servers that differ or are missing, MTU set to different values, and one VLAN id carrying two names.
  • Defaults and weak credentials. Default SNMP communities, v1 or v2c with no v3, enable password with no secret, predictable usernames, telnet reachable and plain HTTP management.
  • Routing and resilience. Redistribution with no filter, a device with only one routed path, speed and duplex fixed rather than negotiated, and interfaces that carry an address but are shut down.
  • Findings with evidence. Each one rated High, Medium, Low or Informational, naming the devices involved and what each of them says — because “six devices disagree about NTP” is no use without knowing which six.
  • Offline by construction. It opens no socket. Configurations are read from disk and the report is written to disk; nothing leaves the machine.
  • A window and a command line. Drag a folder onto the window to see the findings; run it from a script for a text or CSV report and an exit code of 1 when anything is rated high, so it can gate a change.
  • One file, no runtime, no installer, for the same reason as the other tools here: it has to run on the machine that is available, not the one that would be convenient.

The result

The variations are catalogued before a change instead of discovered during one. An engagement starts from what the estate actually says about itself — where it disagrees, what was left at its default, where one failure would cut off a site — with the lines behind each finding, rather than from the documentation, which usually describes the network as it was intended.

It also changes what a review costs. The mechanical half — the comparing, the subnet arithmetic, the spotting of defaults — is done in seconds, and the engineer’s time goes on the half that needs judgement. Every finding is a prompt for that judgement rather than a verdict: a single routed path may be exactly right for a small site. The point is that somebody decided, rather than nobody noticed.

The boundary: it reads configuration files, not a running network, so what is plugged in and what the routing table holds right now are outside its view. It checks IPv4 only, and it does not review access lists or firewall rules. It checks whether an estate agrees with itself, not whether it meets a compliance standard.


Leave a response

Every comment is read before it appears. Yours will not show up straight away, and that is not a fault.

Not published, and not used for anything else.