CONFIG BACKUP & CHANGE TRACKING FOR MACOS, WINDOWS & LINUX

Something changed on the switch. ConfigWatch tells you what, and how to put it back.

The network broke at 2am and nobody touched anything. ConfigWatch logs into your switches and routers over SSH with a read-only account, keeps every version of their running configuration on your own computer, and shows you the exact lines that changed between any two of them — with the commands that would restore the earlier one. No agents on the devices, no cloud account, no configuration is ever pushed.

Read-only SSH Line-by-line diffs Rollback commands Secrets masked Local storage No cloud account

DEMO

See it in action

What it actually does

ConfigWatch opens an SSH session to each device you add, runs the one command that prints its running configuration, and stores the result. When the text differs from last time, it keeps the new version alongside the old one. When it does not, it records that the device was checked and moves on — identical configurations are not stored twice.

Then it answers the question you actually have: what is different? Not "the file changed" — the specific lines, grouped by the part of the configuration they belong to, with noise like uptime counters and timestamps filtered out so a real change is not buried under twenty lines of nothing.

The part you buy it for

Seeing the change is half the job. ConfigWatch also generates the commands that would put the configuration back — the removals first, then the restorations, in the order a device will actually accept them.

It generates them. It does not run them. The commands appear on screen for you to read, check against your own judgement, and paste in yourself if you agree. A tool that automatically reverses configuration on production network gear is a tool that will one day take out a site at 3am.

It cannot change your devices

ConfigWatch asks for a read-only account, and it never sends a configuration command. The commands it runs are the ones that print configuration and nothing else — this is enforced in code, and there are tests whose only job is to fail if a write command ever appears in that list.

Give it an account with read-only privileges anyway. Software should not be trusted because it promises; it should be given no more access than it needs.

Secrets never reach the disk

Configurations are full of credentials — hashed enable passwords, user password hashes, SNMP community strings, pre-shared keys and routing authentication keys. ConfigWatch recognises them per vendor, because the same secret is written differently on each, and masks the value while leaving the line intact so diffs still make sense.

If a line looks like it holds a secret and the masker is not sure it caught all of it, that configuration is not stored at all and you are told why. A backup that quietly leaks a device's enable password onto a laptop is worse than no backup.

Vendors it speaks — three, on purpose

Cisco IOS and IOS-XE, MikroTik RouterOS, and Ubiquiti EdgeOS / UniFi. That is the whole list today, and it is short because every vendor here was verified against real output rather than written from a manual.

A wrong command produces a backup that looks like it worked and contains nothing useful, which is the worst possible failure for a backup tool — so a vendor gets added when it can be checked against a real device, not before. Juniper, Arista, FortiGate and HP/Aruba are the next ones. If you have gear that is not on this list, say so — that is how the list grows.

The vendor is detected from the device's own banner, and when two vendors are equally plausible ConfigWatch refuses to guess and asks you to choose.

Old gear is not an afterthought

The switch that needs configuration backup most is usually the one nobody has updated since 2014. ConfigWatch tries modern SSH algorithms first, and only if the handshake itself fails does it retry with the legacy set that old firmware needs. A failed password is never retried — that is how accounts get locked out.

Everything stays on your computer

Configurations, history, credentials and the licence key all live in a folder in your home directory. Credentials are encrypted with the operating system's own keychain. Nothing is sent to MeshWatch, and ConfigWatch has no code that would let it — there is a test that fails if an outbound HTTP call is ever added to the collection path.

It fits with the rest

If SyslogWatch or DeviceWatch is installed on the same computer, they find each other. A device in DeviceWatch gets a View config history button that opens straight to that device here — because after "the interface went down", the next question is almost always "did someone change something?".

DOWNLOAD

Get ConfigWatch

Notarised · Version 0.4.5 · Apple silicon

macOS

macOS 12 Monterey or newer, Apple silicon. Signed with an Apple Developer ID and notarised by Apple, so it opens without a Gatekeeper warning. Intel build coming later.

Download DMG · 115 MB

Signed · Version 0.4.5

Windows — 64-bit

Windows 10/11 and Windows Server 2016 or newer (Desktop Experience). Authenticode-signed and timestamped. The certificate is new, so SmartScreen may still show a warning until it has built reputation — if it does, choose More info → Run anyway.

Download Installer · 99 MB

Version 0.4.5

Linux — 64-bit

Ubuntu 22.04 or newer, Debian 12 or newer. The .deb declares its dependencies, so it installs and runs on a minimal server install with nothing added by hand. Verified on Ubuntu 24.04, Ubuntu 22.04 and Debian 12.

Verify your download

Run shasum -a 256 ConfigWatch-0.4.5-arm64.dmg in Terminal and compare the result with the published checksum.

Checksums

Installation and administration guide → — first run, settings, firewall rules, and connecting it to MeshWatch Central.

Every install starts with a 30-day trial of Pro. Nothing is asked for up front — no card, no account, no email address.

PRICING

Free for a homelab. Pro when it is your job.

Free

$0

Enough for a rack at home, or to decide whether this is the tool you want.

  • Up to 3 devices shown
  • Manual backup of every device
  • Full version history
  • Line-by-line diffs between any two versions
  • Secret masking
  • Vendor detection
Download

Pro

$149/year

For the person who has to answer "what changed?" with a straight face.

  • Everything in Free
  • Unlimited devices
  • Scheduled automatic backups
  • Rollback command generation
  • Audit CSV and PDF reports
  • Priority support
Buy ConfigWatch Pro

Or start the 30-day trial first — no card, no account.

The diff is free on purpose — you should be able to see what a tool does before deciding it is worth paying for. What Pro adds is scale and the work that follows the diff. Free limits what is shown, never what is backed up: devices beyond the third are still collected and still stored, they are just hidden until you upgrade. A backup tool that quietly skips devices while looking like it is working would be the worst thing this could be. Pro is activated with a licence key emailed after checkout; the key carries its own expiry and is verified on your own computer, so ConfigWatch never contacts a licensing server. When a subscription lapses the free features continue and your history stays.

FAQ

Common questions

Can ConfigWatch change my device configuration?

No. It runs only the commands that display configuration, and that list is fixed in code with tests that fail if a write command is ever added. Rollback commands are generated as text on screen for you to review and run yourself — ConfigWatch never sends them. Use a read-only account regardless; that is the correct level of access for a tool whose entire job is reading.

What happens to passwords inside the configuration?

They are masked before anything is written to disk. ConfigWatch knows the shapes each vendor uses — enable secret, SNMP communities, pre-shared keys, wireless passphrases, API tokens — and replaces the value while leaving the surrounding line intact so diffs still make sense. If a line looks like it holds a secret that was not fully masked, the whole configuration is rejected rather than stored, and the reason is shown.

How is this different from RANCID or Oxidized?

Mostly in who it is for. Those are excellent, free, and run on Linux from the command line with a configuration file and a cron job — if that is already your environment, use them. ConfigWatch is for the person who administers a network but does not run a Linux server to babysit it: you add a device in a window, the diffs are readable, and the rollback commands are written for you. The trade is convenience for a licence fee, and the honest answer is that the free tools do the core job well.

How does it know which vendor a device is?

From what the device says about itself when you connect, matched against known banner patterns. If the evidence points to two vendors at once, ConfigWatch stops and asks rather than picking the higher score — a wrong guess means running the wrong command, which produces a backup that looks fine and contains nothing useful. You can also set the vendor yourself when adding a device.

My switch is old and SSH fails. Now what?

ConfigWatch tries current SSH algorithms first, and if the key exchange itself fails it retries automatically with the legacy algorithms that older firmware needs. That retry only happens on a negotiation failure — an authentication failure is never retried, because repeated attempts are how accounts get locked out. If both attempts fail, the error tells you which stage failed.

How often does it back up?

On Free, whenever you press the button. Pro adds a schedule that runs in the background and skips a run if the previous one is still going, so a slow device cannot cause overlapping sessions. Devices are collected a few at a time rather than all at once — a hundred simultaneous SSH sessions is a good way to get noticed by whoever runs the network.

Does it store a copy every time it checks?

No. If the configuration is identical to the last stored version, ConfigWatch updates the “last checked” time and stores nothing new. History is a list of changes, not a list of runs — a device that never changes uses almost no disk.

Up to 100 versions are kept per device, oldest pruned first. Whatever happens, the most recent version is never deleted: a backup tool that prunes its way down to no backup at all would be the worst bug it could have, so that case is written into the code and pinned by a test.

Where are my credentials kept?

In an encrypted file in your home directory, sealed with the operating system's keychain — the macOS Keychain, or DPAPI on Windows. They can be entered but never read back out: the application window has no way to retrieve a stored password, because it has no need to. If you use an SSH key, ConfigWatch stores the path to the key file, not the key.

Does anything leave my computer?

Only the SSH connections to the devices you added. Configurations, history and diffs are written to a folder in your home directory and go nowhere else. There is no telemetry and no licensing callback — the licence key is verified locally against a public key built into the app, so activation works on an air-gapped network.

How does Pro activation work?

After checkout you receive a licence key by email. It is sent from license@meshwatch.app, usually within a minute — if it is not in your inbox, check your Junk or Spam folder before writing to support. Paste it into the License box in the app and press Activate. The key carries its own expiry date and is checked on your own computer, so it works offline. When you renew, a fresh key is emailed to you.

Does it work with MeshWatch Central?

Optionally. Connect ConfigWatch to your own MeshWatch Central server and its alerts join whatever CertWatch, DeviceWatch, TrafficWatch, SyslogWatch and TrapWatch are reporting into one shared inbox — a config change on the same switch where an interface just dropped shows up as one incident, not two. ConfigWatch sends Central a one-line summary like “3 lines changed on GigabitEthernet0/3” — never the configuration itself, never a secret. Central is a separate product you run on your own server; ConfigWatch works exactly the same with or without it.

CONTACT

Questions or feedback? Email support@meshwatch.app or open a topic on the Support page.