> ## Documentation Index
> Fetch the complete documentation index at: https://docs.myrmex.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Cisco Switch

> Connect a Cisco switch (IOS, IOS-XE, or NX-OS) to Myrmex over SSH — create the CLI account and add the integration.

import { Note, Steps, Step, CardGroup, Card, Tip } from '@mintlify/components';

Connect your **Cisco** switch (IOS, IOS-XE, or NX-OS) so Myrmex can read its configuration, audit its hardening, run diagnostics, and — with approval — apply CLI changes. Myrmex reaches the device over **SSH** through a [Collector](/documentation/agent-endpoint-security/collector-mode) on your network and queries it in real time.

## What Myrmex Can Do

<CardGroup cols={2}>
  <Card title="Read & troubleshoot" icon="magnifying-glass">
    Inspect interfaces, VLANs, trunks, routing, spanning tree, and MAC/ARP tables — read-only diagnostics across IOS, IOS-XE, and NX-OS.
  </Card>

  <Card title="Hardening audit" icon="shield-halved">
    Run a [Security Posture](/documentation/security-posture/overview) audit against the switch configuration.
  </Card>

  <Card title="Run CLI commands" icon="terminal">
    Execute operational and configuration commands, with changes applied on approval.
  </Card>

  <Card title="Config & inventory" icon="floppy-disk">
    Review the running configuration and track the model and OS version — read on demand, never stored.
  </Card>
</CardGroup>

## Before You Start

* A **Collector** that can reach the switch's management IP over SSH. See [Deploying the agent](/documentation/agent-endpoint-security/installation) and [Collector mode](/documentation/agent-endpoint-security/collector-mode).
* An **account with CLI access** to the device — read-only is enough for analysis; read-write is required to apply changes.

## Step 1 — Create the Credential in Cisco

<Steps>
  <Step title="Enable SSH">
    On IOS and IOS-XE, set a hostname and IP domain name, generate host keys with `crypto key generate rsa`, then enable SSH version 2 and set the VTY lines to `transport input ssh` with `login local`. On NX-OS, enable the SSH feature with `feature ssh` (it is on by default).
  </Step>

  <Step title="Create a user">
    Create a local account for Myrmex with a strong password. On IOS/IOS-XE, use `privilege 15` for read-write access, or a lower privilege level for analysis only. On NX-OS, assign the `network-admin` role for read-write, or `network-operator` for read-only. Note the username and password — you'll enter them in Myrmex.
  </Step>
</Steps>

<Tip>
  Prefer least privilege: start with a read-only account, and grant read-write only when you want the agents to apply changes for you.
</Tip>

## Step 2 — Add the Integration in Myrmex

From the [Directory](/documentation/ai-workspace/overview#the-directory), choose **Add Integration → Cisco Switch**, then fill in:

| Field           | Description                                                                                           |
| --------------- | ----------------------------------------------------------------------------------------------------- |
| **Name**        | A unique name for this switch.                                                                        |
| **Description** | Optional note to identify the device.                                                                 |
| **IP**          | The switch management IP or hostname the Collector can reach.                                         |
| **SSH Port**    | The SSH port (default `22`).                                                                          |
| **Username**    | The CLI account created in Step 1.                                                                    |
| **Password**    | That account's password.                                                                              |
| **Model**       | Your Cisco switch model series (Catalyst, Nexus, and others).                                         |
| **Version**     | The Cisco IOS/IOS-XE/NX-OS version running on the device, or **Other**.                               |
| **Collector**   | The [Collector](/documentation/agent-endpoint-security/collector-mode) that opens the SSH connection. |

## Connect

Click **Connect** to validate the SSH connection and finish. The switch then appears under **Environment → Integrations**, and you can ask the [Integration Specialist](/documentation/multi-agent-system/integration-specialist-agent) about it in the Workspace.

<Note>
  Myrmex queries the switch in real time over SSH and acts only on approval. It does not store or retain the device's configuration or data on the Myrmex side.
</Note>
