CiscoTools.dev

Interface Cleanup Auditor

Paste show interfaces status, counters or timers, mac address-table, power inline, cdp or lldp neighbors, running-config, and show version, and get a reviewed cleanup plan for every port: which ones look dead, which look stale, and which are safe to reclaim. Every call shows the evidence behind it — link state, idle timers, MAC activity, PoE draw, neighbor announcements, and config — and everything the data cannot prove is declared, never silently assumed. Pro adds a whole-network mode: download a collector script for a list of devices, upload the evidence file it writes back, and review every device with the same evidence-first verdicts before downloading a reclaim script — generated on the server, dry run by default, and tested against mocks only. It has never touched a real switch or a real SecureCRT session; always run it in dry run first.

Open the Auditor

What it does

Frequently asked

What show commands does it read?

show interfaces status (the roster — paste that one at minimum), show interfaces counters or a full/filtered show interfaces for timers, show mac address-table, show power inline, show cdp neighbors or show lldp neighbors, show running-config, and the show version uptime line.

What verdicts can a port get?

Reclaim, stale, disabled, unknown, recently used, in use, or hands-off. Hands-off covers trunks, port-channel members, routed ports, and anything with a phone, access point or switch heard on it over CDP or LLDP — those are never candidates for reclaiming.

Why does it refuse to call some ports dead?

"Last input never" only means no traffic since the switch last booted. Without a pasted show version uptime line, or before that uptime clears the stale window, the auditor reports the port as unknown or stale rather than reclaim — a "never" on a switch that rebooted an hour ago proves nothing.