Hi,

On Wed, Jul 15, 2009 at 02:09:17AM +0200, Peter Rathlev wrote:
> Currently we only allow "if-authenticated" on the console port. After a
> few funny situations the past year I'm seriously considering just
> enabling it for VTYs also. I'm not exactly sure why I haven't done this
> yet, but there's something inside my head telling me that there's some
> security aspect here. I just can think of it. :-)

Well, one angle of attack could be...

 - null-route the TACACS server IP
 - instant "full" access

Of course the "null-route" command would be visible in TACACS command
accounting, so you know whom to slap :-)

gert
-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             [email protected]
fax: +49-89-35655025                        [email protected]

Attachment: pgpAhXXO3vUJ6.pgp
Description: PGP signature

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to