Hi, On Wed, Jul 15, 2009 at 02:09:17AM +0200, Peter Rathlev wrote: > Currently we only allow "if-authenticated" on the console port. After a > few funny situations the past year I'm seriously considering just > enabling it for VTYs also. I'm not exactly sure why I haven't done this > yet, but there's something inside my head telling me that there's some > security aspect here. I just can think of it. :-)
Well, one angle of attack could be...
- null-route the TACACS server IP
- instant "full" access
Of course the "null-route" command would be visible in TACACS command
accounting, so you know whom to slap :-)
gert
--
USENET is *not* the non-clickable part of WWW!
//www.muc.de/~gert/
Gert Doering - Munich, Germany [email protected]
fax: +49-89-35655025 [email protected]
pgpAhXXO3vUJ6.pgp
Description: PGP signature
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
