On Mon, Nov 1, 2010 at 8:16 AM, Tim Durack <[email protected]> wrote:

> On Mon, Nov 1, 2010 at 7:58 AM, Phil Mayers <[email protected]>
> wrote:
> > On 31/10/10 15:39, Keegan Holley wrote:
> >>
> >> If you are simply trying to disable a command have you thought about
> doing
> >> so in tacacs?  It sounds like it would be simpler and it also has the
> >> benefit of being centralized so you won't need to configure it on each
> >> individual router.
> >
> > It also has the disadvantage of being centralised, so each router has to
> be
> > configured to talk to a central point-of-failure.
> >
> > :o)
> >
> > +1 for wanting to disable this w/o TACACS
>
> Exactly. In my book, "simple" = less operational dependencies. (Plus
> configuration management system carries the burden of making these
> changes anyway.)
>
>
I'm not sure I understand the drawback of TACACS.  It's obvious that
redundancy is needed there.  If you're already using TACACS it seems easier
to place it there.  I'm not sure I like the idea of a network using local
auth everywhere but to each his own.  If you use EEM what's to stop other
"senior" engineers from just removing the script temporarily?
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to