On Mon, Nov 1, 2010 at 8:16 AM, Tim Durack <[email protected]> wrote:
> On Mon, Nov 1, 2010 at 7:58 AM, Phil Mayers <[email protected]> > wrote: > > On 31/10/10 15:39, Keegan Holley wrote: > >> > >> If you are simply trying to disable a command have you thought about > doing > >> so in tacacs? It sounds like it would be simpler and it also has the > >> benefit of being centralized so you won't need to configure it on each > >> individual router. > > > > It also has the disadvantage of being centralised, so each router has to > be > > configured to talk to a central point-of-failure. > > > > :o) > > > > +1 for wanting to disable this w/o TACACS > > Exactly. In my book, "simple" = less operational dependencies. (Plus > configuration management system carries the burden of making these > changes anyway.) > > I'm not sure I understand the drawback of TACACS. It's obvious that redundancy is needed there. If you're already using TACACS it seems easier to place it there. I'm not sure I like the idea of a network using local auth everywhere but to each his own. If you use EEM what's to stop other "senior" engineers from just removing the script temporarily? _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
