--- Begin Message ---
> On Aug 6, 2016, at 11:30 AM, Nick Hilliard <[email protected]> wrote:
> 
> On 5 Aug 2016, at 11:02, Saku Ytti <[email protected]> wrote:
>> I disappointed Cisco does not mention CoPP at all.
> 
> Or running ntp in a vrf, although that didn't stop problems with the last bad 
> ntp bug on ios.

Being primarily a sysadmin, it’s always perplexed me why IOS binds services to 
every 
active interface by default and provides no simple configuration directive to 
specify
which interface a service (ntp, ssh, tftp, snmp, etc.) should listen on.  This 
is the norm
on *nix since the ’90’s.  Even if some daemon listens on all configured IPs, 
there’s going
to be a config option to the daemon to specify which IP to bind to.

How easy would this make configuring things:

interface loopback0 ip address 10.10.10.101

ip ssh listen loopback0
ip ntp listen loopback0
ip snmp listen loopback0

ip access-list mgmt
 permit from mgmt-ips to 10.10.10.101
 deny from all

That seems so much simpler than CoPP and other baroque options to limit
management traffic…

Charles

> 
> Nick
> 
> 
> _______________________________________________
> cisco-nsp mailing list  [email protected]
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/


--- End Message ---
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to