[28382] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

RE: ABOVE.NET SECURITY TRUTHS?

daemon@ATHENA.MIT.EDU (Paul Froutan)
Fri Apr 28 16:57:13 2000

Message-Id: <4.2.2.20000428153946.04dcf970@pop3.rackspace.com>
Date: Fri, 28 Apr 2000 15:46:05 -0500
To: <rmeyer@mhsc.com>
From: Paul Froutan <pfroutan@rackspace.com>
Cc: nanog@merit.edu
In-Reply-To: <003f01bfb150$2b1d3e20$eaaf6cc7@PEREGRIN>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Errors-To: owner-nanog-outgoing@merit.edu


I don't think you can.  However, I use TACACS on all my switches and 
routers.  From what I know, TACACS passwords are encrypted using the key on 
your network devices and the TACACS server.  So, that, in combination with 
a private management LAN not accessible by your customers should lock down 
your network pretty effectively.  Any comments?

At 4/28/00 -0700, you wrote:

> > Exiled Dave
> > Sent: Friday, April 28, 2000 1:10 PM
>
> > Lets think about this, cisco in no way has such a flaw
> > that would allow someone to 'root' and erase all the
> > info on switches. The password was sniffed.
>
>Can one setup SSH on a Cisco 6509?

Paul Froutan                              Email: pfroutan@rackspace.com
Rackspace, Ltd                       <http://www.rackspace.com>



home help back first fref pref prev next nref lref last post