[HECnet] _PROVISIONAL_ map of HECnet, courtesy largely of Brian H.

Ian McLaughlin ian at platinum.net
Mon Jan 7 18:57:15 PST 2013


On 2013-01-07, at 6:31 PM, Dave McGuire <mcguire at neurotica.com> wrote:


Yeah more and more of us are using Ciscos to do this.   We really need
to find a way around this issue that doesn't involve manual maintenance
of routing info.

Perhaps an agreed-upon entry in INFO.TXT ?   That's still manually managed, but it's managed by the individual link owners.

I was digging around trying to find out exactly what DEC-type services Cisco supports.   One interesting vector is it's apparent support of MOP for allowing remote console.   There's this article talking about how bad it is for 'modern' networks:

http://blogs.cisco.com/security/router_spring_cleaning_-_no_mop_required/

The "SHOW DECNET NEIGHBOR" and "SHOW DECNET ROUTE" commands are both non-priviledged.   Perhaps we could allow a 'trusted' network mapping daemon the ability to get a remote console on the Cisco and execute and parse these commands?

Ian



More information about the Hecnet-list mailing list