rmd: (trinity keyboard)
[personal profile] rmd
i am pondering a technical IT config management best-practices problem. I'll put it behind the cut because a lot of you really don't care.


so, i've got a bunch of network devices. some of them are reachable via ssh, and some by telnet. all of them are reachable on their console by telnetting to a console server.

the devices, and the console server, all authenticate via RSA's securid two factor authentication.

most of my network devices let me send a magic SNMP string that tell the devices "hey, tftp your config over here".

but some of them don't. those are the troublesome ones.

the easiest way is for me to set up a static password that's good for half an hour or so per day, and run my "login and grab the config" scripts with those. except for the fact that it would be allowing something with a static password to log into my network gear. even time-restricted, that's more of a big flapping hole than i'm comfortable with.

what are other people doing for config management on network devices that don't support (either by design or by "to be fixed in a later version of code" bugs) snmp-triggered tftp?

EDIT: the problem i am trying to solve is how to get automated periodic downloads of configs from these machines, when i can't authenticate with securid tokens (since that requires a human) and static passwords are pretty much too insecure.

this is the sort of thing that doesn't seem to make it into the "best practices" docs i've found so far, but i'll likely continue pouring over docs today...

thoughts? suggestions?

Date: 2005-07-28 04:15 pm (UTC)
From: [identity profile] rmd.livejournal.com
yeah, i don't have a problem getting to them when i'm doing so interactively. i'm trying to figure out how to get unattended copies of the configs on a regular basis for config management.

Profile

rmd: (Default)
rmd

June 2025

S M T W T F S
1234567
89 1011121314
15161718192021
22232425262728
2930     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 22nd, 2026 10:14 pm
Powered by Dreamwidth Studios