[c-nsp] no mop enabled and PCI implications

Jared Mauch jared at puck.nether.net
Wed Jun 27 15:44:59 EDT 2007


On Wed, Jun 27, 2007 at 12:37:01PM -0700, Kevin Graham wrote:
>  On 6/27/07, Jared Mauch <jared at puck.nether.net> wrote:
> 
> >         Some versions of IOS have 'sh run all' which includes the defaults.
>  [...]
> > Router#sh run ?
> >   all        Configuration with defaults
> 
>  Still obviously a work in progress, looking at a 12.4(11)T box, this
>  specific case ('mop enabled') is not reflected, though I'm glad to see
>  progress begin made.

	If that's the case, it sounds like it's a bug and you should open
up a tac case, or perhaps Rodney could go in and file a bug directly.

>  Another annoying one, the default ISAKMP policy isn't shown either,
>  but that's a bit different and hopefully CSCei20320 will come around
>  before too long.

	Also a bug.  Folks should call tac and report these issues
promptly to help emphasize the importance of revealing all these
wacky things.  If your platform has (for example, lldp) and it's not
showing up as enabled either globally or per-interface, it's also a 'bug'.

	comparing our configs against what is revealed in this +defaults
(at least on a lab router) shows the following:

+parser cache
+service slave-log
+service prompt config

On each interface:
+ snmp trap link-status

and at the end:

+alias exec h help
+alias exec lo logout
+alias exec p ping
+alias exec r resume
+alias exec s show
+alias exec u undebug
+alias exec un undebug
+alias exec w where
+default-value exec-character-bits 7
+default-value special-character-bits 7
+default-value data-character-bits 8

	- jared



-- 
Jared Mauch  | pgp key available via finger from jared at puck.nether.net
clue++;      | http://puck.nether.net/~jared/  My statements are only mine.


More information about the cisco-nsp mailing list