[c-nsp] cisco energywise 'feature'

Alan Buxey A.L.M.Buxey at lboro.ac.uk
Fri Jan 15 15:41:21 EST 2010


hi,

just a quick heads-up on this - see if anyone else has fallen foul
of it or got a registered bug ID before I chase this one further.

we have noted that with IOS 12.2(52)SE on both 2960 and 3750 platforms,
whenever you do a show running-config, the encrypted password (shared-secret)
for energywise (which is a method 7 encryption and not method 5 - natch)
that gets displayed changes. 

of course...this means that any software tools that check for changes to keep
revisions and alert our change system believe that there has been a change.
we use rancid and some home-brew stuff too....so we get a notice for every switch
which we have deployed energywise on.  which is nice.  :-(

those with ASA experience will see the similarities with an ASA 8.x bug that was 
fixed recently - we had the same sort of issue with that :-(

so - just a heads up for those who dont want to find this out themselves

PS there is a 'work around' - insert the shared-secret as plain text (method 0)
- but thats a nice way of letting casual eyes see the shared-secret - and that shared-secret
gives you access to some of the new energywise features - turn ports off/on etc.

alan


More information about the cisco-nsp mailing list