See that last line in the access list? Yeah, that means you don't have an access list
- Reference: 1628843406
- News link: https://www.theregister.co.uk/2021/08/13/on_call/
- Source link:
It seems an awful lot of you have had a run in with Cisco hardware at one time or another. The company is, after all, almost a byword for networking infrastructure and some interesting approaches to licensing.
"Will" (not his name) was no exception and one day was called to exercise his Cisco skills. "Do you," went the question, "know how to do a 'show tech' in a Cisco router?"
[2]
We're pretty sure this was a reference to the [3]show tech-support command which spits out information on the features of the relevant box. Unfiltered, it tends to be rather verbose and so its output is best redirected to a file for later perusal.
[4]
[5]
Will had spent a good few years at the Cisco coalface and so, of course, he knew about this command. Exactly why the customer wanted it, however, was open to question.
"There seems to be a problem with the firewall rules," explained the customer. "We are getting a lot of spam…"
[6]
Further investigation revealed that a new router had recently been installed on site by a crack team of contractors. Of course it had been set up correctly. After all, going near the precious hardware requires all manner of certifications and qualifications, right? Right?
[7]Breaking Bad or just a bad breakpoint? That feeling when your predecessor is BASIC
[8]Malware and Trojans, but there's only one horse the boss man wants to hear about
[9]Exsparko-destructus! What happens when wand waving meets extremely poor wiring
[10]Try placing a pot plant directly above your CRT monitor – it really ties the desk together
Will pondered the problem. "Let me take a look at the filter list first," he said.
Ah.
Sure enough, there was a filter list in place. The good config fairy had been! However, it appeared the bad config fairy had also paid a visit. The contractors had been unable to make things work and so rendered the list worthless with a simple command at the end of the access list: " permit any any ".
It's been a while since we last ventured into the world of Cisco configuration, but that looks pretty… bad. Sure, everything would work. But also, everything would work.
[11]
"The contractors actually didn't know how to program Cisco access lists," Will told us.
"See the last line in the access list?" he told the customer. "That means you don't have one."
A quick call to run show tech-support had expanded into multiple days to fix the rules. "In particular," he said, "email was meant to be channelled through a filtering company and not directly exposed."
Whoops!
Still, justice was swift.
"The contractors were fired."
Sometimes it seems every call-out is to fix somebody else's screw-up. Have you ever found a customer with its trousers so completely round its ankles thanks to a contractor error? Or were you that contractor? Let us know how that call went with an email to [12]On Call . ®
Get our [13]Tech Resources
[1] https://www.theregister.com/Tag/on-call
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YRZC5J4u-tpNtzOyZndweQAAABE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.cisco.com/c/m/en_us/techdoc/dc/reference/cli/nxos/commands/fund/show-tech-support.html
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRZC5J4u-tpNtzOyZndweQAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YRZC5J4u-tpNtzOyZndweQAAABE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRZC5J4u-tpNtzOyZndweQAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2021/08/06/on_call/
[8] https://www.theregister.com/2021/07/30/on_call/
[9] https://www.theregister.com/2021/07/23/on_call/
[10] https://www.theregister.com/2021/07/16/on_call/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YRZC5J4u-tpNtzOyZndweQAAABE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] mailto:oncall@theregister.com
[13] https://whitepapers.theregister.com/
"The contractors were fired."
And I hope they weren't paid.
Re: "The contractors were fired."
In my first employment, as a junior dev, I was working with an expert just contracted for his extensive DB2 knowledge. He was supposed to set up a battery of DB tests on a Friday for me and my mates to follow up during the weekend (as this was a Y2K project and time was running short, we, the minions, would be there - but not the expensive contractor).
The bad news is that he managed to screw up on every single test he was supposed to prepare by not allocating disk. space - and the leaving logs of it for us to see. That meant he had just wasted the whole team a Saturday By the end of the day I'd managed to redo - this time correctly - everything the expert was supposed to have done for us and our team got it's work done for others to take on next Monday.
The good news it that the following Monday, our manager heard us arguing about what had happened (I may have been expressing in not very pleasant terms how pissed off I was about all that sorry affair) and, after investigating it, called me apart and told me I didn't need to worry about it any more as the 'expert' was no longer working there.
Even better news is that I also got promoted a month or so later, with the way I handled that incident being a factor.
"See the last line in the access list?" he told the customer. "That means you don't have one."
That brightened my day somewhat, thanks! Therefore beer ->
Though on a slightly more serious note, makes you wonder WTF the contractors were playing at. How can anyone with any sort of conscience fudge a firewall/ACL with an any:any (or equivalent) and say nothing about it?
I’ve had people come to me with firewall changes with an ‘any’ in the rule.
Now for certain things this is fine i.e. web servers where you have inbound traffic; mail servers to smtp outbound etc
But the only thing that rule should be used for is with a deny statement and then send everything to a syslog server.
It isn’t hard to set up a firewall, think about it logically and check each service properly although with some of the stuff I have seen a lot of people shouldn’t be anywhere near a firewall.
I once had a director ask if the firewall was needed between the public facing web server and database server because "it slowed traffic down"...
was it seman's contracting dicks?
Had a run in with "cisco certified" experts back in late 90's from siemens.
quickly found out "cisco certified" means "can run config generator tool", to the point that they had no clue about subnets and even less clue about t1/e1 and isdn configs.
(they later did hire someone i had worked with, made sense as he was the company idiot! who's CV was written by a fantasy writer.)
Re: was it seman's contracting dicks?
". ..who's CV was written by a fantasy writer "
Either that or it was written and the job applied for by someone from within your own company. Just to, you know, help him get on to that next stage in his career.
Expensive
Usually you get what you pay for.
The difference between a good contractor and a great one
> A quick call to run show tech-support had expanded into multiple days
That sounds like a guy who knows his stuff.
However, a truly great contractor could have turned it into a month's work.
Oh yes!
Was once told of a contractor from a "Very Expensive" outfit whose build scripts for cloud VMs included the line
chmod -R 777 /var/data
Warning, just because you sign the contract with a company which seemed during the tender process to have some very good people no guarantee you won't get the apprentice doing the coding.
Obviously you need your best people getting contracts not actually doing them.
Re: Oh yes!
We once told a company to pull out of tender process because they wouldn't guarantee the people who were pitching for the work would actually be doing it. They were not impressed, and finally had to be told that they were wasting everyone's time and money, especially their own.
We once did the unforgivable and opened port 22 to * on a firewall... (a longish while ago)
...linux server got hacked and people was pissed off with us.
Luckily for us we caught it fairly quickly.
Suffice to say we now install fail2ban on every linux server we now deploy. Just in case.
My boss was a twit.
He executes the command. He specifies it to dump to a log file. He specifies a system critical filename. The command promptly shits itself as it's not able to do as it's told, the system process that has control of the file takes a crap as the system spends a few moments wrestling with itself trying to do the impossible. One hard reboot later and we have our network back, our network monitor restored, and the boss telling everyone "Don't do that last bit, ok?"
*Face palm sigh*