Re: enable/disable features in running configuration

jan <[email protected]>
Newsgroups gmane.linux.keepalived.devel
Message-ID <[email protected]>
Hi All,

Some idés for a new parser

To be secure and handle no ip address at all for routers in standby 
mode, it should be very handy to use LEVEL2 IN PROTOCOL LEVEL (on mac 
level), when talking to daemon, but tcp/ip needed for wan access. Some 
routers have mac-telnet, mac-ping, etc as standard, and discovery 
neighbors easy from management tool.

When tcp is in use, only SSL or ssh style connections should be in use.
Keepalived already use third party for SSL access reuse that.

I think pure telnet is a bad idé from security point, use ssh.

If telnet should be used restrict access at least by a ip access list.

When redesign parser and extend its functionally some kind of socket 
communication and push
technology should be implemented.

Example:

Two management tools is connected to same daemon, when a user do some 
changes, it should be
pushed out in other management tool window without a user refresh.

Counters on every state changes for statistic purpose.

list of some features:

1. handle all configuration from remote access

2. enable / disable features in configuration parts

3. Comment field ( to be use in management tool

4. statistic counters ( host up/down as example )

5. sockets slots for push state/configurations changes and feed of live 
data...

6. Save/Load Configuration from management tool

7. From a clean daemon aka no configuration at all, only LEVEL2 mac is 
possibly
    with default name and password.

8. Security level of user, read only, write, etc

9. Discover function for management tool need a broadcast packet daemon 
?


2015-05-04 09:57 skrev Alexandre Cassen:
> Hi Patrick,
> 
> Any option are open, as netop guy mainly I am used to play with CLI,
> that is the way most of us are conditioned to play around :D, but for
> sure every options are open. Please feel free to discuss and bring
> idea here. But we are all on the same line of saying, current conf
> parser MUST be changed…
> 
> My main constraint is not to rely on any third party lib as much as
> possible, that is my only constraint.
> 
> cheers,
> Alexandre
> 
>> On 02 May 2015, at 20:17, Patrick Schaaf <[email protected]> wrote:
>> 
>> Am 02.05.2015 18:24 schrieb "Alexandre Cassen" <[email protected]>:
>>> 
>>> What is great with CLI/VTY, IMHO, is the fact that client to
>> access is really simple and widely supported on every OS (telnet).
>> 
>> Hi,
>> 
>> I hope telnet (TCP on localhost) will not be the only alternative.
>> Unix domain sockets would be preferred. For TCP, do you tack on some
>> kind of ad hoc authentication? I think keepalived is quite often
>> deployed on hosts that also run internet facing non-root processes
>> (think apache), and a nonauthenticated TCP interface would open a
>> path for a hacked non-root apache process to command the root-run
>> keepalived process.
>> 
>> best regards
>> Patrick
> 
> 
> ------------------------------------------------------------------------------
> One dashboard for servers and applications across 
> Physical-Virtual-Cloud
> Widest out-of-the-box monitoring support with 50+ applications
> Performance metrics, stats and reports that give you Actionable 
> Insights
> Deep dive visibility with transaction tracing using APM Insight.
> http://ad.doubleclick.net/ddm/clk/290420510;117567292;y
> 
> _______________________________________________
> Keepalived-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/keepalived-devel

-- 

/Jan Holmberg

------------------------------------------------------------------------------
One dashboard for servers and applications across Physical-Virtual-Cloud 
Widest out-of-the-box monitoring support with 50+ applications
Performance metrics, stats and reports that give you Actionable Insights
Deep dive visibility with transaction tracing using APM Insight.
http://ad.doubleclick.net/ddm/clk/290420510;117567292;y
_______________________________________________
Keepalived-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/keepalived-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.