10-04-2004 06:05 AM - edited 02-20-2020 11:39 PM
I was very suprised to find that i can't use telnet command from PIX device? Why this functionality is absent?
10-04-2004 06:56 AM
Why would the functionality be there? Wouldn't it seem ironic to be launching an easily snooped, clear-text connection to another device on your network from your "security device"?
Scott
10-04-2004 07:40 AM
OK, I'll bite:
1. Because it's convenient to be able to probe tcp ports and grab banners, etc.
2. If security is the reason, why not SSH then?
3. Because sometimes telnet is OK. Wouldn't it make sense to let the user (firewall admin in this case) make that decision?
Simon
10-04-2004 09:09 AM
More lines of code = less secure code
:)
10-05-2004 12:31 PM
I submitted an enhancement request to the Pix team for a customer maybe a year ago for this feature(telnet from pix), along with traceroute and scheduled reloads.
Only scheduled reloads appear to make it in the next major release. This is most likely due to the reasons the others have mentioned.
peter
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide