Discussion:
enterprise change/configuration management and compliance software?
(too old to reply)
jamie
2008-04-15 04:13:15 UTC
Permalink
Phil Regnauld
2008-04-15 07:31:38 UTC
Permalink
jamie (j) writes
device, and by 'device' i mean router and/or switch) configuratio
management (and (ideally) compliance-auditing_and_assurance) software
We currently use Voyence (now EMC) and are looking into other options fo
various reasons, support being in the top-3 ..
So I guess using something tried, tested and free like Rancid + ISC's audi
scripts are not within scope
So, I pose: To you operators of multi-hundred-device networks : what d
you use for such purposes(*)
Rancid :) (+ and now some home developed stuff
This topic seemed to spark lively debate on efnet
The current weather would spark lively debate on most IRC channels

Phil
Peter Dambier
2008-04-15 09:33:41 UTC
Permalink
Well

at Exodus we started talkimg about IASON

In the long run everybody was afraid of IASON. They dared no
work on it

Later I developed some bits and parts

When we changed hardware in a small company (200 PCs, 20 server
5 HP Procurve switches and two routers) IASON would discove
the switches as fast as they were powered and would move the
to a management network

Operators and management were not amused
IASON was changing passwords and ip-addresses :

That has been the only try

They idea is still a prolog based AI system, learning and knowin
every hardware, how it is configures and connected

You move a PC from one location to another because people do mov
or because a port on a switch has gone dead. IASON reprogramme
switches and ports so you get the same VLAN

Somebody is replacing a switch for whatever reason. IASON find
the new switch and sees the connected pcs and uplinks. It reconfigure
the switch so as to replace the old one. You do net even need t
mind where everything was connected. IASON can change across vendors

I guess it will take same time - but in the long run we will get i
and it will be open source

Kind regard
Pete
Post by Phil Regnauld
jamie (j) writes
device, and by 'device' i mean router and/or switch) configuratio
management (and (ideally) compliance-auditing_and_assurance) software
We currently use Voyence (now EMC) and are looking into other options fo
various reasons, support being in the top-3 ..
So I guess using something tried, tested and free like Rancid + ISC's audi
scripts are not within scope
So, I pose: To you operators of multi-hundred-device networks : what d
you use for such purposes(*)
Rancid :) (+ and now some home developed stuff
This topic seemed to spark lively debate on efnet
The current weather would spark lively debate on most IRC channels
Phil
--
Peter and Karin Dambie
Cesidian Root - Radice Cesidian
Rimbacher Strasse 1
D-69509 Moerlenbach-Bonsweihe
+49(6209)795-816 (Telekom
+49(6252)750-308 (VoIP: sipgate.de
mail: ***@peter-dambier.d
http://iason.site.voila.fr
https://sourceforge.net/projects/iason
http://www.cesidianroot.com
jamie
2008-04-15 13:34:34 UTC
Permalink
Fred Reimer
2008-04-15 14:58:25 UTC
Permalink
Yamasaki, Charles
2008-04-15 17:25:05 UTC
Permalink
Matthew Petach
2008-04-15 20:30:54 UTC
Permalink
Gentlemen (and Ren!): ;-
I'm currently investigating options w.r.t. enterprise-wide (over 25
device, and by 'device' i mean router and/or switch) configuratio
management (and (ideally) compliance-auditing_and_assurance) software
We currently use Voyence (now EMC) and are looking into other options fo
various reasons, support being in the top-3 ..
So, I pose: To you operators of multi-hundred-device networks : what d
you use for such purposes(*)
(*)see subjec
We have several thousand network devices currently in play

***@nowherespecial:/tftp/conf/latest> ls *.conf | wc -
741
***@nowherespecial:/tftp/conf/latest

I hand read each device configuration check-in email that goes pas
to see if there's errors in the configs, security violations, or other WTF-is
elements in the config check-in, and mail back a nag notice to th
person who changed the config

Currently, I received between 1900 and 3000 email messages a day

I sleep 3 hours a night
jamie risha
Hope that helps answer your question

Mat

Loading...