weird commands on CISCO3825 boot

I was quite disturbed at first when I recently saw the following commands being logged after a router boot-up:

idx   sess           user@line      Logged command
1     1        console@console  |access-list 199 permit icmp host 10.10.10.10 host 20.20.20.20
2     1        console@console  |crypto map NiStTeSt1 10 ipsec-manual
3     1        console@console  |match address 199

4     1        console@console  |set peer 20.20.20.20

5     1        console@console  |exit
6     1        console@console  |no access-list 199
7     1        console@console  |no crypto map NiStTeSt1

In this case I am fully certain that there was nothing connected to the console of the device during the aforementioned boot process… a brief google later it turned out the crypto map in question was part of the autotest process of the crypto accelerator when the router boots up. :)

http://www.securityfocus.com/archive/75/474377/30/180/threaded

Tags: , ,

Saturday, October 11th, 2008 General

No comments yet.

Leave a comment