[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: A few potential requirements



    > Whether one connects remotely, or "locally" via a serial console,
    > the management interface should be identical (which seems most
    > likely do-able only via a CLI). 

I think that's something that we probably already have consensus on...
Any operators disagree with those two basic principles?

    1) A uniform management interface must be available via both in-band
       and out-of-band methods, and

    2) Every device must have a CLI.

It seems appropriate to me to start trying to nail down areas of consensus
like this.

    > I think having a CLI command that brings up an
    > *optional* menu-driven interface is okay.
    
I guess I agree, and there are certainly kinds of devices that I like to
have menus for, but I also think we need to be careful about making
suggestions to vendors which are beyond what we _really really want them
to do_, since it may encourage them to invest effort in menu stuff, rather
than in a uniform CLI.

    > - Another requirement that comes to mind is that the operator must be able to
    > specify which "in-band" method(s) to activate explictly. The default is that
    > they are all disabled. That is, I don't want to have to worry about the
    > web-interface, SNMP and CLI being enabled when I first install the box,
    > however I do want explicit knobs to turn those on.

I agree, basically, but think we need a little more discussion.  What
you say is definitely correct and important with respect to big iron.
What about small boxes, like CPE?  End-users won't have serial cables
and terminals, and may really need web access enabled by default.

    > The serial console "out-of-band" should always be on.

Specifically, do you mean that it should be on by default when a box
comes from the factory (I assume we have consensus on that), or that it
should be _impossible to disable_?  I think I'd agree with the latter as
well, but it's likely to be more controversial.

I think this is another reason why we need multiple permissions-levels in
the box, so that people won't feel that they need to disable craft ports.

                                -Bill