Linux, FreeBSD, Juniper, Cisco / Network security articles and troubleshooting guides

FAQ
It is currently Sun Dec 10, 2023 5:35 am


Author Message
mandrei99
Post  Post subject: Junos - How to limit arguments to ping CLI command  |  Posted: Wed Jun 26, 2013 6:31 pm

Joined: Tue Aug 04, 2009 9:16 am
Posts: 250

Offline
 

Junos - How to limit arguments to ping CLI command

The most elegant approach I've found so far is to explicitly allow "ping" arguments that need to be allowed (and the safest, I would say).
Code:
allow-commands = "(^show route)|(^show route .*)|(^quit)|(^ping (r[^a]|s[^i]|c|tt|no-re|.*host.*).*)|(^traceroute .*)|(^show bgp summary)"


And the outcome:
Code:
juniper@CORE_R1> ping ?
Possible completions:
  <host>               Hostname or IP address of remote host
  count                Number of ping requests to send (1..2000000000 packets)
  no-resolve           Don't attempt to print addresses symbolically
  record-route         Record and report packet's path (IPv4)
  routing-instance     Routing instance for ping attempt
  source               Source address of echo request
  strict               Use strict source route option (IPv4)
+ strict-source        Intermediate strict source route entry (IPv4)
  ttl                  IP time-to-live value (IPv6 hop-limit value) (1..255 hops)

So above directive allows
- "ping r" commands, but not "ping ra"
- "ping s" commands, but not "ping si"
- "ping c" commands
- "ping tt" commands
- "ping no-re" commands
- "ping <host>". This is important otherwise you won't be able to use a destination IP/hostname for ping.





Top
admin
Post  Post subject: Re: Junos - How to limit arguments to ping CLI command  |  Posted: Thu Jun 27, 2013 4:04 am
Site Admin

Joined: Mon Aug 03, 2009 8:43 am
Posts: 104

Offline
This is a tacacs format directive, not Junos config.

_________________
VPSie - SSD VPS servers in AMS-IX, LINX, DE-CIX
https://vpsie.com


Top
Display posts from previous:  Sort by  
E-mail friendPrint view

Topics related to - "Junos - How to limit arguments to ping CLI command"
 Topics   Author   Replies   Views   Last post 
There are no new unread posts for this topic. Junos restricted user disallow "ping rapid" and "ping size" operational commands

mandrei99

0

2894

Wed Jun 26, 2013 6:02 pm

mandrei99 View the latest post

There are no new unread posts for this topic. Junos: ping: invalid routing instance `RI0'

mandrei99

0

5100

Fri Jan 03, 2014 10:11 am

mandrei99 View the latest post

There are no new unread posts for this topic. Junos tacacs plus authentication for restricted privileges user with ping restrictions

admin

1

6102

Wed Jun 26, 2013 9:52 am

admin View the latest post

There are no new unread posts for this topic. MTR / My traceroute in Junos

mandrei99

1

7148

Mon Oct 10, 2016 5:54 am

barrel View the latest post

There are no new unread posts for this topic. Juniper - Junos 11.4R8 based Olive

mandrei99

1

5739

Tue Jun 18, 2013 5:36 am

mandrei99 View the latest post

There are no new unread posts for this topic. Junos: How to show uncommitted changes and cancel them

mandrei99

1

37263

Wed Sep 25, 2013 7:31 am

mandrei99 View the latest post

There are no new unread posts for this topic. Junos: How to list routing table IDs

admin

0

3653

Sat Jan 17, 2015 3:53 pm

admin View the latest post

There are no new unread posts for this topic. Juniper SRX / Junos rescue configuration is not set

mandrei99

0

8313

Mon Feb 16, 2015 11:42 am

mandrei99 View the latest post

There are no new unread posts for this topic. How to search junos configuration option within cli help apropos

mandrei99

0

2737

Mon Jan 12, 2015 12:34 pm

mandrei99 View the latest post

There are no new unread posts for this topic. Junos system configuration archival is not working over scp

mandrei99

0

8091

Thu Jan 01, 2015 4:06 am

mandrei99 View the latest post

 

Who is online
Users browsing this forum: No registered users and 0 guests
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum
Jump to:  
News News Site map Site map SitemapIndex SitemapIndex RSS Feed RSS Feed Channel list Channel list


Delete all board cookies | The team | All times are UTC - 5 hours [ DST ]



phpBB SEO