It’s 2025 and you still only support single DES 56 for SNMPv3 monitoring? Really?
Confirmed here they are working on AES. Hey it’s only 2025, no rush.
<>
Also here:
Why not AES256 at this point? Some Cisco switches are 256, Nexus 9Ks though are 128.
11 Spice ups
Guess what doesn’t support DES anymore? RHEL 9. So I can’t poll it from there or even snmpwalk it.
4 Spice ups
A DES key was broken in 22 hours by the EFF in 1999. Anyone want to guess how many micro seconds it would take with a modern GPU now?
5 Spice ups
Half that time maybe less.
2 Spice ups
I would guess more or less instantly.
4 Spice ups
sparkfist
(Sparkfist)
6
Here I was thinking that Cisco Meraki was a good service. Time to start looking for another vendor.
2 Spice ups
Meraki is notoriously, always gimping their devices compared to what they put in the full Cisco suite. Even the Small Business line doesn’t get all the features.
2 Spice ups
I keep waiting for someone to post, no sir, you are misinformed, go here click here, and that’s where you’ll find it, but the employee post stating they are still working on it sealed the deal.
DES should have been dead a decade ago.
4 Spice ups
Cisco Meraki has always been a toy compared to actual enterprise gear. Do their firewalls even support advertising routes via OSPF? Last I checked there was zero BGP support.
1 Spice up
There’s a difference between not supporting a protocol and security malfeasance. I consider only supporting DES to be exactly that.
1 Spice up
I’m glad we use HPE/Aruba for the vast majority of clients, the one Meraki we dealt with was a PITA to manage
somedude2
(somedude2)
12
Well, they were using distributed.net, so 100,000 computers helped out. The key rate was 245 billlion keys per second, and there was a touch of luck, they only searched 22% of the keys to hit the right one.
Having noted that, modern GPU’s have clock speeds 20x faster than cpu’s in 1999 and thousands of cores, not just one.
So, yeah, a day …
Scary bit: Every hacker can use their own GPU..
wslrav
(Rav7027)
13
Using Ruckus at multiple sites. Would recommend.
Wasn’t my choice in this case. And yes I know you can monitor these in the Meraki portal. Was trying to add them to Zabbix for some basic monitoring along with everything else and discovered that security nonsense.