<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Anti-lockout best practice</title>
	<atom:link href="http://ccielab.ro/2010/07/anti-lockout-best-practice/feed/" rel="self" type="application/rss+xml" />
	<link>http://ccielab.ro/2010/07/anti-lockout-best-practice/</link>
	<description>Cry in the Lab, Laugh in the Datacenter</description>
	<lastBuildDate>Mon, 12 Mar 2012 12:15:51 +0200</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: bogd</title>
		<link>http://ccielab.ro/2010/07/anti-lockout-best-practice/comment-page-1/#comment-340</link>
		<dc:creator>bogd</dc:creator>
		<pubDate>Mon, 12 Mar 2012 12:15:51 +0000</pubDate>
		<guid isPermaLink="false">http://ccielab.ro/?p=130#comment-340</guid>
		<description>The &quot;reload in&quot; command should be a last resort - in 99% of the cases, you will not lock yourself out, so you can issue a &quot;reload cancel&quot;.

I agree that it&#039;s a completely different story when dealing with production routers serving &quot;zounds of users&quot;, but then again... you _really_ shouldn&#039;t be making potentially disruptive changes (or any kind of changes!) on such routers outside of a maintenance window.  :)

And to answer the Juniper part - I really do love the &quot;commit&quot; feature, but... if you commit a non-working config, you&#039;re just as scre^H^H^H^H much in trouble :) . </description>
		<content:encoded><![CDATA[<p>The &#8220;reload in&#8221; command should be a last resort &#8211; in 99% of the cases, you will not lock yourself out, so you can issue a &#8220;reload cancel&#8221;.</p>
<p>I agree that it&#8217;s a completely different story when dealing with production routers serving &#8220;zounds of users&#8221;, but then again&#8230; you _really_ shouldn&#8217;t be making potentially disruptive changes (or any kind of changes!) on such routers outside of a maintenance window.  <img src='http://ccielab.ro/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>And to answer the Juniper part &#8211; I really do love the &#8220;commit&#8221; feature, but&#8230; if you commit a non-working config, you&#8217;re just as scre^H^H^H^H much in trouble <img src='http://ccielab.ro/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  .</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mircea</title>
		<link>http://ccielab.ro/2010/07/anti-lockout-best-practice/comment-page-1/#comment-149</link>
		<dc:creator>Mircea</dc:creator>
		<pubDate>Fri, 07 Oct 2011 09:06:08 +0000</pubDate>
		<guid isPermaLink="false">http://ccielab.ro/?p=130#comment-149</guid>
		<description>Yes, it&#039;s a good idea the reload in command, but imho when you are dealing with production routers it is better to lock yourself out than having zounds of users complaining they were disconnected from their applications. 
In my opinion there are  like 3 viable solutions:
1. be careful!
2. use a EEM applet that would issue a &quot;no ip access-list&quot; or reset the acl config to a template-based one, say after 10 minutes, if no &quot;wr mem&quot; is issued.
3. use Juniper ( :P ), that has the &quot;commit&quot; command

PS: anyway, I&#039;m just being picky, I actually used &quot;reload in&quot; many times..but never on backbone equipments</description>
		<content:encoded><![CDATA[<p>Yes, it&#8217;s a good idea the reload in command, but imho when you are dealing with production routers it is better to lock yourself out than having zounds of users complaining they were disconnected from their applications.<br />
In my opinion there are  like 3 viable solutions:<br />
1. be careful!<br />
2. use a EEM applet that would issue a &#8220;no ip access-list&#8221; or reset the acl config to a template-based one, say after 10 minutes, if no &#8220;wr mem&#8221; is issued.<br />
3. use Juniper ( <img src='http://ccielab.ro/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  ), that has the &#8220;commit&#8221; command</p>
<p>PS: anyway, I&#8217;m just being picky, I actually used &#8220;reload in&#8221; many times..but never on backbone equipments</p>
]]></content:encoded>
	</item>
</channel>
</rss>

