it's here

### On 13 Feb 2002 15:55:25 +0000, Eric Brandwine <ericb@UU.NET> casually
### decided to expound upon Ron da Silva <> the following
### thoughts about "Re: it's here":

Without control plane seperation (and it's not possible with Cisco,
Juniper, or most other routers out there), management services are
listening on the public network, and that makes this very scary,
regardless of filtering policies, etc.

Huh? Junipers have the fxp0 interface which can be used for management.
You're just not supposed to route between the management fxp0 and your
production interfaces.

As do Cisco GSR's.. on their e0 interface. Same difference. You can even
enable or disable CEF on it :slight_smile: