Networking-Forums.com

Professional Discussions => Security => Topic started by: deanwebb on June 08, 2016, 12:54:47 PM

Title: Cisco ACS - Only Use Internet Explorer
Post by: deanwebb on June 08, 2016, 12:54:47 PM
Just had a guy blow up our ACS by editing rules using Firefox. Cisco said to use only IE, since Firefox will wipe out the database.

I hope everyone here learns from the mistakes of others. This one's a biggie, since there's no flashing warning sign when folks log on with Firefox...

:tmyk:
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: srg on June 08, 2016, 02:47:51 PM
That's just sad :\

https://en.wikipedia.org/wiki/Usage_share_of_web_browsers#/media/File:Browser_Market_Map_June_2015.svg
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: deanwebb on June 08, 2016, 03:56:17 PM
Even crazier, I remember Cisco telling me to *not* use IE when editing rules/policies in ISE, due to it renumbering all the rules/policies in a crazy way.

So we got one browser that kills ACS but saves the day in ISE and another browser that's the exact opposite.

:facepalm1:
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: DanC on June 08, 2016, 05:07:29 PM
Jesus that's bad! It's been 12 months since I used ACS but the only browser I could get to work properly was a really old version of Firefox (version 12 IIRC). I'm pretty sure it was in the release notes as supported too!
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: deanwebb on June 08, 2016, 05:10:26 PM
Our guy used Firefox because Chrome and IE didn't display all the fields he needed to view, while Firefox did. So he made a change, a teeny tiny change, clicked save and then...

MELTDOWN

We are now providing product feedback to the Cisco ACS developers.

:developers:

Did get back that putting the ACS website into "compatibility mode" will allow all the fields to display in IE. Nice to know, going forward.
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: DanC on June 08, 2016, 05:19:33 PM
That's crap.

I actually rate ACS too, it's a great product 'when' you find a stable version  ;D
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: Dieselboy on June 08, 2016, 10:26:06 PM
Problems like this really pee me off. I don't think you can wholely blame the user here, unless you specifically gave him instructions which said something like DO NOT EFFING USE FIREFOX
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: deanwebb on June 09, 2016, 08:55:11 AM
Quote from: Dieselboy on June 08, 2016, 10:26:06 PM
Problems like this really pee me off. I don't think you can wholely blame the user here, unless you specifically gave him instructions which said something like DO NOT EFFING USE FIREFOX

Believe me, we have given that instruction in the aftermath of the disaster. Still rebuilding the policies...
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: mlan on June 10, 2016, 01:28:40 PM
Dean, why not just restore the config from backup?
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: deanwebb on June 10, 2016, 02:14:29 PM
That's part of the fun... turns out, the original backup failed, but all the incremental ones succeeded. A look at backup jobs shows the last 200 were all successful... they're just also useless because of that original failure...
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: mmcgurty on June 14, 2016, 07:42:49 PM
This just bit us yesterday.  Luckily we were able to restore from a backup but it took like most of the afternoon yesterday.  Total BS by Cisco.

https://www.cisco.com/c/en/us/support/docs/field-notices/641/fn64144.html
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: deanwebb on June 14, 2016, 07:57:17 PM
I lol'd when I saw the date on the field notice... same date as when I started the thread...

:yeahright:
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: Dieselboy on June 14, 2016, 09:59:46 PM
Has that field notice been raised because of you guys?
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: deanwebb on June 14, 2016, 10:10:35 PM
Quote from: Dieselboy on June 14, 2016, 09:59:46 PM
Has that field notice been raised because of you guys?

Not going to say it was because of us... but it was because of us. When a large multinational has a product blow up and then asks for some kind of notification going forward, it gets some kind of notification. Long-term, we want flashing warning lights if someone logs in with The Wrong Browser.
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: wintermute000 on June 15, 2016, 04:58:34 AM
Long term you want clearpass (https://s3.amazonaws.com/tapatalk-emoji/emoji14.png)
But no seriously, that is a DISGRACEFUL bug.


No worky with common browser X? irritating
Explosion with common browser X (with no warning either)? completely unacceptable.


Maybe we can rename this forum to ciscowritesshittysoftwarewhathappenedtotheirQA.com



Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: icecream-guy on June 15, 2016, 07:36:01 AM

thanks for the link, just sent it out to the team as a heads up
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: deanwebb on June 15, 2016, 07:38:49 AM
Quote from: wintermute000 on June 15, 2016, 04:58:34 AM
Maybe we can rename this forum to ciscowritesshittysoftwarewhathappenedtotheirQA.com

I think you misspelled bradreese.com.  >:D
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: routerdork on June 15, 2016, 08:49:33 AM
Quote from: deanwebb on June 15, 2016, 07:38:49 AM
Quote from: wintermute000 on June 15, 2016, 04:58:34 AM
Maybe we can rename this forum to ciscowritesshittysoftwarewhathappenedtotheirQA.com

I think you misspelled bradreese.com.  >:D
LOL
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: NetworkGroover on June 15, 2016, 10:41:37 AM
Quote from: routerdork on June 15, 2016, 08:49:33 AM
Quote from: deanwebb on June 15, 2016, 07:38:49 AM
Quote from: wintermute000 on June 15, 2016, 04:58:34 AM
Maybe we can rename this forum to ciscowritesshittysoftwarewhathappenedtotheirQA.com

I think you misspelled bradreese.com.  >:D
LOL

That comment is pure win.

About QA though.. maybe that's part of their problem.  Arista doesn't do QA.  If you think that sounds weird, look up Ken Duda's speech on software quality.
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: wintermute000 on June 15, 2016, 09:52:12 PM
LOL yeah that blog. I just checked it and it seems like he's taken a break and is writing about candy
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: deanwebb on June 16, 2016, 06:26:20 AM
So it would seem... dishing about candy doesn't have the same *edge* as ripping into Cisco, but I bet it's less stressful.
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: icecream-guy on June 22, 2016, 07:37:13 AM
Quote from: deanwebb on June 16, 2016, 06:26:20 AM
So it would seem... dishing about candy doesn't have the same *edge* as ripping into Cisco, but I bet it's less stressful.

Cisco lawyers probably got to him for ripping into Cisco.  Probably got free candy out of the deal instead of hush money and went underground.
this is all conjecture on my part....
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: Netwörkheäd on June 22, 2016, 08:33:59 AM
He actually is related to the guy that invented the peanut butter cup.

Sent from my SM-N900P using Tapatalk

Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: icecream-guy on November 04, 2016, 05:53:56 AM
Quote from: mmcgurty on June 14, 2016, 07:42:49 PM
https://www.cisco.com/c/en/us/support/docs/field-notices/641/fn64144.html

apologies for the epic grave-dig.

Just got notification from our Advanced Service yesterday on this topic.

Timely
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: deanwebb on November 04, 2016, 09:35:34 AM
It's within five months, that's... uh... sheesh, really?

:ckfacepalm:
Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: icecream-guy on November 04, 2016, 11:05:50 AM
really, I just let it drop, I should have publicly shamed him. but I didn't.


Title: Re: Cisco ACS - Only Use Internet Explorer
Post by: deanwebb on November 04, 2016, 11:27:17 AM
Yeah, public shaming just makes them resent your superior knowledge and intellect and makes them plot your demise. Never ends well.