Sie sind auf Seite 1von 19

PG-7609-CR01

PG-7609-CR01#show running-config
Building configuration...
Current configuration : 28863 bytes
!
! Last configuration change at 16:07:32 MYT Thu Sep 9 2010 by smopuri
! NVRAM config last updated at 19:20:20 MYT Fri Sep 3 2010 by ANA-MANAGER
!
configuration mode exclusive auto
version 12.2
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime localtime show-timezone
service timestamps log datetime localtime show-timezone
service password-encryption
service compress-config
service sequence-numbers
service counters max age 5
!
hostname PG-7609-CR01
!
boot-start-marker
boot system sup-bootdisk:c7600rsp72043-advipservicesk9-mz.122-33.SRD3.bin
boot system sup-bootdisk:c7600rsp72043-advipservicesk9-mz.122-33.SRD2.bin
boot-end-marker
!
logging buffered 16384
no logging console
enable secret 5 $1$B1s0$StIdBNZ5Uv0oKIQJjf6RZ/
!
aaa new-model
!
!
aaa group server tacacs+ cisco-acs
server 10.25.48.225
server 10.25.48.228
ip tacacs source-interface Loopback0
!
aaa authentication attempts login 5
aaa authentication login default group cisco-acs local
aaa authentication login vtylogin group cisco-acs local
aaa authentication login consolelogin group cisco-acs local
aaa authorization exec vtyauthor local
aaa accounting exec default stop-only group tacacs+
aaa accounting commands 15 default start-stop group tacacs+
aaa accounting connection default stop-only group tacacs+
aaa accounting system default start-stop group tacacs+
!
!
!
!
!
aaa session-id common
clock timezone MYT 8
ip subnet-zero
no ip source-route
ip routing protocol purge interface
!
!

no ip domain lookup
ip domain name ytlcomms.net
ip name-server 183.78.0.172
!
!
!
!
mls ip multicast flow-stat-timer 9
mls flow ip interface-full
no mls flow ipv6
mls qos
mls cef error action reset
mls cef maximum-routes ip 210
mls cef maximum-routes mpls 30
multilink bundle-name authenticated
mpls traffic-eng tunnels
mpls traffic-eng logging lsp setups
mpls traffic-eng logging tunnel lsp-selection
mpls traffic-eng logging tunnel path change
mpls ldp password required for ldp-neighbors
mpls ldp neighbor 192.168.132.2 password 7 07363540030A1016141D0A1F4E
mpls ldp neighbor 192.168.132.3 password 7 11300D095A11021F07252A3762
mpls ldp neighbor 192.168.132.4 password 7 11300D095A11021F07252A3762
mpls ldp neighbor 192.168.132.5 password 7 07363540030A1016141D0A1F4E
mpls ldp neighbor 192.168.132.6 password 7 063F1B2D014D000A0618131846
mpls ldp neighbor 192.168.128.1 password 7 033D4F074B0C285F4D0618165D
mpls ldp neighbor 192.168.130.1 password 7 152B1F00492922372B3C343159
mpls ldp graceful-restart
mpls ldp session protection
mpls ldp label
allocate global host-routes
mpls ldp advertise-labels for ytl-loopbacks
no mpls ip propagate-ttl forwarded
mpls label protocol ldp
!
!
!
archive
log config
logging enable
notify syslog contenttype plaintext
hidekeys
path disk0:archived-config
maximum 5
write-memory
memory reserve console 4096
spanning-tree mode pvst
spanning-tree extend system-id
diagnostic bootup level minimal
diagnostic cns publish cisco.cns.device.diag_results
diagnostic cns subscribe cisco.cns.device.diag_commands
no errdisable detect cause link-flap
username ANA-MANAGER password 7 13111F1B2A0A0B2B38132732112C460242
username CS-MANAGER password 7 15112439302222252F3C00361B5E1F5B13
username cisco8 password 7 0702284959051C11180709545C6061
!
redundancy
main-cpu
auto-sync running-config
mode sso

!
vlan internal allocation policy ascending
vlan access-log ratelimit 2000
!
ip ftp username cisco
ip ftp password 7 033D4F074B0C285F4D0618165D
ip tcp path-mtu-discovery
ip ssh time-out 60
ip ssh authentication-retries 2
ip ssh source-interface Loopback0
ip ssh version 2
ip scp server enable
!
!
class-map match-any icmp
match access-group name icmp
class-map match-any catch-all
match access-group name catch-all
class-map match-any bad-routing
match access-group name bad-routing
class-map match-any sip-sig
match ip precedence 3
match mpls experimental topmost 3
class-map match-any good-management
match access-group name good-management
class-map match-any good-routing
match access-group name good-routing
class-map match-any realtime-video
match ip precedence 2
match mpls experimental topmost 2
class-map match-any bad-management
match access-group name bad-management
class-map match-any voip-rtp
match ip precedence 5
match mpls experimental topmost 5
class-map match-any control
match ip precedence 6 7
match mpls experimental topmost 6 7
class-map match-any undesirable
match access-group name undesirable
!
policy-map shaper-child
class voip-rtp
priority
police rate percent 40
class sip-sig
bandwidth percent 5
class realtime-video
bandwidth percent 35
class control
bandwidth percent 2
class class-default
random-detect
bandwidth percent 18
policy-map Intercore-link-shaper25M
class class-default
shape average 25000000
service-policy shaper-child
policy-map YTL-COPP
class undesirable

police 32000 1500 1500 conform-action drop exceed-action drop violate-action


drop
class icmp
police 10000000 100000 100000 conform-action transmit exceed-action drop vio
late-action drop
class good-routing
police 10000000 100000 100000 conform-action transmit exceed-action transmit
violate-action transmit
class bad-routing
police 32000 1500 1500 conform-action drop exceed-action drop violate-action
drop
class good-management
police 10000000 100000 100000 conform-action transmit exceed-action drop vio
late-action drop
class bad-management
police 32000 1500 1500 conform-action drop exceed-action drop violate-action
drop
class catch-all
police 80000 8000 8000 conform-action transmit exceed-action drop violate-ac
tion drop
class class-default
police 80000 8000 8000 conform-action transmit exceed-action drop violate-ac
tion drop
policy-map Intercore-link-shaper20M
class class-default
shape average 20000000
service-policy shaper-child
!
!
!
!
!
!
!
interface Tunnel10501
description Primary_PG-7609-CR01_KL-7609-CR01
ip unnumbered Loopback0
mpls ip
tunnel destination 192.168.128.1
tunnel mode mpls traffic-eng
tunnel mpls traffic-eng autoroute announce
tunnel mpls traffic-eng autoroute metric 1
tunnel mpls traffic-eng priority 1 1
tunnel mpls traffic-eng path-option 1 explicit name Primary_PG-7609-CR01_KL-760
9-CR01
tunnel mpls traffic-eng fast-reroute
!
interface Tunnel10503
description Primary_PG-7609-CR01_JB-7609-CR01
ip unnumbered Loopback0
mpls ip
tunnel destination 192.168.130.1
tunnel mode mpls traffic-eng
tunnel mpls traffic-eng autoroute announce
tunnel mpls traffic-eng autoroute metric 1
tunnel mpls traffic-eng priority 1 1
tunnel mpls traffic-eng path-option 1 explicit name Primary_PG-7609-CR01_JB-760
9-CR01
tunnel mpls traffic-eng fast-reroute
!

interface Tunnel20501
description PG-CR01-NHOP1-KL-CR01-Explicit
ip unnumbered Loopback0
mpls ip
tunnel destination 192.168.128.1
tunnel mode mpls traffic-eng
tunnel mpls traffic-eng priority 2 2
tunnel mpls traffic-eng path-option 2 explicit name PG-CR01-NHOP1-KL-CR01
!
interface Tunnel20503
description PG-CR01-NHOP1-JB-CR01-Explicit
ip unnumbered Loopback0
mpls ip
tunnel destination 192.168.130.1
tunnel mode mpls traffic-eng
tunnel mpls traffic-eng priority 2 2
tunnel mpls traffic-eng path-option 2 explicit name PG-CR01-NHOP1-JB-CR01
!
interface Tunnel30501
description PG-CR01-NHOP1-KL-CR01-Dynamic
ip unnumbered Loopback0
mpls ip
tunnel destination 192.168.128.1
tunnel mode mpls traffic-eng
tunnel mpls traffic-eng priority 3 3
tunnel mpls traffic-eng path-option 3 dynamic
!
interface Tunnel30503
description PG-CR01-NHOP1-JB-CR01-Dynamic
ip unnumbered Loopback0
mpls ip
tunnel destination 192.168.130.1
tunnel mode mpls traffic-eng
tunnel mpls traffic-eng priority 3 3
tunnel mpls traffic-eng path-option 3 dynamic
!
interface Loopback0
description for current IGP EGP MBGP use
ip address 192.168.132.1 255.255.255.255
!
interface Loopback1
description for future L2VPN services
ip address 192.168.196.1 255.255.255.255
!
interface TenGigabitEthernet1/1
description to PG-7609-CR02-T1/1
dampening
mtu 9216
ip address 172.22.0.1 255.255.255.252
no ip redirects
no ip proxy-arp
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 7 003D070A495802150C2E4D5D43
ip ospf network point-to-point
ip ospf bfd
load-interval 30
carrier-delay msec 0
mpls traffic-eng tunnels
mpls ip
bfd interval 400 min_rx 400 multiplier 4

ip rsvp bandwidth
ip rsvp signalling hello bfd
!
interface TenGigabitEthernet1/2
no ip address
!
interface TenGigabitEthernet2/1
no ip address
!
interface TenGigabitEthernet2/2
no ip address
!
interface GigabitEthernet3/1
description to PG-7609-RE01-G1/1
dampening
mtu 9216
ip address 172.22.0.13 255.255.255.252
no ip redirects
no ip proxy-arp
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 7 063F1B2D014D000A0618131846
ip ospf network point-to-point
ip ospf bfd
load-interval 30
carrier-delay msec 0
mpls ip
ip rsvp bandwidth
!
interface GigabitEthernet3/2
description to PG-7609-RE02-G1/2
dampening
mtu 9216
ip address 172.22.0.17 255.255.255.252
no ip redirects
no ip proxy-arp
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 7 152B1F00492922372B3C343159
ip ospf network point-to-point
ip ospf bfd
load-interval 30
carrier-delay msec 0
mpls ip
no cdp enable
ip rsvp bandwidth
!
interface GigabitEthernet3/3
description to KL-7609-CR01-G3/3
dampening
mtu 1578
ip address 172.16.0.6 255.255.255.252
no ip redirects
no ip proxy-arp
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 7 10771D1548141B180F0B2B386E
ip ospf network point-to-point
ip ospf bfd
load-interval 30
carrier-delay msec 0
mpls traffic-eng tunnels
mpls traffic-eng backup-path Tunnel20501

mpls traffic-eng backup-path Tunnel30501


mpls ip
bfd interval 400 min_rx 400 multiplier 4
no cdp enable
service-policy output Intercore-link-shaper25M
ip rsvp bandwidth
ip rsvp signalling hello bfd
!
interface GigabitEthernet3/4
description to JB-7609-CR01-G3/3
dampening
mtu 1578
ip address 172.16.0.26 255.255.255.252
no ip redirects
no ip proxy-arp
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 7 133C031E460F0D39282B29207F
ip ospf network point-to-point
ip ospf bfd
load-interval 30
carrier-delay msec 0
mpls traffic-eng tunnels
mpls traffic-eng backup-path Tunnel20503
mpls traffic-eng backup-path Tunnel30503
mpls ip
bfd interval 400 min_rx 400 multiplier 4
no cdp enable
service-policy output Intercore-link-shaper20M
ip rsvp bandwidth
ip rsvp signalling hello bfd
!
interface GigabitEthernet3/5
no ip address
!
interface GigabitEthernet3/6
no ip address
!
interface GigabitEthernet3/7
no ip address
!
interface GigabitEthernet3/8
no ip address
!
interface GigabitEthernet3/9
no ip address
!
interface GigabitEthernet3/10
no ip address
!
interface GigabitEthernet3/11
no ip address
!
interface GigabitEthernet3/12
no ip address
!
interface GigabitEthernet3/13
no ip address
!
interface GigabitEthernet3/14
no ip address

!
interface GigabitEthernet3/15
no ip address
!
interface GigabitEthernet3/16
no ip address
!
interface GigabitEthernet3/17
no ip address
!
interface GigabitEthernet3/18
no ip address
!
interface GigabitEthernet3/19
no ip address
!
interface GigabitEthernet3/20
no ip address
!
interface TenGigabitEthernet4/1
description to PG-6509-CS01-T1/1 (bad link shut by sada)
dampening
mtu 9216
ip address 172.22.0.5 255.255.255.252
no ip redirects
no ip proxy-arp
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 7 063F1B2D014D000A0618131846
ip ospf network point-to-point
ip ospf bfd
load-interval 30
carrier-delay msec 0
shutdown
no mpls ldp igp sync
mpls ip
no cdp enable
ip rsvp bandwidth
!
interface TenGigabitEthernet4/2
no ip address
!
interface TenGigabitEthernet4/3
no ip address
!
interface TenGigabitEthernet4/4
no ip address
!
interface TenGigabitEthernet4/5
no ip address
!
interface TenGigabitEthernet4/6
no ip address
!
interface TenGigabitEthernet4/7
no ip address
!
interface TenGigabitEthernet4/8
no ip address
!
interface GigabitEthernet5/1

no ip address
!
interface GigabitEthernet5/2
no ip address
!
interface GigabitEthernet6/1
no ip address
!
interface GigabitEthernet6/2
no ip address
!
interface TenGigabitEthernet7/1
description to PG-6509-CS02-T2/1
dampening
mtu 9216
ip address 172.22.0.9 255.255.255.252
no ip redirects
no ip proxy-arp
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 7 033D4F074B0C285F4D0618165D
ip ospf network point-to-point
ip ospf bfd
load-interval 30
carrier-delay msec 0
no mpls ldp igp sync
mpls ip
no cdp enable
ip rsvp bandwidth
!
interface TenGigabitEthernet7/2
no ip address
!
interface TenGigabitEthernet7/3
no ip address
shutdown
!
interface TenGigabitEthernet7/4
no ip address
!
interface TenGigabitEthernet7/5
no ip address
!
interface TenGigabitEthernet7/6
no ip address
!
interface TenGigabitEthernet7/7
no ip address
!
interface TenGigabitEthernet7/8
no ip address
!
interface GigabitEthernet8/1
description reserved for Joseph Lee core performance testing (Mike C)
ip address 172.16.15.1 255.255.255.252
speed 1000
duplex full
!
interface GigabitEthernet8/2
no ip address
!

interface GigabitEthernet8/3
no ip address
!
interface GigabitEthernet8/4
no ip address
!
interface GigabitEthernet8/5
no ip address
!
interface GigabitEthernet8/6
no ip address
!
interface GigabitEthernet8/7
no ip address
!
interface GigabitEthernet8/8
no ip address
!
interface GigabitEthernet8/9
no ip address
!
interface GigabitEthernet8/10
no ip address
!
interface GigabitEthernet8/11
no ip address
!
interface GigabitEthernet8/12
no ip address
!
interface GigabitEthernet8/13
no ip address
!
interface GigabitEthernet8/14
no ip address
!
interface GigabitEthernet8/15
no ip address
!
interface GigabitEthernet8/16
no ip address
!
interface GigabitEthernet8/17
no ip address
!
interface GigabitEthernet8/18
no ip address
!
interface GigabitEthernet8/19
no ip address
!
interface GigabitEthernet8/20
no ip address
!
interface GigabitEthernet8/21
no ip address
!
interface GigabitEthernet8/22
no ip address
!

interface GigabitEthernet8/23
no ip address
!
interface GigabitEthernet8/24
no ip address
!
interface GigabitEthernet8/25
no ip address
!
interface GigabitEthernet8/26
no ip address
!
interface GigabitEthernet8/27
no ip address
!
interface GigabitEthernet8/28
no ip address
!
interface GigabitEthernet8/29
no ip address
!
interface GigabitEthernet8/30
no ip address
!
interface GigabitEthernet8/31
no ip address
!
interface GigabitEthernet8/32
no ip address
!
interface GigabitEthernet8/33
no ip address
!
interface GigabitEthernet8/34
no ip address
!
interface GigabitEthernet8/35
no ip address
!
interface GigabitEthernet8/36
no ip address
!
interface GigabitEthernet8/37
no ip address
!
interface GigabitEthernet8/38
no ip address
!
interface GigabitEthernet8/39
no ip address
!
interface GigabitEthernet8/40
no ip address
!
interface GigabitEthernet8/41
no ip address
!
interface GigabitEthernet8/42
no ip address
!

interface GigabitEthernet8/43
no ip address
!
interface GigabitEthernet8/44
no ip address
!
interface GigabitEthernet8/45
no ip address
!
interface GigabitEthernet8/46
no ip address
!
interface GigabitEthernet8/47
no ip address
!
interface GigabitEthernet8/48
no ip address
!
interface Vlan1
no ip address
shutdown
!
router ospf 1
router-id 192.168.132.1
ispf
log-adjacency-changes
auto-cost reference-bandwidth 40000
nsf ietf
area 0 authentication message-digest
timers throttle spf 50 50 5000
timers throttle lsa 0 20 5000
timers lsa arrival 15
timers pacing flood 15
passive-interface Loopback0
passive-interface Loopback1
network 172.16.0.4 0.0.0.3 area 0
network 172.16.0.24 0.0.0.3 area 0
network 172.22.0.0 0.0.0.3 area 0
network 172.22.0.4 0.0.0.3 area 0
network 172.22.0.8 0.0.0.3 area 0
network 172.22.0.12 0.0.0.3 area 0
network 172.22.0.16 0.0.0.3 area 0
network 192.168.132.1 0.0.0.0 area 0
mpls traffic-eng router-id Loopback0
mpls traffic-eng area 0
!
router bgp 45960
bgp router-id 192.168.132.1
no bgp default ipv4-unicast
no bgp default route-target filter
bgp cluster-id 56
bgp log-neighbor-changes
bgp graceful-restart restart-time 120
bgp graceful-restart stalepath-time 360
bgp graceful-restart
neighbor RR peer-group
neighbor RR remote-as 45960
neighbor RR password 7 10771D1548141B180F0B2B386E
neighbor RR update-source Loopback0
neighbor RR fall-over

neighbor CS-SW peer-group


neighbor CS-SW remote-as 45960
neighbor CS-SW password 7 003D070A495802150C2E4D5D43
neighbor CS-SW update-source Loopback0
neighbor RE peer-group
neighbor RE remote-as 45960
neighbor RE password 7 063F1B2D014D000A0618131846
neighbor RE update-source Loopback0
neighbor L3AGG peer-group
neighbor L3AGG remote-as 45960
neighbor L3AGG password 7 023F1057460506324F41080A4F
neighbor L3AGG update-source Loopback0
neighbor IGW peer-group
neighbor IGW remote-as 45960
neighbor IGW password 7 09755A0554061E010803053961
neighbor IGW update-source Loopback0
neighbor AC-SW peer-group
neighbor AC-SW remote-as 45960
neighbor 192.168.128.1 peer-group RR
neighbor 192.168.128.1 fall-over
neighbor 192.168.130.1 peer-group RR
neighbor 192.168.130.1 fall-over
neighbor 192.168.132.2 peer-group RR
neighbor 192.168.132.2 fall-over
neighbor 192.168.132.3 peer-group RE
neighbor 192.168.132.4 peer-group RE
neighbor 192.168.132.5 peer-group CS-SW
neighbor 192.168.132.6 peer-group CS-SW
neighbor 192.168.132.9 peer-group IGW
neighbor 192.168.132.10 peer-group IGW
neighbor 192.168.166.1 peer-group L3AGG
neighbor 192.168.166.2 peer-group L3AGG
neighbor 192.168.166.3 peer-group L3AGG
neighbor 192.168.166.4 peer-group L3AGG
neighbor 192.168.166.5 peer-group L3AGG
neighbor 192.168.166.6 peer-group L3AGG
neighbor 192.168.167.1 peer-group L3AGG
neighbor 192.168.167.2 peer-group L3AGG
neighbor 192.168.167.3 peer-group L3AGG
neighbor 192.168.167.4 peer-group L3AGG
neighbor 192.168.167.5 peer-group L3AGG
neighbor 192.168.167.6 peer-group L3AGG
neighbor 192.168.167.7 peer-group L3AGG
neighbor 192.168.167.8 peer-group L3AGG
neighbor 192.168.167.9 peer-group L3AGG
neighbor 192.168.168.1 peer-group L3AGG
neighbor 192.168.168.2 peer-group L3AGG
!
address-family ipv4
no synchronization
neighbor RR send-community
neighbor CS-SW send-community
neighbor CS-SW route-reflector-client
neighbor CS-SW default-originate
neighbor CS-SW route-map default-only out
neighbor RE send-community
neighbor RE route-reflector-client
neighbor RE default-originate
neighbor RE route-map default-only out
neighbor IGW send-community

neighbor IGW route-reflector-client


neighbor 192.168.128.1 activate
neighbor 192.168.130.1 activate
neighbor 192.168.132.2 activate
neighbor 192.168.132.3 activate
neighbor 192.168.132.4 activate
neighbor 192.168.132.5 activate
neighbor 192.168.132.6 activate
neighbor 192.168.132.9 activate
neighbor 192.168.132.10 activate
no auto-summary
exit-address-family
!
address-family vpnv4
neighbor RR send-community extended
neighbor CS-SW send-community both
neighbor CS-SW route-reflector-client
neighbor RE send-community both
neighbor RE route-reflector-client
neighbor L3AGG send-community both
neighbor L3AGG route-reflector-client
neighbor AC-SW send-community both
neighbor AC-SW route-reflector-client
neighbor 192.168.128.1 activate
neighbor 192.168.130.1 activate
neighbor 192.168.132.2 activate
neighbor 192.168.132.3 activate
neighbor 192.168.132.4 activate
neighbor 192.168.132.5 activate
neighbor 192.168.132.6 activate
neighbor 192.168.166.1 activate
neighbor 192.168.166.2 activate
neighbor 192.168.166.3 activate
neighbor 192.168.166.4 activate
neighbor 192.168.166.5 activate
neighbor 192.168.166.6 activate
neighbor 192.168.167.1 activate
neighbor 192.168.167.2 activate
neighbor 192.168.167.3 activate
neighbor 192.168.167.4 activate
neighbor 192.168.167.5 activate
neighbor 192.168.167.6 activate
neighbor 192.168.167.7 activate
neighbor 192.168.167.8 activate
neighbor 192.168.167.9 activate
neighbor 192.168.168.1 activate
neighbor 192.168.168.2 activate
exit-address-family
!
ip classless
ip route 192.0.2.1 255.255.255.255 Null0
!
no ip http server
no ip http secure-server
ip rsvp signalling hello bfd
ip tacacs source-interface Loopback0
!
ip explicit-path name Primary_PG-7609-CR01_KL-7609-CR01 enable
next-address 172.16.0.5
!

ip explicit-path name PG-CR01-NHOP1-KL-CR01 enable


next-address 172.22.0.2
next-address 172.16.0.17
next-address 172.20.0.1
!
ip explicit-path name Primary_PG-7609-CR01_JB-7609-CR01 enable
next-address 172.16.0.25
!
ip explicit-path name PG-CR01-NHOP1-JB-CR01 enable
next-address 172.22.0.2
next-address 172.16.0.29
next-address 172.21.0.1
!
ip access-list standard ldp-neighbors
permit 192.168.0.0 0.0.255.255
ip access-list standard vty-acl
permit 10.25.89.240
permit 192.168.0.0 0.0.255.255
permit 10.25.16.0 0.0.15.255
permit 10.24.9.0 0.0.0.255
permit 10.24.7.0 0.0.0.255
permit 10.24.12.0 0.0.0.255
permit 10.24.26.0 0.0.0.255
permit 10.99.3.0 0.0.0.255
ip access-list standard ytl-loopbacks
permit 192.168.0.0 0.0.255.255
ip access-list standard ytl-pnoc
permit 10.25.16.0 0.0.7.255
!
ip access-list extended bad-management
permit tcp any any eq 22
permit tcp any any eq telnet
permit tcp any any eq 443
permit tcp any any eq ftp
permit tcp any any eq ftp-data
permit tcp any any eq 69
permit tcp any any eq domain
permit tcp any any eq tacacs
permit udp any any eq snmp
permit udp any any eq snmptrap
permit udp any any eq ntp
permit udp any any eq syslog
permit udp any any eq 1645
permit udp any any eq 1646
permit udp any any eq 1812
permit udp any any eq 1813
ip access-list extended bad-routing
permit ospf any any
ip access-list extended catch-all
permit ip any any
ip access-list extended good-management
remark pnoc 10.25.16.0/20
remark DNS/NTP 10.25.80.0/21
remark AAA 10.25.48.0/20
remark ip core blocks
permit tcp any host 192.168.132.1 eq 443
permit tcp any host 192.168.132.1 eq 22
permit udp any host 192.168.132.1 eq ntp
permit udp any eq ntp host 192.168.132.1
permit tcp 10.25.16.0 0.0.15.255 host 192.168.132.1 established

permit tcp 10.25.16.0 0.0.15.255 host 192.168.132.1 eq ftp


permit tcp 10.25.16.0 0.0.15.255 host 192.168.132.1 eq ftp-data
permit udp 10.25.16.0 0.0.15.255 host 192.168.132.1 eq snmp
permit udp 10.25.16.0 0.0.15.255 host 192.168.132.1 eq snmptrap
permit udp 10.25.16.0 0.0.15.255 host 192.168.132.1 eq syslog
permit tcp 10.25.16.0 0.0.15.255 host 192.168.132.1 eq 69
permit udp 10.25.80.0 0.0.7.255 eq domain host 192.168.132.1
permit tcp 10.25.80.0 0.0.7.255 eq domain host 192.168.132.1
permit udp 10.25.48.0 0.0.15.255 host 192.168.132.1 eq 1645
permit udp 10.25.48.0 0.0.15.255 host 192.168.132.1 eq 1646
permit udp 10.25.48.0 0.0.15.255 host 192.168.132.1 eq 1812
permit udp 10.25.48.0 0.0.15.255 host 192.168.132.1 eq 1813
permit udp 10.25.48.0 0.0.15.255 host 192.168.132.1 eq tacacs
permit udp 10.25.48.0 0.0.15.255 eq tacacs host 192.168.132.1
ip access-list extended good-routing
remark critical inbound routing traffic
remark ospf
permit ospf host 172.16.0.5 any
permit ospf host 172.22.0.2 any
permit ospf host 172.22.0.6 any
permit ospf host 172.22.0.10 any
permit ospf host 172.22.0.14 any
permit ospf host 172.22.0.18 any
permit ospf host 172.16.0.25 any
permit ospf any host 224.0.0.5
permit ospf any host 224.0.0.6
remark BGP
permit tcp any any eq bgp
permit tcp any eq bgp any
remark LDP:TCP source=host (higher-ip) any dst=host(lower-ip) 646
permit udp any any eq 646
permit udp any eq 646 any
permit tcp any any eq 646
permit tcp any eq 646 any
remark HSRP
permit udp any host 224.0.0.2 eq 1985
remark BFD
permit udp any any eq 3784
ip access-list extended icmp
permit icmp any any ttl-exceeded
permit icmp any any port-unreachable
permit icmp any any host-unreachable
permit icmp any any echo
permit icmp any any echo-reply
permit icmp any any packet-too-big
ip access-list extended undesirable
permit udp any any fragments
permit tcp any any fragments
permit icmp any any fragments
permit udp any any eq 1434
!
logging trap notifications
logging source-interface Loopback0
logging 10.25.89.240
access-list 1 permit 0.0.0.0
!
route-map default-only permit 10
match ip address 1
set local-preference 200
!

snmp-server community hoeyoustoexlQe3a RO ytl-pnoc


snmp-server community bousiabluphi3Pur RW ytl-pnoc
snmp-server trap-source Loopback0
snmp-server enable traps snmp authentication linkdown linkup coldstart warmstart
snmp-server enable traps eigrp
snmp-server enable traps tty
snmp-server enable traps ospf state-change
snmp-server enable traps ospf errors
snmp-server enable traps ospf retransmit
snmp-server enable traps ospf lsa
snmp-server enable traps ospf cisco-specific state-change nssa-trans-change
snmp-server enable traps ospf cisco-specific state-change shamlink interface-old
snmp-server enable traps ospf cisco-specific state-change shamlink neighbor
snmp-server enable traps ospf cisco-specific errors
snmp-server enable traps ospf cisco-specific retransmit
snmp-server enable traps ospf cisco-specific lsa
snmp-server enable traps bgp
snmp-server enable traps bulkstat collection transfer
snmp-server enable traps dhcp
snmp-server enable traps event-manager
snmp-server enable traps frame-relay multilink bundle-mismatch
snmp-server enable traps frame-relay
snmp-server enable traps frame-relay subif
snmp-server enable traps hsrp
snmp-server enable traps ipmulticast
snmp-server enable traps isis
snmp-server enable traps msdp
snmp-server enable traps pim neighbor-change rp-mapping-change invalid-pim-messa
ge
snmp-server enable traps rtr
snmp-server enable traps cef resource-failure peer-state-change peer-fib-state-c
hange inconsistency
snmp-server enable traps ethernet cfm cc mep-up mep-down cross-connect loop conf
ig
snmp-server enable traps ethernet cfm crosscheck mep-missing mep-unknown service
-up
snmp-server enable traps cpu threshold
snmp-server enable traps rsvp
snmp-server enable traps mvpn
snmp-server enable traps mpls traffic-eng
snmp-server enable traps mpls fast-reroute protected
snmp-server enable traps mpls rfc ldp
snmp-server enable traps mpls ldp
snmp-server enable traps pw vc
snmp-server enable traps l2tun session
snmp-server enable traps l2tun pseudowire status
snmp-server enable traps mpls rfc vpn
snmp-server enable traps mpls vpn
snmp-server host 10.25.16.87 version 2c wRlucrlekianCA9u
!
tacacs-server host 10.25.48.225 key 7 070C285F4D06485744
tacacs-server host 10.25.48.228 key 7 121A0C0411045D5679
tacacs-server key 7 033D4F074B0C285F4D0618165D
mpls ldp router-id Loopback0 force
!
control-plane
service-policy input YTL-COPP
!
banner motd ^CC
================================================================================

========
Unauthorised access and/or misuse of the systems is prohibited and a serious
offence under Malaysia laws.Disconnect immediately if you are not an authorized
user!
================================================================================
========
^C
alias exec shr sh run
alias exec kk conf t
alias exec sum sh ip bgp sum
alias exec ship sh ip route
alias exec shop sh ip ospf neighbor
alias exec shib sh ip int brief
alias exec shb sh run | b router bgp
alias exec sb sh run | b router bgp
alias exec so sh run | b router ospf
alias exec sumv sh ip bgp vpnv4 all sum
alias exec shrb sh run | begin
!
line con 0
exec-timeout 15 0
privilege level 15
password 7 070C285F4D06
logging synchronous
login authentication consolelogin
stopbits 1
line vty 0 4
access-class vty-acl in
exec-timeout 15 0
password 7 070C285F4D06
logging synchronous
login authentication vtylogin
transport input ssh
line vty 5 15
access-class vty-acl in
exec-timeout 15 0
logging synchronous
login authentication vtylogin
transport input ssh
line vty 16
access-class vty-acl in
exec-timeout 0 0
logging synchronous
login authentication vtylogin
rotary 10
transport input ssh
!
exception crashinfo buffersize 80
ntp logging
ntp authentication-key 1 md5 033D4F074B0C285F4D0618165D 7
ntp authentication-key 2 md5 10175C315D40225954 7
ntp authenticate
ntp trusted-key 1
ntp trusted-key 2
ntp clock-period 17179899
ntp source Loopback0
ntp peer 192.168.132.5 key 1
ntp peer 192.168.128.2 key 1
ntp peer 192.168.132.6 key 1
ntp peer 192.168.128.5 key 1

ntp
ntp
ntp
ntp
!
end

peer 192.168.128.6
peer 192.168.132.2
server 10.25.80.12
server 10.25.80.15

key
key
key
key

1
1
2 prefer
2 prefer

Das könnte Ihnen auch gefallen