Sie sind auf Seite 1von 6

rPUCPTeologia_PLibre#show run

Building configuration...

Current configuration : 4553 bytes


!
version 15.0
no service pad
service timestamps debug datetime localtime
service timestamps log datetime localtime
service password-encryption
!
hostname rPUCPTeologia_PLibre
!
boot-start-marker
boot-end-marker
!
logging buffered 9000
enable secret 5 $1$..ia$x0xcbFBSIvtZ32/mbpZ5L.
!
aaa new-model
!
!
aaa authentication login default group tacacs+ enable
aaa authentication enable default group tacacs+ enable
aaa authorization commands 1 default group tacacs+ none
aaa authorization commands 1 group group tacacs+ none
aaa authorization commands 15 default group tacacs+ none
aaa authorization commands 15 group group tacacs+ none
aaa accounting exec default
action-type start-stop
group tacacs+
!
aaa accounting commands 1 default
action-type start-stop
group tacacs+
!
aaa accounting commands 15 default
action-type start-stop
group tacacs+
!
aaa accounting network default
action-type start-stop
group tacacs+
!
aaa accounting connection default
action-type start-stop
group tacacs+
!
!
!
!
!
!
aaa session-id common
!
!
!
memory-size iomem 10
clock timezone GMT -5
!
!
no ip source-route
!
!
ip vrf 100
description VPN Servicio Troncal SIP
rd 12252:100
route-target export 12252:100
route-target import 12252:100
!
!
!
ip cef
no ip bootp server
ip name-server 200.62.191.11
ip name-server 200.24.191.11
ip name-server 200.62.191.12
ip name-server 200.24.191.12
no ipv6 cef
!
!
multilink bundle-name authenticated
license udi pid CISCO881-SEC-K9 sn FTX16458082
!
!
!
!
!
class-map match-any qos5_TRUNK_SIP
match ip dscp cs5
class-map match-any P5_TRUNK_SIP
match ip dscp cs5
match access-group name qos5_TRUNK_SIP
!
!
policy-map SetDscpLan_TRUNK_SIP
class P5_TRUNK_SIP
set ip dscp cs5
class class-default
set ip dscp cs5
policy-map wan_TRUNK_SIP
class qos5_TRUNK_SIP
priority 4096
police 4096000 768000 1536000 conform-action transmit exceed-action drop
violate-action drop
class class-default
fair-queue
policy-map Shape4096_TRUNK_SIP
class class-default
shape average 4097000
service-policy wan_TRUNK_SIP
!
!
!
!
!
!
!
!
interface FastEthernet0
!
!
interface FastEthernet1
!
!
interface FastEthernet2
!
!
interface FastEthernet3
description conexion a CENTRAL SIP
switchport access vlan 100
load-interval 30
!
!
interface FastEthernet4
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
load-interval 30
duplex full
speed 100
!
!
interface FastEthernet4.10
description Enlace WAN Internet Corporativo 30 Mbps CID: 5823374
encapsulation dot1Q 501
ip address 190.116.153.182 255.255.255.240
rate-limit input 33792000 6336000 12672000 conform-action transmit exceed-action
drop
rate-limit output 33792000 6336000 12672000 conform-action transmit exceed-action
drop
!
interface FastEthernet4.20
description ENLACE WAN | TRONCAL SIP - Telefonia Fija | CID:6496094 |
encapsulation dot1Q 790
ip vrf forwarding 100
ip address 10.17.2.250 255.255.255.252
no ip redirects
no ip unreachables
no ip proxy-arp
service-policy output Shape4096_TRUNK_SIP
!
interface Vlan1
description Enlace LAN cliente Facultad de Teologia Pueblo Libre
ip address 190.116.28.113 255.255.255.248
no ip redirects
no ip unreachables
no ip proxy-arp
load-interval 30
!
!
interface Vlan20
ip address 172.16.0.1 255.255.255.0
shutdown
!
!
interface Vlan100
description Enlace LAN | TRONCAL SIP - Telefonia Fija |
ip vrf forwarding 100
ip address 192.168.10.1 255.255.255.0 secondary
ip address 172.28.137.49 255.255.255.252
no ip redirects
no ip unreachables
no ip proxy-arp
load-interval 30
no autostate
!
service-policy input SetDscpLan_TRUNK_SIP
!
ip forward-protocol nd
no ip http server
no ip http secure-server
!
!
ip route 0.0.0.0 0.0.0.0 190.116.153.177
ip route vrf 100 0.0.0.0 0.0.0.0 10.17.2.249
!
ip access-list extended qos5_TRUNK_SIP
permit ip 172.28.137.48 0.0.0.3 any
!
access-list 25 permit 200.14.241.34
access-list 25 permit 200.14.241.43
access-list 25 permit 190.116.153.177
!
!
!
!
tacacs-server host 200.14.241.43
tacacs-server host 200.14.241.30
tacacs-server key 7 0827584D045F16121144
!
control-plane
!
!
banner motd ^C DANGER!!!!!!..PROTECTED SYSTEM!!!!!
You have accessed a restricted device. Use of this device without authorization or
for purposes for which authorization has not been extended is prohibited. Log off
immediately.^C
!
line con 0
password 7 06100E2D0A45100B1C
no modem enable
line aux 0
line vty 0 4
session-timeout 10 output
access-class 25 in
password 7 044D0A0A492A555C10
!
scheduler max-task-time 5000
end

rPUCPTeologia_PLibre#$

......
......

!
interface FastEthernet4.10
description Enlace WAN Internet Corporativo 30 Mbps CID: 5823374
encapsulation dot1Q 4047
ip address 10.31.153.163 255.255.255.240
rate-limit input 35840000 6720000 13440000 conform-action transmit exceed-action
drop
rate-limit output 35840000 6720000 13440000 conform-action transmit exceed-action
drop
!
!
router bgp 64516
bgp router-id 10.31.153.163
bgp log-neighbor-changes
no bgp default ipv4-unicast
neighbor WAN_PRINCIPAL peer-group
neighbor WAN_PRINCIPAL remote-as 12252
neighbor WAN_PRINCIPAL password 7 02150B5F0E45496403
neighbor WAN_PRINCIPAL timers 10 30

neighbor iBGP_LAN_CLARO peer-group


neighbor iBGP_LAN_CLARO remote-as 64517
neighbor iBGP_LAN_CLARO password 7 14041D0F09476C6E6B
neighbor iBGP_LAN_CLARO timers 10 30

neighbor 10.31.153.161 peer-group WAN_PRINCIPAL


neighbor 10.31.153.161 description Enlace WAN Internet Principal

neighbor 190.119.129.51 peer-group iBGP_LAN_CLARO


neighbor 190.119.129.51 description Enlace LAN hacia router Contingencia
!
address-family ipv4
network 190.116.28.112 mask 255.255.255.248
neighbor WAN_PRINCIPAL send-community both
neighbor WAN_PRINCIPAL soft-reconfiguration inbound
neighbor WAN_PRINCIPAL route-map From_VPN_INTERNET in
neighbor WAN_PRINCIPAL route-map SET_INTERNET_COMM out

neighbor iBGP_LAN_CLARO send-community both


neighbor iBGP_LAN_CLARO next-hop-self
neighbor iBGP_LAN_CLARO soft-reconfiguration inbound

neighbor 10.31.153.161 activate

neighbor 190.119.129.51 activate


exit-address-family
!
ip forward-protocol nd
no ip http server
no ip http secure-server
ip tftp source-interface GigabitEthernet0
!
ip bgp-community new-format
!
!
ip prefix-list DG seq 10 permit 0.0.0.0/0
!
ip prefix-list LAN_INTERNET seq 10 permit 190.119.129.48/29
access-list 25 permit 200.14.241.43
access-list 25 permit 10.31.153.161
!
route-map SET_INTERNET_COMM permit 10
description SETEAR LA COMUNIDAD 1200
match ip address prefix-list LAN_INTERNET
set community 12252:1200
!
route-map From_VPN_INTERNET permit 10
description PERMITIR red Default
match ip address prefix-list DG
!
.......
.......

!
router bgp 64516
bgp router-id 10.31.153.163
bgp log-neighbor-changes
no bgp default ipv4-unicast
neighbor WAN_PRINCIPAL peer-group
neighbor WAN_PRINCIPAL remote-as 12252
neighbor WAN_PRINCIPAL password 0
neighbor WAN_PRINCIPAL timers 10 30
neighbor 10.31.153.161 peer-group WAN_PRINCIPAL
neighbor 10.31.153.161 description Enlace WAN Internet Principal
!
address-family ipv4
network 190.116.28.112 mask 255.255.255.248
neighbor WAN_PRINCIPAL send-community both
neighbor WAN_PRINCIPAL soft-reconfiguration inbound
neighbor WAN_PRINCIPAL route-map From_VPN_INTERNET in
neighbor WAN_PRINCIPAL route-map SET_INTERNET_COMM out
neighbor 10.31.153.161 activate
exit-address-family
!
!