ansible/backup/files/cisco/IZH-MLK-IZM-SW-1-2.txt

628 lines
10 KiB
Plaintext
Raw Permalink Normal View History

2025-10-31 08:47:26 +04:00
Building configuration...
Current configuration : 10734 bytes
!
! Last configuration change at 21:27:26 MSK Fri Jun 24 2022 by akhmetzyanovrr_adm
! NVRAM config last updated at 21:28:54 MSK Fri Jun 24 2022 by akhmetzyanovrr_adm
!
version 15.0
no service pad
service timestamps debug datetime msec localtime show-timezone year
service timestamps log datetime msec localtime show-timezone year
no service password-encryption
!
hostname IZH-MLK-IZM-SW-1-2
!
boot-start-marker
boot-end-marker
!
logging userinfo
logging buffered 128000
enable secret 5 $1$8Ye.$2052cyes0PP1QlT7T0Qcu0
!
username root privilege 15 secret 5 $1$HLqM$tdwAkQGuE3HAs7XnKDg4O1
username netadmin privilege 15 secret 5 $1$tJvO$MSgnDj5VPBpeZapA1Uz4m/
aaa new-model
!
!
aaa group server radius NPS
server name IZH-RDS002
server name P11-RDS003
ip radius source-interface Vlan300
load-balance method least-outstanding
!
aaa authentication login default group NPS local enable
aaa authentication login CONSOLE local group NPS
aaa authorization console
aaa authorization exec default group NPS local if-authenticated
!
!
!
!
!
!
aaa session-id common
clock timezone MSK 4 0
switch 1 provision ws-c3750x-48
switch 2 provision ws-c3750x-48
system mtu routing 9100
no ip source-route
no ip gratuitous-arps
!
!
no ip domain-lookup
ip domain-name milkom-komos.ru
ip host tftp 10.4.0.214
ip name-server 192.168.8.200
ip name-server 192.168.8.201
login on-failure log
login on-success log
vtp mode off
!
!
!
license boot level ipservices
license boot level ipservices switch 1
archive
log config
logging enable
logging size 900
notify syslog contenttype plaintext
hidekeys
path tftp://tftp/IZH/3750/$H
write-memory
time-period 10080
!
!
!
!
spanning-tree mode pvst
spanning-tree logging
spanning-tree extend system-id
spanning-tree vlan 1-4094 priority 8192
!
!
!
!
!
!
!
!
!
vlan internal allocation policy ascending
!
vlan 8
name --UserNet_8.0/24--
!
vlan 9
name --UserNet_9.0/24--
!
vlan 10
name --UserNet_10.0/24--
!
vlan 11
name --UserNet_11.0/24--
!
vlan 12
name --UserNet_12.0/24--
!
vlan 13
name --UserNet_13.0/24--
!
vlan 14
name --UserNet_14.0/24--
!
vlan 15
name --UserNet_15.0/24--
!
vlan 16
name --UserNet_16.0/24--
!
vlan 17
name --UserNet_17.0/24--
!
vlan 18
name --UserNet_18.0/24--
!
vlan 19
name --UserNet_19.0/24--
!
vlan 20
name --UserNet_20.0/24--
!
vlan 21
name swVlan21_Management
!
vlan 50
name RCOD
!
vlan 93
name VideoNetToStolovaya
!
vlan 96
name --ERTELEKOM--
!
vlan 99
name --MARK_ASTERISK--
!
vlan 100
mtu 9000
!
vlan 101
name --PRINTERS--
!
vlan 113
name TRANSIT_TO_MIKROTIK
!
vlan 150
name --Wi-Fi_Users_32.0/24--
!
vlan 151
name --Wi-Fi_Prod_33.0/24--
!
vlan 172
name TelephotiNet
!
vlan 173
name telephonyTest
!
vlan 200-201
!
vlan 202
name --DMZ--
!
vlan 229
!
vlan 248
name --SANDBOX_ELAR--
!
vlan 249
name --ServTestC_36.0/24--
!
vlan 250
name --ServerNet_0.0/24--
!
vlan 251
name -=ServMail_7.0/28=-
!
vlan 252
name --VOICE_ATS--
!
vlan 289
name -=SRVBakNet_245.0_24=-
!
vlan 290
name -=SrvVmwVMon_242.0/26=-
!
vlan 291
name -=SrvVmwVSan_242.64/26=-
!
vlan 292
name -=SrvBakNet_243.0/24=-
!
vlan 294
name --SRV_iLO_iDrack_etc--
!
vlan 299
name --SrvMng_240.0\24--
!
vlan 300
name --MANAGMENT--
!
vlan 301
name --Wi-Fi_MANAGMENT--
!
vlan 302
name -=Wi-Fi_MANAGMENT=-
!
vlan 350
name --VOICE_28.0/24--
!
vlan 500
name --Wi-Fi_Guest_35.0/24--
!
vlan 550
name --CISCO_ASA--
!
vlan 551
name --TRANSIT_HSRP--
!
vlan 597
name TRANSIT_TO_ISR4431
!
vlan 599
name --MTS_KOMOS_599--
!
vlan 601
name --KMK_PRODACTION--
!
vlan 650
name --ISCSI--
!
vlan 666
name NOT_ROUTED
!
vlan 1000
name --ELAR-TEST--
!
vlan 4030
name --MTS_KOMOS_4030--
!
vlan 4031
name -VeamRepl_172.31.31.0/24-
!
vlan 4032
name -SQLRepl_172.31.33.0/24-
!
vlan 4033
name -SrvVCHA_172.31.33.0/24-
!
vlan 4034
name -ExchRepl_172.31.34.0/24-
!
vlan 4035
name -SrvVCMg_172.31.35.0/24-
!
ip ssh authentication-retries 2
!
!
!
!
!
!
!
!
!
!
interface Port-channel1
description [CORE] SW-1-1
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet0
no ip address
shutdown
!
interface GigabitEthernet1/0/1
description [SRV] bkp008_eth1
switchport access vlan 292
switchport mode access
!
interface GigabitEthernet1/0/2
description [SRV] bkp008_eth3
switchport access vlan 289
switchport mode access
!
interface GigabitEthernet1/0/3
!
interface GigabitEthernet1/0/4
!
interface GigabitEthernet1/0/5
!
interface GigabitEthernet1/0/6
!
interface GigabitEthernet1/0/7
!
interface GigabitEthernet1/0/8
!
interface GigabitEthernet1/0/9
!
interface GigabitEthernet1/0/10
!
interface GigabitEthernet1/0/11
!
interface GigabitEthernet1/0/12
!
interface GigabitEthernet1/0/13
!
interface GigabitEthernet1/0/14
!
interface GigabitEthernet1/0/15
!
interface GigabitEthernet1/0/16
!
interface GigabitEthernet1/0/17
!
interface GigabitEthernet1/0/18
!
interface GigabitEthernet1/0/19
!
interface GigabitEthernet1/0/20
!
interface GigabitEthernet1/0/21
!
interface GigabitEthernet1/0/22
!
interface GigabitEthernet1/0/23
!
interface GigabitEthernet1/0/24
!
interface GigabitEthernet1/0/25
!
interface GigabitEthernet1/0/26
!
interface GigabitEthernet1/0/27
!
interface GigabitEthernet1/0/28
!
interface GigabitEthernet1/0/29
!
interface GigabitEthernet1/0/30
!
interface GigabitEthernet1/0/31
!
interface GigabitEthernet1/0/32
!
interface GigabitEthernet1/0/33
!
interface GigabitEthernet1/0/34
!
interface GigabitEthernet1/0/35
!
interface GigabitEthernet1/0/36
!
interface GigabitEthernet1/0/37
!
interface GigabitEthernet1/0/38
!
interface GigabitEthernet1/0/39
!
interface GigabitEthernet1/0/40
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet1/0/41
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet1/0/42
description SHD003_MNGT
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/0/43
description SHD004_MNGT
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/0/44
description SHD007_MNGT
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/0/45
description [SRV] VMW022_ILO
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/0/46
description [SRV] VMW023_ILO
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/0/47
description [SRV] VMW026_ILO
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/0/48
description ILO
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/1/1
!
interface GigabitEthernet1/1/2
!
interface GigabitEthernet1/1/3
!
interface GigabitEthernet1/1/4
!
interface TenGigabitEthernet1/1/1
description [CORE] SW-1-1
switchport trunk encapsulation dot1q
switchport mode trunk
channel-group 1 mode active
!
interface TenGigabitEthernet1/1/2
!
interface GigabitEthernet2/0/1
description [SRV] bkp008_eth2
switchport access vlan 250
switchport mode access
!
interface GigabitEthernet2/0/2
!
interface GigabitEthernet2/0/3
!
interface GigabitEthernet2/0/4
!
interface GigabitEthernet2/0/5
!
interface GigabitEthernet2/0/6
!
interface GigabitEthernet2/0/7
!
interface GigabitEthernet2/0/8
!
interface GigabitEthernet2/0/9
!
interface GigabitEthernet2/0/10
!
interface GigabitEthernet2/0/11
!
interface GigabitEthernet2/0/12
!
interface GigabitEthernet2/0/13
!
interface GigabitEthernet2/0/14
!
interface GigabitEthernet2/0/15
!
interface GigabitEthernet2/0/16
!
interface GigabitEthernet2/0/17
!
interface GigabitEthernet2/0/18
!
interface GigabitEthernet2/0/19
!
interface GigabitEthernet2/0/20
!
interface GigabitEthernet2/0/21
!
interface GigabitEthernet2/0/22
!
interface GigabitEthernet2/0/23
!
interface GigabitEthernet2/0/24
!
interface GigabitEthernet2/0/25
!
interface GigabitEthernet2/0/26
!
interface GigabitEthernet2/0/27
!
interface GigabitEthernet2/0/28
!
interface GigabitEthernet2/0/29
!
interface GigabitEthernet2/0/30
!
interface GigabitEthernet2/0/31
!
interface GigabitEthernet2/0/32
!
interface GigabitEthernet2/0/33
!
interface GigabitEthernet2/0/34
!
interface GigabitEthernet2/0/35
!
interface GigabitEthernet2/0/36
!
interface GigabitEthernet2/0/37
!
interface GigabitEthernet2/0/38
!
interface GigabitEthernet2/0/39
!
interface GigabitEthernet2/0/40
!
interface GigabitEthernet2/0/41
description [SRV] bkp008-idr
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet2/0/42
description SHD003_MNGT
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet2/0/43
description SHD004_MNGT
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet2/0/44
description SHD007_MNGT
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet2/0/45
description [SRV] VMW024_ILO
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet2/0/46
description [SRV] VMW025_ILO
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet2/0/47
description [SRV] VMW027_ILO
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet2/0/48
!
interface GigabitEthernet2/1/1
!
interface GigabitEthernet2/1/2
!
interface GigabitEthernet2/1/3
!
interface GigabitEthernet2/1/4
!
interface TenGigabitEthernet2/1/1
description [CORE] SW-1-1
switchport trunk encapsulation dot1q
switchport mode trunk
channel-group 1 mode active
!
interface TenGigabitEthernet2/1/2
!
interface Vlan1
no ip address
shutdown
!
interface Vlan100
no ip address
!
interface Vlan300
description --MANAGMENT--
ip address 10.4.254.253 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
!
ip default-gateway 10.4.254.254
ip http server
no ip http secure-server
!
!
logging facility local2
logging source-interface Vlan300
logging host 192.168.8.119 transport udp port 5544
access-list 5 permit 192.168.8.99
access-list 5 permit 10.2.1.245
access-list 23 permit any
access-list 23 deny any log
!
snmp-server community lmTUEsk6Yvlv RO
snmp ifmib ifindex persist
!
!
radius server IZH-RDS002
address ipv4 10.4.0.248 auth-port 1645 acct-port 1646
timeout 3
retransmit 2
key hykFAA@Hg9X9fsokWh5q8wez#&^a9lIizldHKxlRer3RE7AbsTsJwdB^RESF$eJ0
!
radius server P11-RDS003
address ipv4 10.1.122.248 auth-port 1645 acct-port 1646
timeout 3
retransmit 2
key hykFAA@Hg9X9fsokWh5q8wez#&^a9lIizldHKxlRer3RE7AbsTsJwdB^RESF$eJ0
!
!
!
line con 0
logging synchronous
login authentication CONSOLE
line vty 0 4
access-class 23 in
exec-timeout 120 0
logging synchronous
login authentication NPS
length 0
transport input ssh
line vty 5 15
access-class 23 in
exec-timeout 120 0
logging synchronous
login authentication NPS
transport input ssh
!
ntp server 192.168.8.200
end