ansible/backup/files/cisco/IZH-MLK-IZM-SW-1-3.txt

590 lines
13 KiB
Plaintext
Raw Permalink Normal View History

2025-10-31 08:47:26 +04:00
Building configuration...
Current configuration : 13629 bytes
!
! Last configuration change at 16:51:47 SAMT Fri May 27 2022 by adm_ivanovas
! NVRAM config last updated at 16:18:54 SAMT Thu May 26 2022 by adm_ivanovas
!
version 15.2
no service pad
service timestamps debug datetime msec localtime show-timezone year
service timestamps log datetime msec localtime show-timezone year
service password-encryption
!
hostname IZH-MLK-IZM-SW-1-3
!
boot-start-marker
boot-end-marker
!
logging userinfo
logging buffered 64000
enable secret 5 $1$s9Gc$Al.6G1QWOeNqLhCGo6CxP/
!
username netadmin privilege 15 secret 5 $1$8dIx$LHaqu8wsWda0FbCGHiahv1
aaa new-model
!
!
aaa group server radius NPS
server name IZH-RDS002
server name P11-RDS003
load-balance method least-outstanding
!
aaa authentication login default group NPS local enable
aaa authentication login CONSOLE local group NPS
aaa authorization exec default group NPS local if-authenticated
!
!
!
!
!
!
aaa session-id common
clock timezone SAMT 4 0
switch 1 provision ws-c2960x-48fps-l
!
!
no ip domain-lookup
ip domain-name milkom-komos.ru
ip host tftp 10.4.0.214
vtp mode off
!
!
!
!
!
!
!
crypto pki trustpoint TP-self-signed-2757678336
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2757678336
revocation-check none
rsakeypair TP-self-signed-2757678336
!
!
crypto pki certificate chain TP-self-signed-2757678336
certificate self-signed 01
3082022B 30820194 A0030201 02020101 300D0609 2A864886 F70D0101 05050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 32373537 36373833 3336301E 170D3136 30373035 30383333
30325A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 37353736
37383333 3630819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100C949 A7A93DE5 D8B5B5E9 2979F97B 6C3D624D C37A2608 7AE0ACFC 6B4D49D2
5B6D9C13 3D6DC4EA BE322D26 17415D96 D6AD1B88 FF232B08 7AA483B4 468488AA
4B085389 F506F28D AE445DBE AEF57C02 6B049AF7 49D949F8 9065449F 360CBE16
D8FF79FA ABFA0738 A85B74E9 6718283A BA335B63 B1FC0D7C 341E86BB 6631D220
6C2F0203 010001A3 53305130 0F060355 1D130101 FF040530 030101FF 301F0603
551D2304 18301680 1433C158 39B28FCC 92F392E5 430AE8C1 68ECC60A FC301D06
03551D0E 04160414 33C15839 B28FCC92 F392E543 0AE8C168 ECC60AFC 300D0609
2A864886 F70D0101 05050003 81810085 10FEB8C3 6C0DE5C1 4CB7144F 009DEA70
5BA15FDF D741F65D 097C3AE8 D3BB4A54 0319E78B 18820443 0AB9C014 438B7A33
5BD1C9A6 42AD6962 427D0590 F398710D 0350E3A3 0013B013 8F76355A 556858E3
B9F4C7CE B2C52664 012E5048 1AE3447E E81D93AA 76ED3CF5 FACC344E 01DC6A74
F9DE155D 3751DAD5 5DEAC2FB 2D0904
quit
archive
log config
logging enable
logging size 900
notify syslog contenttype plaintext
hidekeys
path tftp://tftp/IZH/2960/$H-$T
write-memory
time-period 10080
spanning-tree mode pvst
spanning-tree logging
spanning-tree extend system-id
errdisable recovery cause udld
errdisable recovery cause bpduguard
errdisable recovery cause security-violation
errdisable recovery cause channel-misconfig
errdisable recovery cause pagp-flap
errdisable recovery cause dtp-flap
errdisable recovery cause link-flap
errdisable recovery cause sfp-config-mismatch
errdisable recovery cause gbic-invalid
errdisable recovery cause psecure-violation
errdisable recovery cause port-mode-failure
errdisable recovery cause dhcp-rate-limit
errdisable recovery cause pppoe-ia-rate-limit
errdisable recovery cause mac-limit
errdisable recovery cause vmps
errdisable recovery cause storm-control
errdisable recovery cause inline-power
errdisable recovery cause arp-inspection
errdisable recovery cause loopback
errdisable recovery cause small-frame
errdisable recovery cause psp
errdisable recovery interval 600
port-channel load-balance src-dst-ip
!
!
!
!
vlan internal allocation policy ascending
!
vlan 8
name --UserNet_8.0/24--
!
vlan 10,20
!
vlan 93
name CCTV_stolovaya
!
vlan 95
name --MTS--
!
vlan 96
name --ERTELEKOM--
!
vlan 97
name --MEGAFON--
!
vlan 98
name --MARK--
!
vlan 99
name --MARK_ASTERISK--
!
vlan 250
name --ServerNet_0.0/24--
!
vlan 253
name exchange_komos-group
!
vlan 292
name -=bak_net_243.0_24=-
!
vlan 294
name --SRV_iLO_iDrack_etc--
!
vlan 299
name --SrvMng_240.0\24--
!
vlan 300
name --MANAGMENT--
!
vlan 301
name --Wi-Fi_MANAGMENT--
!
vlan 553
name VST-IZM_Peering
!
vlan 554
name VRS-IZM Peering
!
vlan 556
name P2P_iBGP_KOMOS_AS_over_ER_Teleco
!
vlan 557
name P2P_iBGP_KOMOS_AS_over_MTS
!
vlan 599
name --MTS_KOMOS_599--
!
vlan 650
name --ISCSI--
!
vlan 3915
name --TEST_ZLOBIN_DENIS_UNTIL_01.07.
!
vlan 4030
name --MTS_KOMOS_4030--
!
vlan 4031
name --MLK-KCOD_VEAMREPL_172.31.31.0/
!
vlan 4032
name --MLK-KCOD_SQLREPL_172.31.33.0/2
!
vlan 4033
name --MLK-KCOD_SRVVCHA_172.31.33.0/2
!
vlan 4034
name --MLK-KCOD_EXCHREPL_172.31.34.0/
!
vlan 4035
name --MLK-KCOD_SRVVCMG_172.31.35.0/2
!
lldp run
!
!
!
!
!
!
!
!
!
!
interface Port-channel1
description [CORE] SW-1-1
switchport mode trunk
!
interface Port-channel2
description NONE
switchport access vlan 294
switchport mode access
!
interface Port-channel3
description [PEER] VST-IZM Peering
switchport trunk allowed vlan 553
switchport mode trunk
storm-control broadcast level pps 200
storm-control multicast level pps 200
spanning-tree bpdufilter enable
!
interface Port-channel4
description [PEER] VRS-IZM Peering
switchport trunk allowed vlan 554
switchport mode trunk
spanning-tree bpdufilter enable
!
interface FastEthernet0
no ip address
!
interface GigabitEthernet1/0/1
description ISP_MARK_ASTERISK (99)
switchport access vlan 99
switchport mode access
spanning-tree bpdufilter enable
!
interface GigabitEthernet1/0/2
description [CAM] P1
!
interface GigabitEthernet1/0/3
description [ISP-100M] ER-Telecom
switchport access vlan 96
switchport mode access
storm-control broadcast level pps 200 180
storm-control multicast level pps 200 180
storm-control action shutdown
no cdp enable
no lldp transmit
no lldp receive
spanning-tree bpdufilter enable
!
interface GigabitEthernet1/0/4
description [CAM] P2
!
interface GigabitEthernet1/0/5
description [ISP-100M] Mark
switchport access vlan 98
switchport mode access
spanning-tree bpdufilter enable
!
interface GigabitEthernet1/0/6
description [CORE] RT-1-1
switchport access vlan 98
switchport mode access
!
interface GigabitEthernet1/0/7
description [ISP-100M] Megafon
switchport access vlan 97
switchport mode access
!
interface GigabitEthernet1/0/8
description [CORE] RT-1-2
switchport access vlan 97
switchport mode access
!
interface GigabitEthernet1/0/9
description NONE
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/10
description NONE
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/11
description --IZH_SHD001_ILOA--
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/12
description --IZH_SHD001_ILOB--
switchport mode trunk
no snmp trap link-status
!
interface GigabitEthernet1/0/13
description --IZH_VMW004_ILO--
switchport mode trunk
!
interface GigabitEthernet1/0/14
description --IZH_VMW006_ILO--
switchport mode trunk
no snmp trap link-status
!
interface GigabitEthernet1/0/15
description --IZH_VMW020_ILO--
switchport mode trunk
no snmp trap link-status
!
interface GigabitEthernet1/0/16
description --IZH_FCC004_ILO--
switchport access vlan 294
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/17
description --IZH_FCC005_ILO--
switchport access vlan 294
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/18
description --IZH_SHD006_INFO_ILO--
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/19
description --IZH_VMW021_ILO--
switchport mode trunk
no snmp trap link-status
!
interface GigabitEthernet1/0/20
description --IZH_VMW005_ILO--
switchport mode trunk
!
interface GigabitEthernet1/0/21
description --IZH_SHD005_HUAWEI_ILO_A--
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/22
description --IZH_VMW013_ILO--
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/0/23
description --IZH_VMW016_ILO--
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/0/24
description --IZH_VMW015_ILO--
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/0/25
description --IZH_FCC001_ILO--
switchport mode trunk
no snmp trap link-status
!
interface GigabitEthernet1/0/26
description --IZH_FCC002_ILO--
switchport mode trunk
no snmp trap link-status
!
interface GigabitEthernet1/0/27
description -=IZH_SHD002_QSAN_ILO=-
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/28
description --IZH_VMW016_ILO--
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/0/29
description --IZH_VMW012_ILO--
switchport mode trunk
no snmp trap link-status
!
interface GigabitEthernet1/0/30
description --IZH_SHD005_HUAWEI_ILO_B--
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/31
description --IZH_VMW011_ILO--
switchport mode trunk
no snmp trap link-status
!
interface GigabitEthernet1/0/32
description --IZH_VMW007_ILO--
switchport mode access
!
interface GigabitEthernet1/0/33
description --IZH_BKP007_ILO--
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/0/34
description --IZH_VMW008_ILO--
switchport mode access
!
interface GigabitEthernet1/0/35
description [SRV] VMW028_ILO
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/0/36
description NONE
switchport access vlan 294
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/37
description --MON_COD_Condition1.2--
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/38
description --MON_COD_NetPing--
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/39
description --MON_COD_Condition1.1--
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/40
description --MON_COD_Chiller--
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/41
description --MON_COD_Vut230--
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/42
description --MON_COD_UPS--
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/43
description --MON_COD_MOXA_DGU--
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/44
description --MON_COD_Condition1.3--
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/45
description --MON_COD_Vut231
switchport access vlan 299
switchport mode access
no snmp trap link-status
!
interface GigabitEthernet1/0/46
description [SRV] VMW027_ILO
switchport access vlan 294
switchport mode access
!
interface GigabitEthernet1/0/47
description [CORE] RT-1-3
switchport access vlan 300
switchport mode access
!
interface GigabitEthernet1/0/48
description [CORE] RT-1-4
switchport access vlan 300
switchport mode access
!
interface GigabitEthernet1/0/49
description [CORE] Po1 SW-1-1
switchport mode trunk
channel-group 1 mode on
!
interface GigabitEthernet1/0/50
description [CORE] Po1 SW-1-1
switchport mode trunk
channel-group 1 mode on
!
interface GigabitEthernet1/0/51
description [PEER] Po3 VST-IZM Peering
switchport trunk allowed vlan 553
switchport mode trunk
storm-control broadcast level pps 200
storm-control multicast level pps 200
channel-group 3 mode active
!
interface GigabitEthernet1/0/52
description [PEER] Po4 VRS-IZM Peering
switchport trunk allowed vlan 554
switchport mode trunk
spanning-tree bpdufilter enable
channel-group 4 mode active
!
interface Vlan1
no ip address
shutdown
!
interface Vlan292
description -=bak_net_243.0_24=-
no ip address
!
interface Vlan300
description --MANAGMENT--
ip address 10.4.254.245 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Vlan4000
no ip address
!
ip default-gateway 10.4.254.254
ip http server
ip http secure-server
!
!
logging origin-id hostname
logging source-interface Vlan300
logging host 192.168.8.119 transport udp port 5544
logging host 10.4.244.4 transport udp port 515
!
snmp-server community lmTUEsk6Yvlv RO
!
!
radius server IZH-RDS002
address ipv4 10.4.0.248 auth-port 1645 acct-port 1646
timeout 3
retransmit 2
key 7 08707B1C5017412008034A2E0B1562073C2C2F3136060C40127A797F7203470C32747705467D0D6C296C23175D53171A23357A380C072C411822322347275D022A
!
radius server P11-RDS003
address ipv4 10.1.122.248 auth-port 1645 acct-port 1646
timeout 3
retransmit 2
key 7 0657387315404D2E1F1F54212D3A6C042B313E1713030857472277757E5E101A2735390B4D780B6A77632E4B03034B5E2122273751030B027767652F4930411C25
!
!
!
line con 0
logging synchronous
login authentication CONSOLE
line vty 0 4
exec-timeout 120 0
logging synchronous
length 0
transport input ssh
line vty 5 15
access-class 23 in
exec-timeout 120 0
logging synchronous
transport input ssh
!
ntp server 192.168.8.200
ntp server 192.168.8.201
end