ansible/backup/files/cisco/IZH-VRS-PFV-RT-1-1.txt

1599 lines
61 KiB
Plaintext
Raw Permalink Normal View History

2025-10-31 08:47:26 +04:00
Building configuration...
Current configuration : 62006 bytes
!
! Last configuration change at 10:42:27 IZH Fri Jul 22 2022 by menshikov
! NVRAM config last updated at 01:30:00 IZH Thu Jul 28 2022
!
version 15.7
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone year
service timestamps log datetime msec localtime show-timezone year
service password-encryption
service sequence-numbers
!
hostname IZH-VRS-PFV-RT-1-1
!
boot-start-marker
boot system flash:c2900-universalk9-mz.SPA.157-3.M.bin
boot-end-marker
!
!
security authentication failure rate 3 log
logging buffered 16386
logging rate-limit 100 except warnings
logging console critical
!
aaa new-model
!
!
aaa group server radius NPS
server name IZH-RDS002
server name P11-RDS003
ip radius source-interface GigabitEthernet0/2.300
load-balance method least-outstanding
!
aaa authentication login default local group NPS enable
aaa authentication login LOCAL_AUTH local
aaa authentication login sslvpn local
aaa authentication login CONSOLE local group NPS
aaa authorization exec default local group NPS if-authenticated
aaa authorization network sslvpn local
!
aaa attribute list ANYCONNECT_USERS
attribute type user-vpn-group "WEBVPN_POLICY_USERS"
!
aaa attribute list ANYCONNECT_ADMINISTRATORS
attribute type user-vpn-group "WEBVPN_POLICY_ADMINISTRATORS"
!
aaa attribute list ANYCONNECT_USERS_K_LOG
attribute type user-vpn-group "WEBVPN_POLICY_USERS_K_LOG"
!
aaa attribute list ANYCONNECT_USERS_TO_MILK_SRV-T2
attribute type user-vpn-group "WEBVPN_POLICY_TO_MILK_PORT3389"
!
!
!
!
!
aaa session-id common
clock timezone IZH 4 0
!
!
!
!
!
!
no ip source-route
no ip gratuitous-arps
!
!
!
!
!
!
ip flow-cache timeout inactive 60
ip flow-cache timeout active 5
no ip bootp server
ip domain name komos.ru
ip host SERVER_VPN 192.168.1.20
ip host tftp 10.4.0.214
ip cef
login block-for 60 attempts 3 within 20
login on-failure log
login on-success log
no ipv6 cef
!
multilink bundle-name authenticated
!
!
!
!
!
cts logging verbose
!
crypto pki trustpoint CA_VPNPFV_KOMOS_RU
enrollment terminal pem
revocation-check none
!
crypto pki trustpoint VPNPFV_KOMOS_RU
enrollment pkcs12
revocation-check none
rsakeypair VPNPFV_KOMOS_RU
!
crypto pki trustpoint VPNPFV_KOMOS_RU_2022
enrollment pkcs12
revocation-check crl
rsakeypair VPNPFV_KOMOS_RU_2022
!
crypto pki trustpoint VPNPFV_KOMOS_RU_2023
enrollment pkcs12
revocation-check crl
rsakeypair VPNPFV_KOMOS_RU_2023
!
!
crypto pki certificate chain CA_VPNPFV_KOMOS_RU
certificate ca 01FD6D30FCA3CA51A81BBC640E35032D
308205DE 308203C6 A0030201 02021001 FD6D30FC A3CA51A8 1BBC640E 35032D30
0D06092A 864886F7 0D01010C 05003081 88310B30 09060355 04061302 55533113
30110603 55040813 0A4E6577 204A6572 73657931 14301206 03550407 130B4A65
72736579 20436974 79311E30 1C060355 040A1315 54686520 55534552 54525553
54204E65 74776F72 6B312E30 2C060355 04031325 55534552 54727573 74205253
41204365 72746966 69636174 696F6E20 41757468 6F726974 79301E17 0D313030
32303130 30303030 305A170D 33383031 31383233 35393539 5A308188 310B3009
06035504 06130255 53311330 11060355 0408130A 4E657720 4A657273 65793114
30120603 55040713 0B4A6572 73657920 43697479 311E301C 06035504 0A131554
68652055 53455254 52555354 204E6574 776F726B 312E302C 06035504 03132555
53455254 72757374 20525341 20436572 74696669 63617469 6F6E2041 7574686F
72697479 30820222 300D0609 2A864886 F70D0101 01050003 82020F00 3082020A
02820201 00801265 17360EC3 DB08B3D0 AC570D76 EDCD27D3 4CAD5083 61E2AA20
4D092D64 09DCCE89 9FCC3DA9 ECF6CFC1 DCF1D3B1 D67B3728 112B47DA 39C6BC3A
19B45FA6 BD7D9DA3 6342B676 F2A93B2B 91F8E26F D0EC1620 90093EE2 E874C918
B491D462 64DB7FA3 06F18818 6A90223C BCFE13F0 87147BF6 E41F8ED4 E451C611
67460851 CB861454 3FBC33FE 7E6C9CFF 169D18BD 518E35A6 A766C872 67DB2166
B1D49B78 03C0503A E8CCF0DC BC9E4CFE AF059635 1F575AB7 FFCEF93D B72CB6F6
54DDC8E7 123A4DAE 4C8AB75C 9AB4B720 3DCA7F22 34AE7E3B 68660144 E7014E46
539B3360 F794BE53 37907343 F332C353 EFDBAAFE 744E69C7 6B8C6093 DEC4C70C
DFE132AE CC933B51 7895678B EE3D56FE 0CD0690F 1B0FF325 266B336D F76E47FA
7343E57E 0EA566B1 297C3284 635589C4 0DC19354 301913AC D37D37A7 EB5D3A6C
355CDB41 D712DAA9 490BDFD8 808A0993 628EB566 CF2588CD 84B8B13F A4390FD9
029EEB12 4C957CF3 6B05A95E 1683CCB8 67E2E813 9DCC5B82 D34CB3ED 5BFFDEE5
73AC233B 2D00BF35 55740949 D849581A 7F9236E6 51920EF3 267D1C4D 17BCC9EC
4326D0BF 415F40A9 4444F499 E757879E 501F5754 A83EFD74 632FB150 6509E658
422E431A 4CB4F025 4759FA04 1E93D426 464A5081 B2DEBE78 B7FC6715 E1C95784
1E0F63D6 E962BAD6 5F552EEA 5CC62808 042539B8 0E2BA9F2 4C971C07 3F0D52F5
EDEF2F82 0F020301 0001A342 3040301D 0603551D 0E041604 145379BF 5AAA2B4A
CF5480E1 D89BC09D F2B20366 CB300E06 03551D0F 0101FF04 04030201 06300F06
03551D13 0101FF04 05300301 01FF300D 06092A86 4886F70D 01010C05 00038202
01005CD4 7C0DCFF7 017D4199 650C73C5 529FCBF8 CF99067F 1BDA4315 9F9E0255
579614F1 523C2787 9428ED1F 3A0137A2 76FC5350 C0849BC6 6B4EBA8C 214FA28E
556291F3 6915D8BC 88E3C4AA 0BFDEFA8 E94B552A 06206D55 782919EE 5F305C4B
241155FF 249A6E5E 2A2BEE0B 4D9F7FF7 01389414 95430709 FB60A9EE 1CAB128C
A09A5EA7 986A596D 8B3F08FB C8D145AF 18156490 120F7328 2EC5E224 4EFC58EC
F0F445FE 22B3EB2F 8ED2D945 6105C197 6FA87672 8F8B8C36 AFBF0D05 CE718DE6
A66F1F6C A67162C5 D8D08372 0CF16711 890C9C13 4C7234DF BCD571DF AA71DDE1
B96C8C3C 125D65DA BD5712B6 436BFFE5 DE4D6611 51CF99AE EC17B6E8 71918CDE
49FEDD35 71A21527 941CCF61 E326BB6F A3672521 5DE6DD1D 0B2E681B 3B82AFEC
836785D4 985174B1 B9998089 FF7F7819 5C794A60 2E9240AE 4C372A2C C9C762C8
0E5DF736 5BCAE025 2501B4DD 1A079C77 003FD0DC D5EC3DD4 FABB3FCC 85D66F7F
A92DDFB9 02F7F597 9AB535DA C367B087 4AA9289E 238EFF5C 276BE1B0 4FF307EE
002ED459 87CB5241 95EAF447 D7EE6441 557C8D59 0295DD62 9DC2B9EE 5A287484
A59BB790 C70C07DF F5893674 32D628C1 B0B00BE0 9C4CC31C D6FCE369 B5474681
2FA282AB D3634470 C48DFF2D 33BAAD8F 7BB57088 AE3E19CF 4028D8FC C890BB5D
9922F552 E658C51F 883143EE 881DD7C6 8E3C436A 1DA718DE 7D3D16F1 62F9CA90 A8FD
quit
crypto pki certificate chain VPNPFV_KOMOS_RU
certificate 0093FAAC8A0C37F508F5D3C800883BFDB6
308206C2 308205AA A0030201 02021100 93FAAC8A 0C37F508 F5D3C800 883BFDB6
300D0609 2A864886 F70D0101 0B050030 8195310B 30090603 55040613 02474231
1B301906 03550408 13124772 65617465 72204D61 6E636865 73746572 3110300E
06035504 07130753 616C666F 72643118 30160603 55040A13 0F536563 7469676F
204C696D 69746564 313D303B 06035504 03133453 65637469 676F2052 5341204F
7267616E 697A6174 696F6E20 56616C69 64617469 6F6E2053 65637572 65205365
72766572 20434130 1E170D32 30303532 31303030 3030305A 170D3231 30363036
32333539 35395A30 81BF310B 30090603 55040613 02525531 0F300D06 03550411
13063132 37303135 31193017 06035504 08131055 646D7572 74736B61 79612052
65737031 0F300D06 03550407 13064D6F 73636F77 31433041 06035504 09133A64
2E203220 6B6F7270 2E203120 706F6D2E 20584C49 206B6F6D 2E203120 6574617A
6820352C 20756C2E 204E6F76 6F646D69 74726F76 736B6179 61311930 17060355
040A1310 4B4F4D4F 53204752 5550502C 204F4F4F 31133011 06035504 030C0A2A
2E6B6F6D 6F732E72 75308201 22300D06 092A8648 86F70D01 01010500 0382010F
00308201 0A028201 0100A9BC A8041307 C2830836 182F1AD2 C9D774D7 E50702F9
60DC1C7B BBD56BD9 398B8CDB F56C4BD7 F6F0C489 EC427A54 B89402D5 B305D795
0F52D67A D6F82E80 89650879 4F719B66 21C14B0D 0FABC31E 6FE730EF 71B553C8
DBE2A5C4 F069BB0D 3C141AC6 3DA12719 31D1DE66 D34DCCCB 490B0FAA D68C5E15
7A9962FD 09E2B17D 74115809 B1ABDE35 323B7E3E 48816379 338849E9 5F906B3E
A711DBBC 1C3C76C2 2E5FE73C E67A9249 90347DE7 79623B3D 42D48F61 C745B439
54B21C99 9FB93878 F298AB84 53CFF3CC A34C039E 89393DF1 80192065 DCDA3811
291251A8 43C27A6D A5119AB1 9BECCF61 B14BE8B9 5822B8E0 07DF763F E688AB56
F630725B 040F0C58 86010203 010001A3 8202DF30 8202DB30 1F060355 1D230418
30168014 17D9D625 2767F931 C24943D9 3036448C 6CA94FEB 301D0603 551D0E04
1604144D 10DBEA91 956D4FC3 2B72ED20 556CFA1E 38927130 0E060355 1D0F0101
FF040403 0205A030 0C060355 1D130101 FF040230 00301D06 03551D25 04163014
06082B06 01050507 03010608 2B060105 05070302 304A0603 551D2004 43304130
35060C2B 06010401 B2310102 01030430 25302306 082B0601 05050702 01161768
74747073 3A2F2F73 65637469 676F2E63 6F6D2F43 50533008 06066781 0C010202
305A0603 551D1F04 53305130 4FA04DA0 4B864968 7474703A 2F2F6372 6C2E7365
63746967 6F2E636F 6D2F5365 63746967 6F525341 4F726761 6E697A61 74696F6E
56616C69 64617469 6F6E5365 63757265 53657276 65724341 2E63726C 30818A06
082B0601 05050701 01047E30 7C305506 082B0601 05050730 02864968 7474703A
2F2F6372 742E7365 63746967 6F2E636F 6D2F5365 63746967 6F525341 4F726761
6E697A61 74696F6E 56616C69 64617469 6F6E5365 63757265 53657276 65724341
2E637274 30230608 2B060105 05073001 86176874 74703A2F 2F6F6373 702E7365
63746967 6F2E636F 6D301F06 03551D11 04183016 820A2A2E 6B6F6D6F 732E7275
82086B6F 6D6F732E 72753082 0104060A 2B060104 01D67902 04020481 F50481F2
00F00076 007D3EF2 F88FFF88 556824C2 C0CA9E52 89792BC5 0E78097F 2E6A9768
997E22F0 D7000001 7236A9F2 D2000004 03004730 45022100 BACB9772 4718DCE5
AFEED323 E69255EB F80BC770 691BC5CC 6ED46DC0 7B943C7A 02206694 07DA794C
00D45D62 77AE3C67 551C8579 1809B227 1DB745AD 453697BE 07130076 009420BC
1E8ED58D 6C88731F 828B222C 0DD1DA4D 5E6C4F94 3D61DB4E 2F584DA2 C2000001
7236A9F3 87000004 03004730 45022100 F36F3BC4 9BA01275 14F2FF66 148551B5
C6A70EBE 09A65A0D CCF96BF1 92C2B748 02207971 87B7F2D7 A2E5C871 A2643DCB
F9D929BA 8FA907CC B13764C8 087C64E5 E33E300D 06092A86 4886F70D 01010B05
00038201 010091BE 0134215B E5683466 47B8CBD4 95E668A9 E30DE2EA A58F0276
88F68F0B D5656A80 642FB4C4 633C68E5 FB95144E 185DDB2A 9E796A26 2F0147D8
6850CEFC A41D8856 A62E9EBF 907523C5 AB9F25C0 E0556618 2416F912 AE30B0F1
C4621BDB AEF3E06F 55FA13E9 F9549290 3AD8617F BCEE2058 4B04A901 4C1E9A18
D5FD603C C92178FB 1ABC12E8 84E8F30E 3E08F04F D8544887 460AC53B 78A06E0E
27EC0426 2AA9E09D A5EF10C1 1EEA1FA4 CE572F16 9081F5CE 94371A35 35B32B0B
DCB1BCD8 A872E24D A7045002 52764CAD F80FAC74 FBF9EF0F DD9F3397 DAE4CE81
BB504649 0A2DE226 8E037485 4392319B 7116D45E B8D40724 FC487229 4651A35D
0483B01E E61E
quit
certificate ca 137D539CAA7C31A9A433701968847A8D
30820619 30820401 A0030201 02021013 7D539CAA 7C31A9A4 33701968 847A8D30
0D06092A 864886F7 0D01010C 05003081 88310B30 09060355 04061302 55533113
30110603 55040813 0A4E6577 204A6572 73657931 14301206 03550407 130B4A65
72736579 20436974 79311E30 1C060355 040A1315 54686520 55534552 54525553
54204E65 74776F72 6B312E30 2C060355 04031325 55534552 54727573 74205253
41204365 72746966 69636174 696F6E20 41757468 6F726974 79301E17 0D313831
31303230 30303030 305A170D 33303132 33313233 35393539 5A308195 310B3009
06035504 06130247 42311B30 19060355 04081312 47726561 74657220 4D616E63
68657374 65723110 300E0603 55040713 0753616C 666F7264 31183016 06035504
0A130F53 65637469 676F204C 696D6974 6564313D 303B0603 55040313 34536563
7469676F 20525341 204F7267 616E697A 6174696F 6E205661 6C696461 74696F6E
20536563 75726520 53657276 65722043 41308201 22300D06 092A8648 86F70D01
01010500 0382010F 00308201 0A028201 01009C93 0246454A 524892FC 578DF92D
EA53BEB3 2CD5D8A8 A5EC5B69 03C01D10 F65933DE FE0748A8 E88C7A67 4AF1F58D
C33766D0 3291F7C4 9D0460C4 B54AE283 8BA7AE26 D45D3A5E F8D11671 BB8ABD71
A27DC8CE A26024B0 52A03A45 51DE7893 6C6260F1 E4569CB7 3BF73C55 D8DFD57A
317C357F 125170E1 2CBE04AC CBFA4FE1 7C656AC0 40A7D97C A5638419 E1F7CAEF
AAB4E858 5AD999E3 26DF8E12 B2B8DC33 B236DA14 1D965842 406E0B22 851C5122
AEC4C806 456D92E6 67B71923 E4D8366B 85D07FC7 52E3CFB0 7501E089 B4A8BF8A
364EA3E0 6CEB8441 CEA52F48 22139750 62451E09 A5CC9F6C 57704006 DB20E81B
D6F3938B A7329EB7 441509D7 AFFD7C01 1CDB0203 010001A3 82016E30 82016A30
1F060355 1D230418 30168014 5379BF5A AA2B4ACF 5480E1D8 9BC09DF2 B20366CB
301D0603 551D0E04 16041417 D9D62527 67F931C2 4943D930 36448C6C A94FEB30
0E060355 1D0F0101 FF040403 02018630 12060355 1D130101 FF040830 060101FF
02010030 1D060355 1D250416 30140608 2B060105 05070301 06082B06 01050507
0302301B 0603551D 20041430 12300606 04551D20 00300806 0667810C 01020230
50060355 1D1F0449 30473045 A043A041 863F6874 74703A2F 2F63726C 2E757365
72747275 73742E63 6F6D2F55 53455254 72757374 52534143 65727469 66696361
74696F6E 41757468 6F726974 792E6372 6C307606 082B0601 05050701 01046A30
68303F06 082B0601 05050730 02863368 7474703A 2F2F6372 742E7573 65727472
7573742E 636F6D2F 55534552 54727573 74525341 41646454 72757374 43412E63
72743025 06082B06 01050507 30018619 68747470 3A2F2F6F 6373702E 75736572
74727573 742E636F 6D300D06 092A8648 86F70D01 010C0500 03820201 004E1340
96C9C3E6 6E5BC0E3 BAF417E1 AE091FC9 BFCB0C25 16F27353 B3761AB7 AB4806D6
CD007C20 4543456C 165A1B13 61D749BA A402A4AC E8CECE2D C92A74A3 DCDEAEAB
D06836F8 91AF3C01 F777D50B CF97ABEB 87E715A8 FA305A61 7120B1C0 43C4B98F
6D8A31EB 153624FB 62D50B9C 8FE966BD E6615197 93B61D87 BDB0B56C FEA61129
06613431 303D2027 7351D0DE 8583D377 39204696 DAA7C65A 162785B2 CF4E0F4E
8C5CBEBE 3800F84B F9727BD4 F27AD7A2 2985D004 BAD3422C 5188522E D13D2467
47EC55CC 1BF4CA34 EA26C1DE DDC42189 F6BA7B32 1E8E965E 844538CF 80AA3769
8B601774 1548919C 6DF04EA3 77CA1B1C 48FAF9CF 49E85F4F 850AE28F 901BAB70
4C9AEBB7 A63FB4AC 5DA45FCF E6D88A96 90F74F26 8160765D 0F247791 B32A319F
165AB25D 8C1C29AA 489C8E6F D3784070 DB77ECDD E3D15705 702DE649 98880584
62057056 7686394E D3226F1D FE6DF10E B362C43C CBC085B9 611EBAE1 15805994
0CAE05BB 8C7F56BE 1CD25ABF 97F26A4C B0C67076 B0908DC1 0B36B911 D8D6285C
EA4FFE24 B7180A9B 0CD0C17C 5CFB69BD CCA24DC6 90BCA64D F2B1BAD6 9A675B96
0252D082 F9C40A5C 0D28E03F C8FA9595 89D5A4BE 496C40B2 3EA86BB8 D525B2C4
FEF1D3D7 E7D6DC43 017630FB 3B8B5DF7 4A897C9A 35BEFCCA F05701F0 8D3FA087
327B475A 974B82D2 66C2C42D EA3F24F4 A7F9A8B9 E36AD918 61A03B8C 15
quit
crypto pki certificate chain VPNPFV_KOMOS_RU_2022
certificate 77E2BE4C21E6316A24DBB868F00BED04
3082070C 308205F4 A0030201 02021077 E2BE4C21 E6316A24 DBB868F0 0BED0430
0D06092A 864886F7 0D01010B 05003081 8F310B30 09060355 04061302 4742311B
30190603 55040813 12477265 61746572 204D616E 63686573 74657231 10300E06
03550407 13075361 6C666F72 64311830 16060355 040A130F 53656374 69676F20
4C696D69 74656431 37303506 03550403 132E5365 63746967 6F205253 4120446F
6D61696E 2056616C 69646174 696F6E20 53656375 72652053 65727665 72204341
301E170D 32313035 32353030 30303030 5A170D32 32303532 35323335 3935395A
30183116 30140603 55040313 0D6D6169 6C2E6B6F 6D6F732E 72753082 0122300D
06092A86 4886F70D 01010105 00038201 0F003082 010A0282 010100D9 E5B4EF4B
02550906 AD8F730A 3B2A5DC0 C3FF5C21 CD616258 59D1D1C0 D69E073E 45B6B40C
68BE4CC4 36220DB5 981C5879 B2E704FF 45A40B66 9CB029CE 57E804F7 178F2822
4F5DDEBE 48843A82 018BD466 62BB7DCD 524F2B4E FB3535A0 E2EEDE16 50C5D163
A7CE7373 07D6F7A3 E1AEBD53 3B962EE9 75B653C7 7CFDFADB F36D89AD 6462D3B4
B5862E88 627BE4A4 816E820A 329AF53D D76A8655 D4A4CE86 6CA5A0A1 B05D3949
9F794F1F B13AC467 872032E4 7219AFC4 B6D63547 70CA3328 9604EB22 840DD3A0
77DCCF7B A45E9B53 03FCDD7E 7B1E4A5A 0E513143 63D28FDE 7DBC0D07 3F95D8C0
FDA7F1E2 B403F91B DAFC2413 34029A68 43665DED 27201116 4D2D9702 03010001
A38203D8 308203D4 301F0603 551D2304 18301680 148D8C5E C454AD8A E177E99B
F99B05E1 B8018D61 E1301D06 03551D0E 04160414 002A7EC2 662907EB F75BC17D
F7F9DF0A F42ACB09 300E0603 551D0F01 01FF0404 030205A0 300C0603 551D1301
01FF0402 3000301D 0603551D 25041630 1406082B 06010505 07030106 082B0601
05050703 02304906 03551D20 04423040 3034060B 2B060104 01B23101 02020730
25302306 082B0601 05050702 01161768 74747073 3A2F2F73 65637469 676F2E63
6F6D2F43 50533008 06066781 0C010201 30818406 082B0601 05050701 01047830
76304F06 082B0601 05050730 02864368 7474703A 2F2F6372 742E7365 63746967
6F2E636F 6D2F5365 63746967 6F525341 446F6D61 696E5661 6C696461 74696F6E
53656375 72655365 72766572 43412E63 72743023 06082B06 01050507 30018617
68747470 3A2F2F6F 6373702E 73656374 69676F2E 636F6D30 82018006 0A2B0601
0401D679 02040204 82017004 82016C01 6A007700 46A555EB 75FA9120 30B5A289
69F4F37D 112C4174 BEFD49B8 85ABF2FC 70FE6D47 00000179 A2B18A2A 00000403
00483046 02210092 9FC14921 8829BB54 E5E5C0F9 26E9BF14 11A7A072 61F619F0
80F84A75 752E8A02 2100CE89 C0522F38 B6737C73 DE0D1491 B1313F82 F15D5633
13C7E4D8 6FAD9964 40AA0077 00DFA55E AB68824F 1F6CADEE B85F4E3E 5AEACDA2
12A46A5E 8E3B12C0 20445C2A 73000001 79A2B18A 0A000004 03004830 46022100
ECE6B915 0E3C7EAA B12AB377 553E7369 F3D2C44B FF4348D3 4E0BA6F3 DA6F8A8E
02210098 74BCFFA2 CAAEBA83 C21EBF13 15E1C072 3A39E90D 993D5BFB 08002E76
2B39FD00 76002979 BEF09E39 3921F056 739F63A5 77E5BE57 7D9C600A F8F94D5D
265C255D C7840000 0179A2B1 8A0A0000 04030047 30450221 0084C089 AE0D2BD3
04A1FAF7 27E361A8 8F9C3145 A71E8F80 24BECC0A E25962FC AC022072 04E7044D
5CEB5B80 D3737353 2186F2BD DE8B2A57 701F6D02 D3089039 F110FA30 81FE0603
551D1104 81F63081 F3820D6D 61696C2E 6B6F6D6F 732E7275 820E2A2E 6365732D
6B6F6D6F 732E7275 820E2A2E 6674642E 6B6F6D6F 732E7275 820E2A2E 66746B2E
6B6F6D6F 732E7275 820E2A2E 697A686D 6F6C6F6B 6F2E7275 820A2A2E 697A686D
702E7275 82102A2E 6B616772 6F2E6B6F 6D6F732E 72758210 2A2E6B6F 6D6F732D
67726F75 702E7275 82112A2E 6B6F6D6F 732D696E 666F726D 2E727582 0A2A2E6B
6F6D6F73 2E727582 0D2A2E6D 65617463 6F6D702E 72758211 2A2E6D69 6C6B6F6D
2D6B6F6D 6F732E72 75820E2A 2E6D746B 2D6B6F6D 6F732E72 7582112A 2E73656C
6F2D7A65 6C656E6F 652E7275 820E2A2E 747A6B2E 6B6F6D6F 732E7275 300D0609
2A864886 F70D0101 0B050003 82010100 994B295C 3B944D1D BB4D6F36 A46ABBCA
69FC4D7E CA670906 659F3A44 98D61B34 9B14C179 86C043AE F4B8EA04 1D7C7222
5A432098 BB011AB4 CA7382D7 C3559881 F8D9C361 8B8DDD56 04402632 BCF1DC99
0B3208D6 29CDAAFB C9A573F9 57B14ABF 4A9B029D 271410F5 1ACC293A 72AC4552
5FFDA7B2 47EB39E5 56A10494 E96ADBE6 9D6AA80A 1057F9AA 9C898750 7D8D477A
6ED280DA 3E849164 6879C0F6 4142AB10 1C7B34EA 94E6A366 5E2B1AFA D7C6CC09
A600F322 2C14E057 CA3EC496 BB984A02 7153D15B BC65DCD0 DCAA6866 74E58E8A
9F4B2358 6261F618 1CF31DF2 047F592A 2D37163A 0A662B3D 0D730EDB 6000B4BB
968A4F16 EC858C6A 037C51CC 888E39EF
quit
certificate ca 7D5B5126B476BA11DB74160BBC530DA7
30820613 308203FB A0030201 0202107D 5B5126B4 76BA11DB 74160BBC 530DA730
0D06092A 864886F7 0D01010C 05003081 88310B30 09060355 04061302 55533113
30110603 55040813 0A4E6577 204A6572 73657931 14301206 03550407 130B4A65
72736579 20436974 79311E30 1C060355 040A1315 54686520 55534552 54525553
54204E65 74776F72 6B312E30 2C060355 04031325 55534552 54727573 74205253
41204365 72746966 69636174 696F6E20 41757468 6F726974 79301E17 0D313831
31303230 30303030 305A170D 33303132 33313233 35393539 5A30818F 310B3009
06035504 06130247 42311B30 19060355 04081312 47726561 74657220 4D616E63
68657374 65723110 300E0603 55040713 0753616C 666F7264 31183016 06035504
0A130F53 65637469 676F204C 696D6974 65643137 30350603 55040313 2E536563
7469676F 20525341 20446F6D 61696E20 56616C69 64617469 6F6E2053 65637572
65205365 72766572 20434130 82012230 0D06092A 864886F7 0D010101 05000382
010F0030 82010A02 82010100 D67333D6 D73C20D0 00D21745 B8D63E07 A23FC741
EE3230C9 B06CFDF4 9FCB1298 0F2D3F8D 4D010C82 0F177F62 2EE9B848 79FB1683
4EADD732 2593B707 BFB9503F A94CC340 2AE939FF D981CA1F 163241DA 8026B923
7A87201E E3FF209A 3C95446F 87750690 40B43293 16091008 233ED2DD 870F6F5D
51146A0A 69C54F01 7269CFD3 934C6D04 A0A31B82 7EB19AB9 EDC59EC5 37789F9A
0834FB56 2E58C409 0E06645B BC37DCF1 9F2868A8 56B092A3 5C9FBB88 98081B24
1DAB3085 AEAFB02E 9E7A9DC1 C0421CE2 02F0EAE0 4AD2EF90 0EB4C140 16F06F85
424A64F7 A430A0FE BF2EA327 5A8E8B58 B8ADC319 178463ED 6F56FD83 CB6034C4
74BEE69D DBE1E4E5 CA0C5F15 02030100 01A38201 6E308201 6A301F06 03551D23
04183016 80145379 BF5AAA2B 4ACF5480 E1D89BC0 9DF2B203 66CB301D 0603551D
0E041604 148D8C5E C454AD8A E177E99B F99B05E1 B8018D61 E1300E06 03551D0F
0101FF04 04030201 86301206 03551D13 0101FF04 08300601 01FF0201 00301D06
03551D25 04163014 06082B06 01050507 03010608 2B060105 05070302 301B0603
551D2004 14301230 06060455 1D200030 08060667 810C0102 01305006 03551D1F
04493047 3045A043 A041863F 68747470 3A2F2F63 726C2E75 73657274 72757374
2E636F6D 2F555345 52547275 73745253 41436572 74696669 63617469 6F6E4175
74686F72 6974792E 63726C30 7606082B 06010505 07010104 6A306830 3F06082B
06010505 07300286 33687474 703A2F2F 6372742E 75736572 74727573 742E636F
6D2F5553 45525472 75737452 53414164 64547275 73744341 2E637274 30250608
2B060105 05073001 86196874 74703A2F 2F6F6373 702E7573 65727472 7573742E
636F6D30 0D06092A 864886F7 0D01010C 05000382 02010032 BF61BD0E 48C34FC7
BA474DF8 9C781901 DC131D80 6FFCC370 B4529A31 339A5752 FB319E6B A4EF54AA
898D4017 68F81110 7CD2CAB1 F15586C7 EEB33691 86F63951 BF46BF0F A0BAB4F7
7E49C42A 36179EE4 68397AAF 944E566F B27B3BBF 0A86BDCD C5771C03 B838B1A2
1F5F7EDB 8ADC4648 B6680ACF B2B5B4E2 34E467A9 3866095E D2B8FC9D 283A1740
27C2724E 29FD213C 7CCF13FB 962CC531 44FD13ED D59BA969 68777CEE E1FFA4F9
36380853 39A28434 9C19F3BE 0EACD524 37EB23A8 78D0D3E7 EF924764 623922EF
C6F711BE 2285C666 4424268E 10328DC8 93AE079E 833E2FD9 F9F5468E 63BEC1E6
B4DCA6CD 21A8860A 95D92E85 261AFDFC B1B65742 6D95D133 F6391406 824138F5
8F58DC80 5BA4D57D 9578FDA7 9BFFFDC5 A869AB26 E7A7A405 875BA9B7 B8A3200B
97A94585 DDB38BE5 89378E29 0DFC0617 F638400E 42E41206 FB7BF3C6 116862DF
E398F413 D8154F8B B169D910 60BC642A EA31B7E4 B5A33A14 9B26E30B 7BFD028E
B699C138 975936F6 A874A286 B65EEBC6 64EACFA0 A3F96E9E BA2D11B6 86980858
2DC9AC25 64F25E75 B438C1AE 7F5A4683 EA51CAB6 F1991135 6BA56A7B C600B0E7
F8BE64B2 ADC8C2F1 ACE351EA A493E079 C8E18140 C90A5BE1 123CC160 2AE397C0
8942CA94 CF469812 69BB98D0 C2D30D72 4B476EE5 93C43228 638743E4 B0323E0A
D34BBF23 9B142941 2B9A041F 932DF1C7 39483CAD 5A127F
quit
crypto pki certificate chain VPNPFV_KOMOS_RU_2023
certificate 2A5EAB726A4EB4250FB6F883
30820699 30820581 A0030201 02020C2A 5EAB726A 4EB4250F B6F88330 0D06092A
864886F7 0D01010B 05003050 310B3009 06035504 06130242 45311930 17060355
040A1310 476C6F62 616C5369 676E206E 762D7361 31263024 06035504 03131D47
6C6F6261 6C536967 6E205253 41204F56 2053534C 20434120 32303138 301E170D
32323035 32363134 31353133 5A170D32 33303632 37313431 3531325A 305D310B
30090603 55040613 02525531 0F300D06 03550408 0C064D6F 73636F77 310F300D
06035504 070C064D 6F73636F 77311430 12060355 040A0C0B 4B4F4D4F 53204752
55505031 16301406 03550403 0C0D6D61 696C2E6B 6F6D6F73 2E727530 82012230
0D06092A 864886F7 0D010101 05000382 010F0030 82010A02 82010100 B3AAF65C
591925C8 D486F4BF 6069B2BE 65E711AD 4A048377 D82DC5D1 EA2019EA 48A2522A
A3AF18EC 9FB75631 4C113EE3 1E5F0B54 3F24D89E AA410F8D FC75BD30 CBD0E6F8
BB188642 9A75C4B2 B37EBA56 21E65446 63424FDF A544CEA3 EA145645 9A1F0861
D35EF609 72F9C83A 71A74828 E11C865C F707C114 AE3E5CE5 507D0A07 C0D75410
A1F3A2A1 F331CB25 169CAFC9 45B175BD B8B1C382 308F6753 BFEADE05 4086C7D8
467073D1 0CECAE04 D7C4976B EA989DF9 7E052AF0 B753CC42 F329A784 315EC537
81497F30 F4CC2107 620B387F 39E545DA DFC03F93 DBCB9249 5A08F32B 23976FA0
82997EDE 5AB32633 B25E9250 87D1563A 0301ED6C D6418896 F3B2F42D 02030100
01A38203 64308203 60300E06 03551D0F 0101FF04 04030205 A030818E 06082B06
01050507 01010481 81307F30 4406082B 06010505 07300286 38687474 703A2F2F
73656375 72652E67 6C6F6261 6C736967 6E2E636F 6D2F6361 63657274 2F677372
73616F76 73736C63 61323031 382E6372 74303706 082B0601 05050730 01862B68
7474703A 2F2F6F63 73702E67 6C6F6261 6C736967 6E2E636F 6D2F6773 7273616F
7673736C 63613230 31383056 0603551D 20044F30 4D304106 092B0601 0401A032
01143034 30320608 2B060105 05070201 16266874 7470733A 2F2F7777 772E676C
6F62616C 7369676E 2E636F6D 2F726570 6F736974 6F72792F 30080606 67810C01
02023009 0603551D 13040230 00307906 03551D11 04723070 820D6D61 696C2E6B
6F6D6F73 2E727582 0E2A2E63 65732D6B 6F6D6F73 2E727582 102A2E6B 6F6D6F73
2D67726F 75702E72 75820A2A 2E6B6F6D 6F732E72 7582112A 2E6D696C 6B6F6D2D
6B6F6D6F 732E7275 82112A2E 73656C6F 2D7A656C 656E6F65 2E727582 0B2A2E76
6F73746F 632E7275 301D0603 551D2504 16301406 082B0601 05050703 0106082B
06010505 07030230 1F060355 1D230418 30168014 F8EF7FF2 CD7867A8 DE6F8F24
8D88F187 0302B3EB 301D0603 551D0E04 160414C8 D671DDFC A376913B 2B3C542A
6FAD7323 90A16B30 82017E06 0A2B0601 0401D679 02040204 82016E04 82016A01
68007600 E83ED0DA 3EF50635 32E75728 BC896BC9 03D3CBD1 116BECEB 69E1777D
6D06BD6E 00000181 00B8B8B5 00000403 00473045 02205D08 B5F819D4 E2EBE5F2
243C1E6A D420AF77 22C5AF30 982FBE60 0DAE95F6 DDA80221 00A8AA61 F122DCCE
CF441E9D 4114547B D94E83C2 AA721AAD 41921966 A328EBA3 2C007700 6F5376AC
31F03119 D89900A4 5115FF77 151C11D9 02C10029 068DB208 9A37D913 00000181
00B8B8A6 00000403 00483046 022100D0 0AD56CAA FB2E9A24 D903B9FF 6E8F5305
2016EA5A 02A9E039 6916B200 F1B52402 21008A43 1E10571D 81137797 C7005B1E
2BB1E35C 9D0D0F22 6C780BDD C9A62620 D9940075 00B37377 07E18450 F86386D6
05A9DC11 094A792D B1670C0B 87DCF003 0E7936A5 9A000001 8100B8B8 D3000004
03004630 4402201E 70621E80 9A36990E 9FFC1C80 AB4885F0 9757EF73 21E810FD
91E0E9C7 66E3E302 206A50F3 45FAD344 BE550198 764A210B 7127BCA6 756F1A17
730ABE13 27A68026 99300D06 092A8648 86F70D01 010B0500 03820101 006A7B95
B1446135 56190E98 4E160D7B 229FD6EC 8015D03A CA23EE37 C4D1E266 99BD1F66
5C58A1CE 61FE0C7A 3AF10757 9807EE5A FF9CE930 88180265 F8D1E73F 4AED3DE8
F62E897D 6A04F6F1 DA93C8AA 3BCDF662 6C72515A 11A1EFB1 843301DE DC0C8FA4
8090B542 18ED3990 AF130E26 3B8D718D 393AD761 0EAA60A6 78777CD1 357CE4C1
EEAC2DC6 ACF530B2 656DEFB0 7C5B7708 B6899215 181627BC 4CACE11B E58698A0
F1541B25 262C2A4D BDE6830B 1665D386 667BE4B5 3D41EE67 B6091E00 E205F0E4
D676F5B3 6C605B42 7E5154E3 CA70F4A8 7B85F281 DE584332 BDE42B53 03B02637
23219873 E4F02F05 AB3F3BA3 B14FFAD1 2FF5D552 7BE5463A 5ADDF514 1F
quit
certificate ca 01EE5F221DFC623BD4333A8557
3082044E 30820336 A0030201 02020D01 EE5F221D FC623BD4 333A8557 300D0609
2A864886 F70D0101 0B050030 4C312030 1E060355 040B1317 476C6F62 616C5369
676E2052 6F6F7420 4341202D 20523331 13301106 0355040A 130A476C 6F62616C
5369676E 31133011 06035504 03130A47 6C6F6261 6C536967 6E301E17 0D313831
31323130 30303030 305A170D 32383131 32313030 30303030 5A305031 0B300906
03550406 13024245 31193017 06035504 0A131047 6C6F6261 6C536967 6E206E76
2D736131 26302406 03550403 131D476C 6F62616C 5369676E 20525341 204F5620
53534C20 43412032 30313830 82012230 0D06092A 864886F7 0D010101 05000382
010F0030 82010A02 82010100 A75AC9D5 0C182100 23D5970F EBAEDD5C 686B6B8F
5060137A 81CB97EE 8E8A6194 4B2679F6 04A72AFB A4DA56BB EEA0A4F0 7B8A7F55
1F479361 0D6E7151 3A252408 2F8CE1F7 89D692CF AFB3A73F 30EDB5DF 21AEFEF5
4417FDD8 63D92FD3 815A6B5F D347B0AC F2AB3B24 794F1FC7 2EEAB915 3A7C184C
69B3B520 59095E29 C363E62E 465BAA94 90490EB9 F0F54AA1 092F7C34 4DD0BC00
C5065579 06CEA2D0 10F14843 E8B95AB5 9555BD31 D21B3D86 BEA1EC0D 12DB2C99
24AD47C2 6F03E67A 70B570CC CD272CA5 8C8EC218 3C92C92E 736F0610 569340AA
A3C552FB E5C505D6 69685C06 B9EE5189 E18A0E41 4D9B9290 0A89E916 6BEFEF75
BE7A46B8 E3478A1D 1C2EA74F 02030100 01A38201 29308201 25300E06 03551D0F
0101FF04 04030201 86301206 03551D13 0101FF04 08300601 01FF0201 00301D06
03551D0E 04160414 F8EF7FF2 CD7867A8 DE6F8F24 8D88F187 0302B3EB 301F0603
551D2304 18301680 148FF04B 7FA82E45 24AE4D50 FA639A8B DEE2DD1B BC303E06
082B0601 05050701 01043230 30302E06 082B0601 05050730 01862268 7474703A
2F2F6F63 7370322E 676C6F62 616C7369 676E2E63 6F6D2F72 6F6F7472 33303606
03551D1F 042F302D 302BA029 A0278625 68747470 3A2F2F63 726C2E67 6C6F6261
6C736967 6E2E636F 6D2F726F 6F742D72 332E6372 6C304706 03551D20 0440303E
303C0604 551D2000 30343032 06082B06 01050507 02011626 68747470 733A2F2F
7777772E 676C6F62 616C7369 676E2E63 6F6D2F72 65706F73 69746F72 792F300D
06092A86 4886F70D 01010B05 00038201 01009990 C82D5F42 8AD40B66 DB980373
11D48886 5228538A FBADDFFD 738E3A67 04DBC353 14701409 7CC3E0F8 D71C981A
A2C43EDB E900E3CA 70B2F122 302156DB D3AD795E 81580B6D 148035F5 6F5D1DEB
9A4705FF 598D00B1 40DA9098 961ABA6C 6D7F8CF5 B380DF8C 64733696 79796974
EABFF89E 018FA095 698DE984 BAE9E5D4 8838DB78 3B98D036 7B29B0D2 521890DE
524300AE 6A27C814 9E8695AC E1803130 7E9A25BB 8BAC0423 A69900E8 F1D226EC
0F7E3B8A 2B923813 1D8F86CD 865247E6 347C5BA4 023E8A61 7C227653 5A945333
86B892A8 72AFA1F9 52871F31 A5FCB081 572FCDF4 CEDCF624 CFA7E234 90689DFE
AAF1A99A 12CC9BC0 C6C3A8A5 B0217EDE 48F6
quit
voice-card 0
!
!
!
!
!
!
!
!
license udi pid CISCO2911R-V/K9 sn JTV2030TJBR
license accept end user agreement
license boot module c2900 technology-package securityk9
!
!
archive
log config
logging enable
logging size 200
notify syslog contenttype plaintext
hidekeys
path tftp://tftp/IZH/VRS/PFV-RT/$H.$T.conf
write-memory
time-period 10080
object-group network NET_MLK
description :: MILKOM_DATACENTER
host 85.140.32.177
host 78.85.14.98
host 213.87.95.1
!
object-group network NET_VPF
description VOTKINSKAYA_PF
host 88.80.33.14
host 78.85.13.118
!
object-group network NET_IPF
description IZHEVSKAYA_PF
host 85.140.32.141
host 78.85.13.117
!
object-group network NET_KOMOSGROUP
host 88.80.33.50
91.240.179.0 255.255.255.0
host 62.141.96.126
host 94.25.46.122
host 88.80.33.10
host 5.227.124.143
host 84.201.247.190
!
object-group network NET_MPF
description MENDELEEVSAYA_PF
host 178.47.130.10
host 5.227.121.127
!
object-group network NET_IZH_MLK
description --IZHMOLOKO--
host 78.85.13.42
host 85.140.32.27
host 31.173.105.54
host 217.14.195.253
host 84.201.247.157
!
object-group network NET_PS_PF
host 5.227.121.127
host 46.232.164.108
host 78.85.13.117
host 78.85.13.118
host 78.85.13.119
host 78.85.14.98
host 78.85.33.50
host 85.140.32.141
host 85.140.32.177
host 85.140.32.178
host 88.80.33.14
host 95.215.208.234
host 178.47.130.10
host 178.205.241.114
!
object-group network NET_DMVPN_NBRS
group-object NET_MLK
group-object NET_VPF
group-object NET_IPF
group-object NET_KOMOSGROUP
group-object NET_MPF
group-object NET_IZH_MLK
group-object NET_PS_PF
!
object-group network NET_KOMENERGO
description :: KOMOS_ENERGO
host 92.55.54.109
host 83.143.54.246
host 77.222.40.133
host 178.79.148.203
!
object-group network NET_REMOTE_MANAGERS
host 91.146.62.155
host 213.87.95.1
host 92.241.255.114
!
object-group network NET_UPF
description :: UDMURTSKAYA_PF
host 88.80.33.162
host 212.46.204.74
host 146.120.104.227
host 95.215.208.234
!
object-group network NET_RT_VATS
host 178.45.249.116
!
object-group network NET_REMOTE_SITES
group-object NET_VPF
group-object NET_UPF
group-object NET_MPF
group-object NET_IPF
group-object NET_KOMENERGO
group-object NET_KOMOSGROUP
group-object NET_IZH_MLK
group-object NET_RT_VATS
!
object-group network NET_RUK_USERS
group-object NET_REMOTE_SITES
host 213.87.95.1
host 78.85.18.142
host 78.85.18.104
!
object-group network OBJ_BBN_RN_BBN
host 85.140.32.104
host 78.85.13.205
!
object-group network OBJ_BBN_VST_BBN
host 85.140.32.103
host 83.169.220.204
!
object-group network OBJ_IZH_MLK_IZM
host 85.140.32.27
host 78.85.13.42
host 5.227.126.169
host 31.173.105.54
host 217.14.195.253
host 85.175.86.74
!
object-group network OBJ_IZH_KG_P11
91.240.179.0 255.255.255.0
host 5.227.124.143
host 78.85.13.93
host 62.141.96.126
host 84.201.247.190
host 88.80.33.50
host 94.25.46.122
range 91.240.179.1 91.240.179.254
!
object-group network OBJ_IZH_VST_IZM
host 5.227.124.82
host 78.85.13.38
!
object-group network OBJ_IZH_TK_M44
host 212.46.204.74
host 88.80.33.162
!
object-group network OBJ_IZH_TK_M48
host 87.249.237.250
!
object-group network OBJ_IZH_TK_SMR
host 87.249.239.226
host 88.80.33.42
!
object-group network OBJ_MSK_KG_MSK
host 185.62.195.150
host 185.6.175.101
!
object-group network OBJ_GLZ_MLK_GMK
host 31.173.105.62
host 85.140.32.29
!
object-group network OBJ_KZN_MLK_KMK
host 83.69.126.54
host 94.180.253.210
host 78.138.171.82
!
object-group network OBJ_KEZ_MLK_KZS
host 31.173.105.66
host 78.85.13.52
host 85.140.32.30
!
object-group network OBJ_PRM_MLK_PHK
host 178.47.128.18
host 46.146.210.68
!
object-group network OBJ_SAR_MLK_SRM
host 31.173.105.58
host 78.85.13.53
host 85.140.32.28
!
object-group network OBJ_CLB_MLK_CMK
host 37.113.128.241
host 149.255.6.35
!
object-group network OBJ_GLZ_GKZ_GKZ
host 78.85.13.94
host 146.120.104.181
!
object-group network OBJ_KIA_RN_KIA
host 78.85.14.97
!
object-group network OBJ_IZH_TZK_TZK
host 78.25.80.134
host 5.227.124.235
!
object-group network OBJ_IZH_MK_VS17
host 5.227.124.141
!
object-group network OBJ_IZH_KL_KLI
host 78.85.15.85
host 84.201.247.24
host 79.175.36.97
host 84.201.244.235
!
object-group network OBJ_EKB_KG_EKB
host 62.168.232.182
host 176.215.14.11
!
object-group network OBJ_IZH_KEN_VS56
host 83.143.54.246
host 92.55.54.109
!
object-group network OBJ_IZH_VRS_IZM
host 85.140.32.177
host 78.85.14.98
host 213.87.95.1
host 92.241.255.114
!
object-group network OBJ_GLZ_VRS_UPF
host 95.215.208.234
host 78.85.13.119
!
object-group network OBJ_IZH_VRS_IPF
host 85.140.32.141
host 78.85.13.117
!
object-group network OBJ_IZH_VRS_PFV
host 85.140.32.178
host 94.181.119.90
host 78.85.33.50
!
object-group network OBJ_VOT_VRS_VPF
host 78.85.13.118
host 88.80.33.14
!
object-group network OBJ_MSB_TMA_MSB
host 78.138.182.214
!
object-group network OBJ_KIB_TMA_KIB
host 78.138.182.126
!
object-group network OBJ_PRM_VRS_MPF
host 178.47.130.10
host 5.227.121.127
!
object-group network OBJ_LAI_VRS_DPF
host 178.205.241.114
host 46.232.164.108
!
object-group network OBJ_SHM_TMA_SHM
host 89.232.91.106
host 31.173.182.210
!
object-group network OBJ_EVL_TMA_EVL
host 89.232.102.166
!
object-group network OBJ_ITL_VST_ITL
host 5.227.124.130
host 78.85.34.99
host 81.211.13.82
!
object-group network OBJ_MZH_VST_MZH
host 88.80.33.250
host 83.169.220.171
!
object-group network OBJ_KIA_VST_KIA
host 85.140.32.24
host 188.94.168.238
!
object-group network OBJ_KGB_VST_KBB
host 78.85.37.88
host 88.80.33.154
!
object-group network OBJ_SAR_VST_SMK
host 78.85.19.93
host 88.80.33.234
!
object-group network OBJ_KNK_VST_KMK
host 178.161.242.67
!
object-group network OBJ_IZH_KM_S61
host 84.201.247.32
host 88.80.33.194
!
object-group network OBJ_YAN_GKZ_YEL
host 77.94.97.222
!
object-group network OBJ_KUN_KMK_B2
94.138.150.0 255.255.255.0
!
object-group network OBJ_KUN_KMK_H80
host 178.161.207.26
host 77.43.193.88
!
object-group network OBJ_KUN_KMK_CH9
host 178.47.128.98
host 194.150.90.20
!
object-group network OBJ_KGB_RN_KGB
host 78.85.13.165
!
object-group network OBJ_NCH_RN_NCH
host 78.85.13.166
!
object-group network OBJ_PRI_RN_PRI
host 78.85.13.167
!
object-group network OBJ_URN_RN_URN
host 78.85.20.49
!
object-group network OBJ_MZH_TK_TKM
host 88.80.32.230
host 78.85.35.34
!
object-group network OBJ_GLZ_TK_TKG
host 95.215.208.240
host 146.120.104.235
host 95.215.208.173
!
object-group network OBJ_IZH_TK_M21
host 84.201.242.133
!
object-group network OBJ_IZH_HLA_PP
host 92.61.17.250
!
object-group network OBJ_IZH_HLA_UHK
host 92.55.7.148
!
object-group network OBJ_IZH_VD_VS17
host 84.201.247.100
!
object-group network OBJ_IZH_KS_H17
85.140.32.64 255.255.255.252
host 85.140.32.63
host 85.140.32.68
!
object-group network OBJ_IZH_VRS_AKS
host 5.227.124.50
host 87.249.233.80
!
object-group network OBJ_SPB_KG_SPB
host 62.141.114.190
host 94.72.27.43
!
object-group network OBJ_BRANCHES
group-object OBJ_IZH_MLK_IZM
group-object OBJ_IZH_KG_P11
group-object OBJ_IZH_VST_IZM
group-object OBJ_IZH_TK_M44
group-object OBJ_IZH_TK_M48
group-object OBJ_IZH_TK_SMR
group-object OBJ_MSK_KG_MSK
group-object OBJ_GLZ_MLK_GMK
group-object OBJ_KZN_MLK_KMK
group-object OBJ_KEZ_MLK_KZS
group-object OBJ_PRM_MLK_PHK
group-object OBJ_SAR_MLK_SRM
group-object OBJ_CLB_MLK_CMK
group-object OBJ_BBN_RN_BBN
group-object OBJ_GLZ_GKZ_GKZ
group-object OBJ_KIA_RN_KIA
group-object OBJ_IZH_TZK_TZK
group-object OBJ_IZH_MK_VS17
group-object OBJ_IZH_KL_KLI
group-object OBJ_EKB_KG_EKB
group-object OBJ_IZH_KEN_VS56
group-object OBJ_IZH_VRS_IZM
group-object OBJ_GLZ_VRS_UPF
group-object OBJ_IZH_VRS_IPF
group-object OBJ_IZH_VRS_PFV
group-object OBJ_VOT_VRS_VPF
group-object OBJ_MSB_TMA_MSB
group-object OBJ_KIB_TMA_KIB
group-object OBJ_PRM_VRS_MPF
group-object OBJ_LAI_VRS_DPF
group-object OBJ_BBN_VST_BBN
group-object OBJ_SHM_TMA_SHM
group-object OBJ_EVL_TMA_EVL
group-object OBJ_ITL_VST_ITL
group-object OBJ_MZH_VST_MZH
group-object OBJ_KIA_VST_KIA
group-object OBJ_KGB_VST_KBB
group-object OBJ_SAR_VST_SMK
group-object OBJ_KNK_VST_KMK
group-object OBJ_IZH_KM_S61
group-object OBJ_YAN_GKZ_YEL
group-object OBJ_KUN_KMK_B2
group-object OBJ_KUN_KMK_H80
group-object OBJ_KUN_KMK_CH9
group-object OBJ_KGB_RN_KGB
group-object OBJ_NCH_RN_NCH
group-object OBJ_PRI_RN_PRI
group-object OBJ_URN_RN_URN
group-object OBJ_MZH_TK_TKM
group-object OBJ_GLZ_TK_TKG
group-object OBJ_IZH_TK_M21
group-object OBJ_IZH_HLA_PP
group-object OBJ_IZH_HLA_UHK
group-object OBJ_IZH_VD_VS17
group-object OBJ_IZH_KS_H17
group-object OBJ_IZH_VRS_AKS
group-object OBJ_SPB_KG_SPB
!
object-group network STATIC_ISP_IP
host 85.140.32.178
host 94.181.119.90
!
object-group service SVC_ANYCONNECT
tcp eq 443
tcp eq 3000
!
object-group service SVC_EMAIL
tcp eq smtp
tcp eq 26
tcp eq 587
tcp eq pop3
tcp eq 143
tcp eq 993
tcp eq 465
tcp eq 995
!
object-group service SVC_SNMP
udp eq snmp
udp eq snmptrap
!
username menshikov privilege 15 secret 5 $1$jKjV$FRCadPiBRpyUc8/VTp5ks.
username menshikov aaa attribute list ANYCONNECT_ADMINISTRATORS
username prozorov privilege 0 secret 5 $1$qMdD$CelXDP6HGiupqBFimhdJ//
username prozorov aaa attribute list ANYCONNECT_ADMINISTRATORS
username kirillov_sl privilege 2 secret 5 $1$TbOV$ddr4JoAfGqW9elInRfo7d1
username kirillov_sl aaa attribute list ANYCONNECT_USERS
username chistiakova_ia privilege 2 secret 5 $1$72Nf$NA19CgiYe4G1XrbqPPvFK/
username chistiakova_ia aaa attribute list ANYCONNECT_USERS
username prokosheva_oi privilege 2 secret 5 $1$5PDC$aB.lJLHssZq7Qwcz0M/FG.
username prokosheva_oi aaa attribute list ANYCONNECT_USERS
username krasilnikov_ev privilege 2 secret 5 $1$NzLN$7L3s/2G9DvAaixjn3q.ja1
username krasilnikov_ev aaa attribute list ANYCONNECT_ADMINISTRATORS
username simakov_dn privilege 2 secret 5 $1$p/se$w7ndGBLSUpnP6RoFfrMsc1
username simakov_dn aaa attribute list ANYCONNECT_USERS
username merzlyakov_aa privilege 2 secret 5 $1$HM6g$IlJYziMWwTjvOA28deL.T.
username merzlyakov_aa aaa attribute list ANYCONNECT_USERS
username pecherskikh_io privilege 2 secret 5 $1$icVW$/jmd/lCp1Cwx.q5JUY8V21
username pecherskikh_io aaa attribute list ANYCONNECT_USERS
username bukhaltsev_kn privilege 2 secret 5 $1$ttaz$3/0CmsN1kDhJAM7v3XlrS.
username bukhaltsev_kn aaa attribute list ANYCONNECT_USERS
username nemtsov_va privilege 2 secret 5 $1$sQFr$WwdyUPsQ.DNzpXpkibYG3/
username nemtsov_va aaa attribute list ANYCONNECT_USERS
username avis privilege 2 secret 5 $1$/lTO$LobqhTkmHBhEI3Uk2OFJj.
username avis aaa attribute list ANYCONNECT_USERS
username drygailo_ai privilege 2 secret 5 $1$5NF4$r3fXIyYxzUTB1ChfyhfDS0
username drygailo_ai aaa attribute list ANYCONNECT_USERS
username melnikova_mv privilege 2 secret 5 $1$bTpA$cnXcsrIFb38ngH.K6ixu9/
username melnikova_mv aaa attribute list ANYCONNECT_USERS
username permiakov_dd privilege 2 secret 5 $1$t3ua$jf4RNeY6Npj5Vyy4U7iRJ.
username permiakov_dd aaa attribute list ANYCONNECT_USERS
username araslanov_am privilege 2 secret 5 $1$..ie$80d1Np30rxzkobdKdE32B1
username araslanov_am aaa attribute list ANYCONNECT_USERS
username merzlyakova_av privilege 2 secret 5 $1$5EUS$UnVNfV97KSkIlky4dphie0
username merzlyakova_av aaa attribute list ANYCONNECT_USERS
username moshev_ag privilege 2 secret 5 $1$cr/5$X3gi3Hn/yWI2.3F7Rrquf1
username moshev_ag aaa attribute list ANYCONNECT_ADMINISTRATORS
username karelin_yua privilege 2 secret 5 $1$DXeK$VzM.Pnc5hlY0.L6L/rwJt/
username karelin_yua aaa attribute list ANYCONNECT_USERS_TO_MILK_SRV-T2
username nikiforova_si privilege 2 secret 5 $1$GB/c$4LIBOhrWbv8FssPSgHHNT1
username nikiforova_si aaa attribute list ANYCONNECT_USERS
username moiseevskix_en privilege 2 secret 5 $1$lpPG$X5lBVCZ0Zt1M18rlEEJ4K1
username moiseevskix_en aaa attribute list ANYCONNECT_USERS
username kramchaninov_pi privilege 2 secret 5 $1$hD5D$/ennoxLU8PM18NHQsTbi80
username kramchaninov_pi aaa attribute list ANYCONNECT_USERS
username netadmin privilege 15 secret 5 $1$m/mQ$KqBYDbB13GiR.2/Iu3sru/
username budzivula_in privilege 2 secret 5 $1$EUKN$klq7.waVBOeNnbEt24eUU.
username budzivula_in aaa attribute list ANYCONNECT_USERS
username popova_ov privilege 2 secret 5 $1$6FcF$ajO82ooxdf0JKrf.XAVpS1
username popova_ov aaa attribute list ANYCONNECT_USERS
username tiunova_ei privilege 2 secret 5 $1$FzhJ$9zve7ex.iNND6v1ShnAJr/
username tiunova_ei aaa attribute list ANYCONNECT_USERS
username kurochkin_ol privilege 2 secret 5 $1$DrNj$OozDUcZs31u9aJSTFBYI20
username kurochkin_ol aaa attribute list ANYCONNECT_USERS
username akhmetzyanovrr privilege 15 secret 5 $1$4ajK$8IhQ.F/zgk6iATjBybsWg/
username samerkhanova_rr privilege 2 secret 5 $1$tlPT$NIVGxaDrdveu9gghAoGyX/
username samerkhanova_rr aaa attribute list ANYCONNECT_USERS
username lozhkina_ev privilege 2 secret 5 $1$D80f$SNwO1445dX1lxid30n4Pv.
username lozhkina_ev aaa attribute list ANYCONNECT_USERS
username vasileva_ip privilege 2 secret 5 $1$5Z/1$51JFhbhCvcMV.VAZMtZGV.
username vasileva_ip aaa attribute list ANYCONNECT_USERS
username tretiakova_oa privilege 2 secret 5 $1$Es5N$9byzcb.CDzBKQrdBxh1bh/
username tretiakova_oa aaa attribute list ANYCONNECT_USERS
username izotov_da privilege 2 secret 5 $1$KjJ.$nS/UitFVgHQtQyXHQb.6N0
username izotov_da aaa attribute list ANYCONNECT_USERS
username KlimovNP privilege 2 secret 5 $1$hpBZ$6Pk7PUqhWWUKAU/vEfy30.
username KlimovNP aaa attribute list ANYCONNECT_ADMINISTRATORS
username Zakharova_EM privilege 2 secret 5 $1$2qNF$KdmAq5Qu1WEFbelTmJGAI0
username Zakharova_EM aaa attribute list ANYCONNECT_USERS
username pozmogova_gr privilege 2 secret 5 $1$NYM2$oRkqa3INO.DyB4hpkUnAm1
username pozmogova_gr aaa attribute list ANYCONNECT_USERS
username pfd privilege 2 secret 5 $1$v3yh$pWlx4DwwpcyNfMomeEghx1
username pfd aaa attribute list ANYCONNECT_USERS
username shakina_ai privilege 2 secret 5 $1$6Coz$siakt7ZFhALMV77Q/f9Oh/
username shakina_ai aaa attribute list ANYCONNECT_USERS
username Pupyreva_AI privilege 2 secret 5 $1$.vRN$gxNJ8.5OFmkPMBpggIF0T1
username Pupyreva_AI aaa attribute list ANYCONNECT_USERS
username matveevaan privilege 2 secret 5 $1$xJ6U$K21Zb2.FZfQfKSD.JFyNI0
username matveevaan aaa attribute list ANYCONNECT_USERS
username petrova_nn privilege 2 secret 5 $1$uYfa$JjjW2VF2/BYcCNYyUF5g61
username petrova_nn aaa attribute list ANYCONNECT_USERS
username shakirov_di privilege 2 secret 5 $1$IfgB$owkJG4NI3xTRw0Ys/PGuR1
username shakirov_di aaa attribute list ANYCONNECT_USERS
username galieva_li privilege 2 secret 5 $1$wFcp$MsNZSOY8.WifTyivcNEWp1
username galieva_li aaa attribute list ANYCONNECT_USERS
username Pianov_A privilege 2 secret 5 $1$TpE7$3mpsr6IjZJnq.HeNEGaOK0
username Pianov_A aaa attribute list ANYCONNECT_USERS
username Ivanov_E privilege 2 secret 5 $1$gjdb$JpUtjp/y1RekWo5mWpXAp0
username Ivanov_E aaa attribute list ANYCONNECT_USERS
username nasretdinova_ar privilege 2 secret 5 $1$xtqE$ymmKvHjZeLWop9lx0Fi181
username nasretdinova_ar aaa attribute list ANYCONNECT_USERS
username shishkina_em privilege 2 secret 5 $1$ulag$.KtUITQ6aedaEPKWDn/Bc.
username shishkina_em aaa attribute list ANYCONNECT_USERS
username shakirova_gi privilege 2 secret 5 $1$oOru$msSjGUY2IDAgxcylKY8.u0
username shakirova_gi aaa attribute list ANYCONNECT_USERS
username Galaida_O privilege 2 secret 5 $1$kQaW$lMTHntzRz2Ju0uQAf7Eca.
username Galaida_O aaa attribute list ANYCONNECT_USERS
username Idrisova_EI privilege 2 secret 5 $1$IPvV$.q8SQ0KcuVjOHuAfc4lBg/
username Idrisova_EI aaa attribute list ANYCONNECT_USERS
username tsd_vrs privilege 2 secret 5 $1$4opL$qws4DhApFzOkNfnjzmsjE1
username tsd_vrs aaa attribute list ANYCONNECT_USERS
username Volkova_AA privilege 2 secret 5 $1$sBGI$io6P3F/2XKqtNIk89GQsc/
username Volkova_AA aaa attribute list ANYCONNECT_USERS
username merzliakov_in privilege 2 secret 5 $1$tsXX$r7fMymeCeMTmZ9RIwh8gf/
username merzliakov_in aaa attribute list ANYCONNECT_USERS
username oseeva_en privilege 2 secret 5 $1$9SKC$DUnrY/oxFIvbB3jfGqCcA1
username oseeva_en aaa attribute list ANYCONNECT_USERS
username egorochkina_es privilege 2 secret 5 $1$uElO$GUOCNxa5oLxBKTu7FEP5z0
username egorochkina_es aaa attribute list ANYCONNECT_USERS
username CHastikova_AA privilege 2 secret 5 $1$3vfq$xTZbbk8mwD3a6CqF42HZp0
username CHastikova_AA aaa attribute list ANYCONNECT_USERS
username Sineokov_A privilege 2 secret 5 $1$iVHs$Q6bGqN5mYzSbJzruaBLdT/
username Sineokov_A aaa attribute list ANYCONNECT_USERS
username merzliakova_gk privilege 2 secret 5 $1$N1mm$m5URNxpqV2Y0GpC41IEIU0
username merzliakova_gk aaa attribute list ANYCONNECT_USERS
username Galieva_OA privilege 2 secret 5 $1$ke5D$wwy5XdvJifASK24tfdLor/
username Galieva_OA aaa attribute list ANYCONNECT_USERS
username Bazhenova_EIU privilege 2 secret 5 $1$b5fH$rpLZqna5e5YC6CeFG/89B1
username Bazhenova_EIU aaa attribute list ANYCONNECT_USERS
username Riabova_A privilege 2 secret 5 $1$b8Te$buEp7mL8/jd3EAn01.q3X1
username Riabova_A aaa attribute list ANYCONNECT_USERS
username glumovami privilege 2 secret 5 $1$Zlfj$hAZnERgMIGivMVkejT2sz/
username glumovami aaa attribute list ANYCONNECT_ADMINISTRATORS
username ivanenko_sa privilege 2 secret 5 $1$D6Jz$k1GK/LzvihGWjyLJEa8fO0
username ivanenko_sa aaa attribute list ANYCONNECT_USERS
username burmistrov_va privilege 2 secret 5 $1$fGnB$/ZLVNdt1RLj8TIVBsiYjt1
username burmistrov_va aaa attribute list ANYCONNECT_USERS
username mikryukova_aa privilege 2 secret 5 $1$6Czj$aEbJSmg4yqqXpzEd2L5X01
username mikryukova_aa aaa attribute list ANYCONNECT_USERS
username mileshchova_ov privilege 2 secret 5 $1$f/pQ$shjUDXhhaG1V.hXDVo5lm0
username mileshchova_ov aaa attribute list ANYCONNECT_USERS
username holmogorovasm privilege 2 secret 5 $1$TNJF$ISonivoyV.ZFu8OdYiPGR/
username holmogorovasm aaa attribute list ANYCONNECT_USERS
username Artamonova_IA privilege 2 secret 5 $1$v9B8$GGGKB1ij0oIx/mieMt.EY/
username Artamonova_IA aaa attribute list ANYCONNECT_USERS
username Sidorova_NM privilege 2 secret 5 $1$JBs2$RiDe5Ge/ufwH1CHdAefWx1
username Sidorova_NM aaa attribute list ANYCONNECT_USERS
username osinkina_aa privilege 2 secret 5 $1$blDa$ZsZYMeecXCRudRzZbajgn.
username osinkina_aa aaa attribute list ANYCONNECT_USERS
username Ryabchenko_IN privilege 2 secret 5 $1$h23G$BYvr7DaF4BMku5Kkh3E7E0
username Ryabchenko_IN aaa attribute list ANYCONNECT_USERS
username timofeeva_va privilege 2 secret 5 $1$fctr$oXbjSeZ68X9qNgMCPVgbi0
username timofeeva_va aaa attribute list ANYCONNECT_USERS
username Shalamov_AI privilege 2 secret 5 $1$Y3Ht$8IxkolDk2S.45PI1YSTfL0
username Shalamov_AI aaa attribute list ANYCONNECT_USERS
!
redundancy
!
!
!
!
!
track 1 ip sla 1 reachability
delay down 26 up 11
!
!
crypto logging session
!
crypto vpn anyconnect flash0:/webvpn/anyconnect-win-4.3.05017-k9.pkg sequence 1
!
crypto vpn anyconnect flash0:/webvpn/anyconnect-linux-64-4.3.05017-k9.pkg sequence 2
!
crypto vpn anyconnect flash0:/webvpn/anyconnect-macosx-i386-4.3.05017-k9.pkg sequence 3
!
crypto isakmp policy 150
encr aes
authentication pre-share
group 2
crypto isakmp key mlk20kom19 address 0.0.0.0 no-xauth
crypto isakmp keepalive 30
crypto isakmp nat keepalive 10
!
!
crypto ipsec transform-set CRYPTO_TS_DMVPN esp-aes esp-sha-hmac
mode transport
!
crypto ipsec profile CRYPTO_IPSEC_DMVPN
description --SPOKE_TO_SITE_DMVPN_IPSEC_GRE--
set transform-set CRYPTO_TS_DMVPN
!
!
!
!
!
!
!
interface Loopback0
ip address 10.8.20.126 255.255.255.128
!
interface Loopback1
description -== REMOTE SENSOR ==-
ip address 10.1.72.3 255.255.255.255
!
interface Tunnel1
description PRIMARY_CONNECTION_TO_MILKOM
bandwidth 100000
ip address 172.16.254.1 255.255.255.224
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1400
ip flow ingress
ip flow egress
ip nhrp authentication nh10001
ip nhrp map 172.16.254.30 85.140.32.177
ip nhrp map multicast 85.140.32.177
ip nhrp network-id 10001
ip nhrp holdtime 300
ip nhrp nhs 172.16.254.30
ip tcp adjust-mss 1360
tunnel source GigabitEthernet0/0
tunnel mode gre multipoint
tunnel key 12
!
interface Tunnel1001
description --DMVPN_SPOKE_25_CLOUD_1--
ip address 172.30.1.27 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1400
ip flow ingress
ip flow egress
ip nhrp authentication M_K.Cl01
ip nhrp map 172.30.1.1 85.140.32.27
ip nhrp map 172.30.1.2 78.85.13.42
ip nhrp map multicast 85.140.32.27
ip nhrp map multicast 78.85.13.42
ip nhrp network-id 1001
ip nhrp holdtime 300
ip nhrp nhs 172.30.1.1
ip nhrp nhs 172.30.1.2
ip tcp adjust-mss 1360
tunnel source GigabitEthernet0/0
tunnel mode gre multipoint
tunnel key 1001
tunnel protection ipsec profile CRYPTO_IPSEC_DMVPN shared
!
interface Tunnel1002
description --DMVPN_SPOKE_25_CLOUD_2--
ip address 172.30.2.27 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1400
ip flow ingress
ip flow egress
ip nhrp authentication M_K.Cl02
ip nhrp map 172.30.2.1 5.227.124.143
ip nhrp map 172.30.2.2 78.85.13.93
ip nhrp map multicast 5.227.124.143
ip nhrp map multicast 78.85.13.93
ip nhrp network-id 1002
ip nhrp holdtime 300
ip nhrp nhs 172.30.2.1
ip nhrp nhs 172.30.2.2
ip tcp adjust-mss 1360
tunnel source GigabitEthernet0/0
tunnel mode gre multipoint
tunnel key 1002
tunnel protection ipsec profile CRYPTO_IPSEC_DMVPN shared
!
interface Embedded-Service-Engine0/0
no ip address
shutdown
!
interface GigabitEthernet0/0
description ISP_MTS
ip address 85.140.32.178 255.255.255.0
ip access-group ACL_FIREWALL in
ip access-group ACL_LAN_TO_WAN out
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip flow egress
ip nat outside
ip virtual-reassembly in
load-interval 30
duplex auto
speed auto
no cdp enable
!
interface GigabitEthernet0/1
description ISP_ERTELECOM
ip address 94.181.119.90 255.255.255.0
ip access-group ACL_FIREWALL in
ip access-group ACL_LAN_TO_WAN out
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat outside
ip virtual-reassembly in
shutdown
duplex auto
speed auto
!
interface GigabitEthernet0/2
description LOCAL_NETWORK
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly in
duplex auto
speed auto
!
interface GigabitEthernet0/2.300
description NETWORK_MANAGEMENT
encapsulation dot1Q 300
ip address 10.8.21.251 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip virtual-reassembly in
standby version 2
standby 300 ip 10.8.21.253
standby 300 timers 5 15
standby 300 priority 50
standby 300 preempt delay minimum 30
standby 300 authentication pfv2017
standby 300 name NM-HSRP
!
interface GigabitEthernet0/2.555
description --BGP_TRANSIT--
encapsulation dot1Q 555
ip address 172.30.30.161 255.255.255.248
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Virtual-Template1
ip unnumbered Loopback0
!
router bgp 64525
bgp router-id 172.30.30.161
bgp log-neighbor-changes
bgp graceful-restart
aggregate-address 10.8.16.0 255.255.240.0
redistribute connected route-map RM_BGP_REDISTR_CON
neighbor PG_BGP_OCOD peer-group
neighbor PG_BGP_OCOD remote-as 64512
neighbor PG_BGP_OCOD next-hop-self
neighbor PG_BGP_OCOD soft-reconfiguration inbound
neighbor PG_BGP_OCOD route-map RM_BGP_TO_HUB out
neighbor PG_BGP_RCOD peer-group
neighbor PG_BGP_RCOD remote-as 64513
neighbor PG_BGP_RCOD next-hop-self
neighbor PG_BGP_RCOD soft-reconfiguration inbound
neighbor PG_BGP_RCOD route-map RM_BGP_TO_HUB out
neighbor PG_BGP_IPF peer-group
neighbor PG_BGP_IPF remote-as 64526
neighbor PG_BGP_IPF next-hop-self
neighbor PG_BGP_IPF soft-reconfiguration inbound
neighbor PG_BGP_IPF prefix-list PFL_FROM_IPF in
neighbor PG_BGP_IPF prefix-list PFL_TO_IPF out
neighbor PG_BGP_MLK peer-group
neighbor PG_BGP_MLK remote-as 64523
neighbor PG_BGP_MLK next-hop-self
neighbor PG_BGP_MLK soft-reconfiguration inbound
neighbor PG_BGP_MLK prefix-list PFL_TO_MLK out
neighbor PG_BGP_MLK route-map RM_FROM_MLK in
neighbor PG_BGP_VRS_AKS peer-group
neighbor PG_BGP_VRS_AKS remote-as 64553
neighbor PG_BGP_VRS_AKS soft-reconfiguration inbound
neighbor 172.16.254.30 peer-group PG_BGP_MLK
neighbor 172.30.1.1 peer-group PG_BGP_OCOD
neighbor 172.30.1.1 route-map RM_BGP_FROM_HUB in
neighbor 172.30.1.2 peer-group PG_BGP_OCOD
neighbor 172.30.1.2 route-map RM_TO_COD in
neighbor 172.30.1.23 peer-group PG_BGP_MLK
neighbor 172.30.1.29 peer-group PG_BGP_IPF
neighbor 172.30.1.30 peer-group PG_BGP_IPF
neighbor 172.30.1.74 peer-group PG_BGP_VRS_AKS
neighbor 172.30.1.75 peer-group PG_BGP_VRS_AKS
neighbor 172.30.2.1 peer-group PG_BGP_RCOD
neighbor 172.30.2.1 route-map RM_BGP_FROM_HUB in
neighbor 172.30.2.2 peer-group PG_BGP_RCOD
neighbor 172.30.2.2 route-map RM_BGP_FROM_HUB in
neighbor 172.30.2.23 peer-group PG_BGP_MLK
neighbor 172.30.2.29 peer-group PG_BGP_IPF
neighbor 172.30.2.30 peer-group PG_BGP_IPF
neighbor 172.30.2.74 peer-group PG_BGP_VRS_AKS
neighbor 172.30.2.75 peer-group PG_BGP_VRS_AKS
neighbor 172.30.30.162 remote-as 64525
neighbor 172.30.30.162 next-hop-self
neighbor 172.30.30.162 soft-reconfiguration inbound
neighbor 172.30.30.163 remote-as 64525
neighbor 172.30.30.163 next-hop-self
neighbor 172.30.30.163 soft-reconfiguration inbound
distance bgp 150 150 150
!
ip local policy route-map RM_SELF
ip local pool ANYCONNECT_POOL 10.8.20.1 10.8.20.125
ip forward-protocol nd
!
no ip http server
no ip http secure-server
ip flow-export source GigabitEthernet0/2.300
ip flow-export version 5
ip flow-export destination 10.4.0.215 9995
ip flow-export destination 10.4.0.217 9995
ip flow-top-talkers
top 10
sort-by bytes
cache-timeout 20000
!
ip tftp source-interface GigabitEthernet0/2.300
ip nat translation timeout 450
ip nat translation tcp-timeout 300
ip nat translation pptp-timeout 1800
ip nat translation udp-timeout 45
ip nat translation dns-timeout 5
ip nat translation port-timeout tcp 110 60
ip nat translation port-timeout tcp 25 60
ip nat translation port-timeout tcp 80 15
ip nat translation port-timeout udp 5060 180
ip nat translation max-entries all-host 400
ip nat inside source route-map ISP_MTS interface GigabitEthernet0/0 overload
ip route 0.0.0.0 0.0.0.0 85.140.32.1
ip route 85.140.32.177 255.255.255.255 85.140.32.1
ip route 192.168.0.0 255.255.252.0 10.8.21.254
ip ssh version 2
ip ssh server algorithm encryption aes128-ctr aes192-ctr aes256-ctr
ip ssh client algorithm encryption aes128-ctr aes192-ctr aes256-ctr
!
ip access-list standard ACL_ACCESS_NET
permit 192.168.0.0 0.0.3.255
permit 10.8.16.0 0.0.1.255
permit 10.8.21.0 0.0.0.255
ip access-list standard ACL_ANYCONNECT_SPLIT
permit 192.168.1.39
permit 192.168.1.38
permit 192.168.72.192 0.0.0.63
permit 192.168.72.0 0.0.0.63
ip access-list standard ACL_NTP_CLIENTS
permit 192.168.0.0 0.0.3.255
ip access-list standard ACL_NTP_SERVERS
permit 172.16.254.30
deny any
ip access-list standard ACL_SPLIT_ADMIN
permit 192.168.0.0 0.0.3.255
permit 192.168.72.0 0.0.0.255
permit 10.1.72.0 0.0.0.255
permit 10.8.32.0 0.0.0.255
permit 10.8.40.0 0.0.0.255
permit 10.8.16.0 0.0.1.255
permit 10.8.48.0 0.0.0.255
permit 10.8.56.0 0.0.0.255
permit 10.8.20.0 0.0.0.255
permit 10.8.21.0 0.0.0.255
!
ip access-list extended ACL_FIREWALL
permit ip object-group OBJ_BRANCHES object-group STATIC_ISP_IP
permit udp any eq ntp object-group STATIC_ISP_IP
permit icmp any any unreachable
permit icmp any any echo-reply
permit icmp any any packet-too-big
permit icmp any any time-exceeded
permit icmp any any traceroute
permit icmp any any administratively-prohibited
permit icmp any any echo
permit object-group SVC_ANYCONNECT any object-group STATIC_ISP_IP
permit tcp object-group NET_KOMENERGO object-group STATIC_ISP_IP eq 50001
permit tcp host 5.227.120.65 object-group STATIC_ISP_IP eq 50001
permit tcp object-group NET_KOMENERGO object-group STATIC_ISP_IP eq 33822
permit object-group SVC_EMAIL any object-group STATIC_ISP_IP
permit tcp object-group NET_RUK_USERS object-group STATIC_ISP_IP eq 1838
evaluate reflectedtraffic
permit tcp host 178.45.249.116 object-group STATIC_ISP_IP
permit udp host 178.45.249.116 object-group STATIC_ISP_IP
ip access-list extended ACL_LAN_TO_WAN
permit ip any any reflect reflectedtraffic timeout 300
ip access-list extended ACL_WEBVPN_TO_MILK_PORT3389
permit udp any host 192.168.72.39 eq 3389
permit tcp any host 192.168.72.39 eq 3389
!
!
ip prefix-list PFL_BGP_REDISTR_CON seq 10 permit 10.0.0.0/8 le 24
ip prefix-list PFL_BGP_REDISTR_CON seq 20 permit 10.8.20.0/25
!
ip prefix-list PFL_FROM_IPF seq 10 permit 172.16.23.0/24
ip prefix-list PFL_FROM_IPF seq 20 permit 10.8.32.0/21
!
ip prefix-list PFL_FROM_MLK seq 10 permit 192.168.72.0/24 le 26
!
ip prefix-list PFL_TO_HUB seq 10 permit 10.8.16.0/20
!
ip prefix-list PFL_TO_IPF seq 10 permit 172.16.3.0/24
ip prefix-list PFL_TO_IPF seq 20 permit 10.8.16.0/20
!
ip prefix-list PFL_TO_MLK seq 10 permit 10.8.16.0/23
!
ip prefix-list PL_TO_COD seq 5 permit 10.4.0.0/24
ip sla 1
icmp-echo 85.140.32.1 source-interface GigabitEthernet0/0
threshold 2
timeout 2000
frequency 5
ip sla schedule 1 life forever start-time now
kron occurrence EveryDay at 1:30 recurring
policy-list SaveBackup
!
kron occurrence off_webvpn_23-59 at 23:59 recurring
policy-list off_webvpn_23-59
!
kron policy-list SaveBackup
cli write memory
!
kron policy-list off_webvpn_23-59
cli clear webvpn session context all
!
logging trap debugging
logging source-interface GigabitEthernet0/2.300
logging host 192.168.72.34
logging host 10.8.16.100
logging host 10.4.244.4
!
route-map RM_BGP_REDISTR_CON permit 10
match ip address prefix-list PFL_BGP_REDISTR_CON PFL_TO_IPF
!
route-map RM_FROM_MLK permit 10
match ip address prefix-list PFL_FROM_MLK
set local-preference 1500
!
route-map RM_TO_COD permit 10
match ip address prefix-list PL_TO_COD
set local-preference 1100
!
route-map RM_TO_COD permit 20
!
route-map RM_BGP_TO_HUB permit 10
match ip address prefix-list PFL_TO_HUB
!
route-map ISP_ERTELECOM permit 10
match ip address ACL_ACCESS_NET
match interface GigabitEthernet0/1
!
route-map RM_SELF permit 10
match ip address 98
set ip next-hop 85.140.32.1
!
route-map RM_SELF permit 20
match ip address 99
set ip next-hop 94.181.119.254
!
route-map RM_BGP_FROM_HUB permit 10
set local-preference 1000
!
route-map ISP_MTS permit 10
match ip address ACL_ACCESS_NET
match interface GigabitEthernet0/0
!
!
snmp-server community public RO
snmp-server community lmTUEsk6Yvlv RO
access-list 98 permit 85.140.32.178
access-list 99 permit 94.181.119.90
!
radius server IZH-RDS002
address ipv4 10.4.0.248 auth-port 1645 acct-port 1646
timeout 3
retransmit 2
key 7 082955452F3824373A0C553C732D372738022A46164E14044C1A1E6D55570F311F4354537B794D58395E14546A72533204176F182C18256E703B3C3631560E2654
!
radius server IZH-RDS003
address ipv4 10.1.122.248 auth-port 1645 acct-port 1646
timeout 3
retransmit 2
key 7 020E1D502D272E01644950215C1101040733227E357024303850412802585A705149580A2B330E556A52410167715C7A04146C442E0402266539233C07084B2349
!
!
!
control-plane
!
!
!
!
!
!
mgcp behavior rsip-range tgcp-only
mgcp behavior comedia-role none
mgcp behavior comedia-check-media-src disable
mgcp behavior comedia-sdp-force disable
!
mgcp profile default
!
!
!
!
!
!
!
gatekeeper
shutdown
!
!
vstack
alias exec q exit
!
line con 0
logging synchronous
login authentication CONSOLE
speed 115200
line aux 0
line 2
no activation-character
no exec
transport preferred none
transport output pad telnet rlogin lapb-ta mop udptn v120 ssh
stopbits 1
line vty 0 4
exec-timeout 120 0
privilege level 15
logging synchronous
length 0
transport input ssh
line vty 5 15
exec-timeout 120 0
privilege level 15
logging synchronous
transport input ssh
!
scheduler allocate 20000 1000
ntp logging
ntp access-group peer ACL_NTP_SERVERS
ntp access-group serve-only ACL_NTP_CLIENTS
ntp master 4
ntp update-calendar
ntp server 172.16.254.30
!
!
webvpn gateway ANYCONNECT-WEBVPN-GATEWAY
ip interface GigabitEthernet0/0 port 443
ssl encryption aes128-sha1 aes256-sha1 rsa-dhe-aes256-sha1
ssl trustpoint VPNPFV_KOMOS_RU_2023
logging enable
inservice
dtls port 3000
!
webvpn context ANYCONNECT-WEBVPN
aaa authentication list sslvpn
aaa authorization list sslvpn
gateway ANYCONNECT-WEBVPN-GATEWAY
logging enable
!
ssl authenticate verify all
inservice
!
policy group WEBVPN_POLICY_ADMINISTRATORS
functions svc-enabled
svc address-pool "ANYCONNECT_POOL" netmask 255.255.255.128
svc default-domain "varaksino.local"
svc rekey method new-tunnel
svc split include acl ACL_SPLIT_ADMIN
svc dns-server primary 10.8.17.100
svc dns-server secondary 10.8.17.101
!
policy group WEBVPN_POLICY_USERS
functions svc-enabled
svc address-pool "ANYCONNECT_POOL" netmask 255.255.255.128
svc default-domain "varaksino.local"
svc rekey method new-tunnel
svc split include 192.168.72.0 255.255.255.192
svc dns-server primary 10.8.17.100
svc dns-server secondary 192.168.72.59
!
policy group WEBVPN_POLICY_TO_MILK_PORT3389
functions svc-enabled
svc address-pool "ANYCONNECT_POOL" netmask 255.255.255.128
svc rekey method new-tunnel
svc split include 192.168.72.39 255.255.255.255
default-group-policy WEBVPN_POLICY_USERS
!
end