ansible/backup/files/huawei/IZH-VRS-IZM-SW-1-1.txt

415 lines
9.2 KiB
Plaintext
Raw Normal View History

2025-10-31 08:47:26 +04:00
!Software Version V200R001C00SPC700
!Last configuration was updated at 2022-05-26 13:41:48+04:00 by akhmetzyanovrr_adm
!Last configuration was saved at 2022-05-26 13:41:56+04:00 by akhmetzyanovrr_adm
#
clock timezone UL add 04:00:00
#
sysname milkhuaw0900
#
device board 1 board-type CE6810-24S2Q-LI
device board 2 board-type CE6810-24S2Q-LI
#
drop-profile default
#
dcb pfc
#
dcb ets-profile default
#
dns domain komos.ru
#
vlan batch 200 250 300 to 301 350 400 554 to 555
#
stp mode rstp
#
telnet server disable
telnet ipv6 server disable
#
radius enable
#
diffserv domain default
#
radius server group rad-serv
radius server shared-key-cipher %^%#"{4}+Fm|2Gld`[4`u4N%;~No'O%E~JEo^[HJs{Z(+9\cH9D=l-N8W&:h+BP!|a]%'3x>UY,]!nA3gCSH<|UkAWEyaJq9Sj!,b8^C%^%#
radius server authentication 10.4.0.248 1645 source Vlanif300
radius server authentication 10.1.122.248 1645 source Vlanif300 secondary
radius server retransmit 2
radius server user-name domain-excluded
#
vlan 200
name LAN_Varaksino
#
vlan 250
name LAN_Udm
#
vlan 300
name MGM
#
vlan 301
name vMotion
#
vlan 350
name For_Routers
#
vlan 400
name Management
#
vlan 554
name VRS-IZM_Peering
#
acl number 2000
rule 100 permit
#
aaa
local-user adminssh password irreversible-cipher $1c$<o'x7x6_d>$Ziq30HAS:V{A,2.o';B!h-waR$Dh@5=o)TH7<e4($
local-user adminssh service-type ssh
local-user adminssh level 3
local-user akhmetzyanovrr password irreversible-cipher $1c$';#6)+pfh3$hve_0!RyiT+rkX#3JDt9^~2TG!^rg'"h(S4iINU.$
local-user akhmetzyanovrr service-type ssh
local-user akhmetzyanovrr level 3
local-user netadmin password irreversible-cipher $1c$9+'%L}RSU4$"M'/8eY*V#0S5'4^H]`Rn3BN8h)!_J!whs@tMF\F$
local-user netadmin service-type ssh
local-user netadmin level 3
#
authentication-scheme default
authentication-mode local radius
#
authorization-scheme default
#
accounting-scheme default
#
domain default
radius server group rad-serv
#
domain default_admin
radius server group rad-serv
#
stack
#
stack member 1 domain 10
stack member 1 priority 200
#
stack member 2 domain 10
#
interface Vlanif300
ip address 10.8.64.190 255.255.255.192
#
interface Vlanif400
ip address 192.168.72.220 255.255.255.192
#
interface Vlanif554
description VRS-IZM Peering
ip address 172.30.32.10 255.255.255.252
#
interface Vlanif555
description BGP_TRANSIT
ip address 172.30.30.147 255.255.255.248
#
interface MEth0/0/0
#
interface Eth-Trunk1
description Nod_A
port default vlan 300
mode lacp-static
#
interface Eth-Trunk2
description Nod_B
port default vlan 300
mode lacp-static
#
interface Eth-Trunk4
description [PEER] VRS-IZM Peering
port link-type trunk
port trunk allow-pass vlan 554
stp bpdu-filter enable
mode lacp-static
#
interface Stack-Port1/1
#
interface Stack-Port2/1
#
interface 10GE1/0/1
eth-trunk 1
device transceiver 10GBASE-COPPER
#
interface 10GE1/0/2
eth-trunk 1
device transceiver 10GBASE-COPPER
#
interface 10GE1/0/3
eth-trunk 2
device transceiver 10GBASE-COPPER
#
interface 10GE1/0/4
eth-trunk 2
device transceiver 10GBASE-COPPER
#
interface 10GE1/0/5
description TO_milkdell0901
port link-type trunk
port trunk allow-pass vlan 200 250 300 to 301 400
device transceiver 10GBASE-COPPER
#
interface 10GE1/0/6
description TO_milkdell0902
port link-type trunk
port trunk allow-pass vlan 200 250 300 to 301 400
device transceiver 10GBASE-COPPER
#
interface 10GE1/0/7
description TO_milkdell0903
port link-type trunk
port trunk allow-pass vlan 200 250 300 to 301 400
device transceiver 10GBASE-COPPER
#
interface 10GE1/0/8
port default vlan 400
device transceiver 1000BASE-T
#
interface 10GE1/0/9
#
interface 10GE1/0/10
#
interface 10GE1/0/11
port default vlan 300
device transceiver 10GBASE-COPPER
#
interface 10GE1/0/12
device transceiver 10GBASE-FIBER
#
interface 10GE1/0/13
port default vlan 200
device transceiver 1000BASE-T
#
interface 10GE1/0/14
device transceiver 10GBASE-FIBER
#
interface 10GE1/0/15
#
interface 10GE1/0/16
#
interface 10GE1/0/17
#
interface 10GE1/0/18
description Mgmt_NOD_A
port default vlan 400
device transceiver 1000BASE-T
#
interface 10GE1/0/19
description iDr_dell0901
port default vlan 400
device transceiver 1000BASE-T
#
interface 10GE1/0/20
description iDr_dell0902
port default vlan 400
device transceiver 1000BASE-T
#
interface 10GE1/0/21
port default vlan 400
device transceiver 1000BASE-T
#
interface 10GE1/0/22
description Men_milkdell0901
port default vlan 400
device transceiver 1000BASE-T
#
interface 10GE1/0/23
description Men_milkdell0902
port default vlan 400
device transceiver 1000BASE-T
#
interface 10GE1/0/24
description [CORE] RT-1-2
port link-type trunk
port trunk allow-pass vlan 200 250 300 350 400 555
device transceiver 1000BASE-T
#
interface 10GE2/0/1
eth-trunk 1
device transceiver 10GBASE-COPPER
#
interface 10GE2/0/2
eth-trunk 1
device transceiver 10GBASE-COPPER
#
interface 10GE2/0/3
eth-trunk 2
device transceiver 10GBASE-COPPER
#
interface 10GE2/0/4
eth-trunk 2
device transceiver 10GBASE-COPPER
#
interface 10GE2/0/5
description TO_milkdell0901
port link-type trunk
port trunk allow-pass vlan 200 250 300 to 301 400
device transceiver 10GBASE-COPPER
#
interface 10GE2/0/6
description TO_milkdell0902
port link-type trunk
port trunk allow-pass vlan 200 250 300 to 301 400
device transceiver 10GBASE-COPPER
#
interface 10GE2/0/7
description TO_milkdell0903
port link-type trunk
port trunk allow-pass vlan 200 250 300 to 301 400
device transceiver 10GBASE-COPPER
#
interface 10GE2/0/8
port default vlan 400
device transceiver 1000BASE-T
#
interface 10GE2/0/9
#
interface 10GE2/0/10
#
interface 10GE2/0/11
port default vlan 300
device transceiver 10GBASE-COPPER
#
interface 10GE2/0/12
device transceiver 10GBASE-COPPER
#
interface 10GE2/0/13
description [PEER] ET4 VRS-IZM Peering
eth-trunk 4
device transceiver 1000BASE-X
#
interface 10GE2/0/14
#
interface 10GE2/0/15
#
interface 10GE2/0/16
#
interface 10GE2/0/17
device transceiver 1000BASE-T
#
interface 10GE2/0/18
description Mgmt_NOD_B
port default vlan 400
device transceiver 1000BASE-T
#
interface 10GE2/0/19
device transceiver 1000BASE-T
#
interface 10GE2/0/20
device transceiver 1000BASE-T
#
interface 10GE2/0/21
port default vlan 400
device transceiver 1000BASE-T
#
interface 10GE2/0/22
description iDr_dell0903
port default vlan 400
device transceiver 1000BASE-T
#
interface 10GE2/0/23
description Men_milkdell0903
port default vlan 400
device transceiver 1000BASE-T
#
interface 10GE2/0/24
description [CORE] RT-1-1
port link-type trunk
port trunk allow-pass vlan 200 250 300 350 400 555
device transceiver 1000BASE-T
#
interface 40GE1/0/1
port mode stack
stack-port 1/1
port crc-statistics trigger error-down
device transceiver 40GBASE-COPPER
#
interface 40GE1/0/2
port mode stack
stack-port 1/1
port crc-statistics trigger error-down
device transceiver 40GBASE-COPPER
#
interface 40GE2/0/1
port mode stack
stack-port 2/1
port crc-statistics trigger error-down
device transceiver 40GBASE-COPPER
#
interface 40GE2/0/2
port mode stack
stack-port 2/1
port crc-statistics trigger error-down
device transceiver 40GBASE-COPPER
#
interface NULL0
#
bgp 64523
graceful-restart
peer 172.30.30.145 as-number 64523
peer 172.30.30.146 as-number 64523
peer 172.30.32.9 as-number 64512
peer 172.30.32.9 description IZH-MLK-IZM-SW-1-1
#
ipv4-family unicast
network 10.8.64.0 255.255.248.0
peer 172.30.30.145 enable
peer 172.30.30.145 next-hop-local
peer 172.30.30.146 enable
peer 172.30.30.146 next-hop-local
peer 172.30.32.9 enable
peer 172.30.32.9 route-policy RP_FROM_IZM-P2P import
peer 172.30.32.9 route-policy RP_TO_IZM-P2P export
peer 172.30.32.9 next-hop-local
#
route-policy RP_FROM_IZM-P2P permit node 10
if-match ip-prefix PL_FROM_IZM-P2P
apply local-preference 1500
#
route-policy RP_TO_IZM-P2P permit node 10
#
ip ip-prefix PL_FROM_IZM-P2P index 10 permit 10.1.0.0 16 greater-equal 16 less-equal 32
ip ip-prefix PL_FROM_IZM-P2P index 20 permit 10.4.0.0 16 greater-equal 16 less-equal 32
ip ip-prefix PL_FROM_IZM-P2P index 30 permit 192.168.0.0 22
#
ip route-static 0.0.0.0 0.0.0.0 192.168.72.254
ip route-static 10.8.64.0 255.255.248.0 NULL0 preference 255
#
snmp-agent
snmp-agent local-engineid 800007DB0384A9C4CEA9F1
snmp-agent community read cipher %^%#lnlc&>9~X()U%2J9Fc&E[Q#eO4ZLX(M=jdImd>rA8QzSAQcz98/A]*TL~~B%SvF#,8/09A@Sp\1rO"96%^%#
#
snmp-agent sys-info location Izhevsk,V. Shosse,178
snmp-agent sys-info version v2c v3
#
lldp enable
#
stelnet server enable
ssh authentication-type default password
ssh user adminssh
ssh user adminssh authentication-type password
ssh user adminssh service-type all
ssh user akhmetzyanovrr
ssh user akhmetzyanovrr authentication-type password
ssh user akhmetzyanovrr service-type all
ssh user netadmin
ssh user netadmin authentication-type password
ssh user netadmin service-type all
ssh authorization-type default aaa
#
ssh server cipher aes256_ctr aes128_ctr
ssh server hmac sha2_256_96 sha2_256 sha1_96
ssh server key-exchange dh_group_exchange_sha256 dh_group_exchange_sha1 ecdh_sha2_nistp256 ecdh_sha2_nistp384 ecdh_sha2_nistp521 sm2_kep
#
user-interface con 0
authentication-mode password
set authentication password cipher $1c$mn646e^9*O$$)Mq,8`H]Rh=Bz!7Qs33TF2b3p$t}DW]H9J50WG-$
#
user-interface vty 0 4
authentication-mode aaa
user privilege level 3
protocol inbound ssh
#
vm-manager
#
return