628 lines
10 KiB
Plaintext
628 lines
10 KiB
Plaintext
Building configuration...
|
|
|
|
Current configuration : 10734 bytes
|
|
!
|
|
! Last configuration change at 21:27:26 MSK Fri Jun 24 2022 by akhmetzyanovrr_adm
|
|
! NVRAM config last updated at 21:28:54 MSK Fri Jun 24 2022 by akhmetzyanovrr_adm
|
|
!
|
|
version 15.0
|
|
no service pad
|
|
service timestamps debug datetime msec localtime show-timezone year
|
|
service timestamps log datetime msec localtime show-timezone year
|
|
no service password-encryption
|
|
!
|
|
hostname IZH-MLK-IZM-SW-1-2
|
|
!
|
|
boot-start-marker
|
|
boot-end-marker
|
|
!
|
|
logging userinfo
|
|
logging buffered 128000
|
|
enable secret 5 $1$8Ye.$2052cyes0PP1QlT7T0Qcu0
|
|
!
|
|
username root privilege 15 secret 5 $1$HLqM$tdwAkQGuE3HAs7XnKDg4O1
|
|
username netadmin privilege 15 secret 5 $1$tJvO$MSgnDj5VPBpeZapA1Uz4m/
|
|
aaa new-model
|
|
!
|
|
!
|
|
aaa group server radius NPS
|
|
server name IZH-RDS002
|
|
server name P11-RDS003
|
|
ip radius source-interface Vlan300
|
|
load-balance method least-outstanding
|
|
!
|
|
aaa authentication login default group NPS local enable
|
|
aaa authentication login CONSOLE local group NPS
|
|
aaa authorization console
|
|
aaa authorization exec default group NPS local if-authenticated
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
aaa session-id common
|
|
clock timezone MSK 4 0
|
|
switch 1 provision ws-c3750x-48
|
|
switch 2 provision ws-c3750x-48
|
|
system mtu routing 9100
|
|
no ip source-route
|
|
no ip gratuitous-arps
|
|
!
|
|
!
|
|
no ip domain-lookup
|
|
ip domain-name milkom-komos.ru
|
|
ip host tftp 10.4.0.214
|
|
ip name-server 192.168.8.200
|
|
ip name-server 192.168.8.201
|
|
login on-failure log
|
|
login on-success log
|
|
vtp mode off
|
|
!
|
|
!
|
|
!
|
|
license boot level ipservices
|
|
license boot level ipservices switch 1
|
|
archive
|
|
log config
|
|
logging enable
|
|
logging size 900
|
|
notify syslog contenttype plaintext
|
|
hidekeys
|
|
path tftp://tftp/IZH/3750/$H
|
|
write-memory
|
|
time-period 10080
|
|
!
|
|
!
|
|
!
|
|
!
|
|
spanning-tree mode pvst
|
|
spanning-tree logging
|
|
spanning-tree extend system-id
|
|
spanning-tree vlan 1-4094 priority 8192
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
vlan internal allocation policy ascending
|
|
!
|
|
vlan 8
|
|
name --UserNet_8.0/24--
|
|
!
|
|
vlan 9
|
|
name --UserNet_9.0/24--
|
|
!
|
|
vlan 10
|
|
name --UserNet_10.0/24--
|
|
!
|
|
vlan 11
|
|
name --UserNet_11.0/24--
|
|
!
|
|
vlan 12
|
|
name --UserNet_12.0/24--
|
|
!
|
|
vlan 13
|
|
name --UserNet_13.0/24--
|
|
!
|
|
vlan 14
|
|
name --UserNet_14.0/24--
|
|
!
|
|
vlan 15
|
|
name --UserNet_15.0/24--
|
|
!
|
|
vlan 16
|
|
name --UserNet_16.0/24--
|
|
!
|
|
vlan 17
|
|
name --UserNet_17.0/24--
|
|
!
|
|
vlan 18
|
|
name --UserNet_18.0/24--
|
|
!
|
|
vlan 19
|
|
name --UserNet_19.0/24--
|
|
!
|
|
vlan 20
|
|
name --UserNet_20.0/24--
|
|
!
|
|
vlan 21
|
|
name swVlan21_Management
|
|
!
|
|
vlan 50
|
|
name RCOD
|
|
!
|
|
vlan 93
|
|
name VideoNetToStolovaya
|
|
!
|
|
vlan 96
|
|
name --ERTELEKOM--
|
|
!
|
|
vlan 99
|
|
name --MARK_ASTERISK--
|
|
!
|
|
vlan 100
|
|
mtu 9000
|
|
!
|
|
vlan 101
|
|
name --PRINTERS--
|
|
!
|
|
vlan 113
|
|
name TRANSIT_TO_MIKROTIK
|
|
!
|
|
vlan 150
|
|
name --Wi-Fi_Users_32.0/24--
|
|
!
|
|
vlan 151
|
|
name --Wi-Fi_Prod_33.0/24--
|
|
!
|
|
vlan 172
|
|
name TelephotiNet
|
|
!
|
|
vlan 173
|
|
name telephonyTest
|
|
!
|
|
vlan 200-201
|
|
!
|
|
vlan 202
|
|
name --DMZ--
|
|
!
|
|
vlan 229
|
|
!
|
|
vlan 248
|
|
name --SANDBOX_ELAR--
|
|
!
|
|
vlan 249
|
|
name --ServTestC_36.0/24--
|
|
!
|
|
vlan 250
|
|
name --ServerNet_0.0/24--
|
|
!
|
|
vlan 251
|
|
name -=ServMail_7.0/28=-
|
|
!
|
|
vlan 252
|
|
name --VOICE_ATS--
|
|
!
|
|
vlan 289
|
|
name -=SRVBakNet_245.0_24=-
|
|
!
|
|
vlan 290
|
|
name -=SrvVmwVMon_242.0/26=-
|
|
!
|
|
vlan 291
|
|
name -=SrvVmwVSan_242.64/26=-
|
|
!
|
|
vlan 292
|
|
name -=SrvBakNet_243.0/24=-
|
|
!
|
|
vlan 294
|
|
name --SRV_iLO_iDrack_etc--
|
|
!
|
|
vlan 299
|
|
name --SrvMng_240.0\24--
|
|
!
|
|
vlan 300
|
|
name --MANAGMENT--
|
|
!
|
|
vlan 301
|
|
name --Wi-Fi_MANAGMENT--
|
|
!
|
|
vlan 302
|
|
name -=Wi-Fi_MANAGMENT=-
|
|
!
|
|
vlan 350
|
|
name --VOICE_28.0/24--
|
|
!
|
|
vlan 500
|
|
name --Wi-Fi_Guest_35.0/24--
|
|
!
|
|
vlan 550
|
|
name --CISCO_ASA--
|
|
!
|
|
vlan 551
|
|
name --TRANSIT_HSRP--
|
|
!
|
|
vlan 597
|
|
name TRANSIT_TO_ISR4431
|
|
!
|
|
vlan 599
|
|
name --MTS_KOMOS_599--
|
|
!
|
|
vlan 601
|
|
name --KMK_PRODACTION--
|
|
!
|
|
vlan 650
|
|
name --ISCSI--
|
|
!
|
|
vlan 666
|
|
name NOT_ROUTED
|
|
!
|
|
vlan 1000
|
|
name --ELAR-TEST--
|
|
!
|
|
vlan 4030
|
|
name --MTS_KOMOS_4030--
|
|
!
|
|
vlan 4031
|
|
name -VeamRepl_172.31.31.0/24-
|
|
!
|
|
vlan 4032
|
|
name -SQLRepl_172.31.33.0/24-
|
|
!
|
|
vlan 4033
|
|
name -SrvVCHA_172.31.33.0/24-
|
|
!
|
|
vlan 4034
|
|
name -ExchRepl_172.31.34.0/24-
|
|
!
|
|
vlan 4035
|
|
name -SrvVCMg_172.31.35.0/24-
|
|
!
|
|
ip ssh authentication-retries 2
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
interface Port-channel1
|
|
description [CORE] SW-1-1
|
|
switchport trunk encapsulation dot1q
|
|
switchport mode trunk
|
|
!
|
|
interface FastEthernet0
|
|
no ip address
|
|
shutdown
|
|
!
|
|
interface GigabitEthernet1/0/1
|
|
description [SRV] bkp008_eth1
|
|
switchport access vlan 292
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet1/0/2
|
|
description [SRV] bkp008_eth3
|
|
switchport access vlan 289
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet1/0/3
|
|
!
|
|
interface GigabitEthernet1/0/4
|
|
!
|
|
interface GigabitEthernet1/0/5
|
|
!
|
|
interface GigabitEthernet1/0/6
|
|
!
|
|
interface GigabitEthernet1/0/7
|
|
!
|
|
interface GigabitEthernet1/0/8
|
|
!
|
|
interface GigabitEthernet1/0/9
|
|
!
|
|
interface GigabitEthernet1/0/10
|
|
!
|
|
interface GigabitEthernet1/0/11
|
|
!
|
|
interface GigabitEthernet1/0/12
|
|
!
|
|
interface GigabitEthernet1/0/13
|
|
!
|
|
interface GigabitEthernet1/0/14
|
|
!
|
|
interface GigabitEthernet1/0/15
|
|
!
|
|
interface GigabitEthernet1/0/16
|
|
!
|
|
interface GigabitEthernet1/0/17
|
|
!
|
|
interface GigabitEthernet1/0/18
|
|
!
|
|
interface GigabitEthernet1/0/19
|
|
!
|
|
interface GigabitEthernet1/0/20
|
|
!
|
|
interface GigabitEthernet1/0/21
|
|
!
|
|
interface GigabitEthernet1/0/22
|
|
!
|
|
interface GigabitEthernet1/0/23
|
|
!
|
|
interface GigabitEthernet1/0/24
|
|
!
|
|
interface GigabitEthernet1/0/25
|
|
!
|
|
interface GigabitEthernet1/0/26
|
|
!
|
|
interface GigabitEthernet1/0/27
|
|
!
|
|
interface GigabitEthernet1/0/28
|
|
!
|
|
interface GigabitEthernet1/0/29
|
|
!
|
|
interface GigabitEthernet1/0/30
|
|
!
|
|
interface GigabitEthernet1/0/31
|
|
!
|
|
interface GigabitEthernet1/0/32
|
|
!
|
|
interface GigabitEthernet1/0/33
|
|
!
|
|
interface GigabitEthernet1/0/34
|
|
!
|
|
interface GigabitEthernet1/0/35
|
|
!
|
|
interface GigabitEthernet1/0/36
|
|
!
|
|
interface GigabitEthernet1/0/37
|
|
!
|
|
interface GigabitEthernet1/0/38
|
|
!
|
|
interface GigabitEthernet1/0/39
|
|
!
|
|
interface GigabitEthernet1/0/40
|
|
switchport trunk encapsulation dot1q
|
|
switchport mode trunk
|
|
!
|
|
interface GigabitEthernet1/0/41
|
|
switchport trunk encapsulation dot1q
|
|
switchport mode trunk
|
|
!
|
|
interface GigabitEthernet1/0/42
|
|
description SHD003_MNGT
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet1/0/43
|
|
description SHD004_MNGT
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet1/0/44
|
|
description SHD007_MNGT
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet1/0/45
|
|
description [SRV] VMW022_ILO
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet1/0/46
|
|
description [SRV] VMW023_ILO
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet1/0/47
|
|
description [SRV] VMW026_ILO
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet1/0/48
|
|
description ILO
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet1/1/1
|
|
!
|
|
interface GigabitEthernet1/1/2
|
|
!
|
|
interface GigabitEthernet1/1/3
|
|
!
|
|
interface GigabitEthernet1/1/4
|
|
!
|
|
interface TenGigabitEthernet1/1/1
|
|
description [CORE] SW-1-1
|
|
switchport trunk encapsulation dot1q
|
|
switchport mode trunk
|
|
channel-group 1 mode active
|
|
!
|
|
interface TenGigabitEthernet1/1/2
|
|
!
|
|
interface GigabitEthernet2/0/1
|
|
description [SRV] bkp008_eth2
|
|
switchport access vlan 250
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet2/0/2
|
|
!
|
|
interface GigabitEthernet2/0/3
|
|
!
|
|
interface GigabitEthernet2/0/4
|
|
!
|
|
interface GigabitEthernet2/0/5
|
|
!
|
|
interface GigabitEthernet2/0/6
|
|
!
|
|
interface GigabitEthernet2/0/7
|
|
!
|
|
interface GigabitEthernet2/0/8
|
|
!
|
|
interface GigabitEthernet2/0/9
|
|
!
|
|
interface GigabitEthernet2/0/10
|
|
!
|
|
interface GigabitEthernet2/0/11
|
|
!
|
|
interface GigabitEthernet2/0/12
|
|
!
|
|
interface GigabitEthernet2/0/13
|
|
!
|
|
interface GigabitEthernet2/0/14
|
|
!
|
|
interface GigabitEthernet2/0/15
|
|
!
|
|
interface GigabitEthernet2/0/16
|
|
!
|
|
interface GigabitEthernet2/0/17
|
|
!
|
|
interface GigabitEthernet2/0/18
|
|
!
|
|
interface GigabitEthernet2/0/19
|
|
!
|
|
interface GigabitEthernet2/0/20
|
|
!
|
|
interface GigabitEthernet2/0/21
|
|
!
|
|
interface GigabitEthernet2/0/22
|
|
!
|
|
interface GigabitEthernet2/0/23
|
|
!
|
|
interface GigabitEthernet2/0/24
|
|
!
|
|
interface GigabitEthernet2/0/25
|
|
!
|
|
interface GigabitEthernet2/0/26
|
|
!
|
|
interface GigabitEthernet2/0/27
|
|
!
|
|
interface GigabitEthernet2/0/28
|
|
!
|
|
interface GigabitEthernet2/0/29
|
|
!
|
|
interface GigabitEthernet2/0/30
|
|
!
|
|
interface GigabitEthernet2/0/31
|
|
!
|
|
interface GigabitEthernet2/0/32
|
|
!
|
|
interface GigabitEthernet2/0/33
|
|
!
|
|
interface GigabitEthernet2/0/34
|
|
!
|
|
interface GigabitEthernet2/0/35
|
|
!
|
|
interface GigabitEthernet2/0/36
|
|
!
|
|
interface GigabitEthernet2/0/37
|
|
!
|
|
interface GigabitEthernet2/0/38
|
|
!
|
|
interface GigabitEthernet2/0/39
|
|
!
|
|
interface GigabitEthernet2/0/40
|
|
!
|
|
interface GigabitEthernet2/0/41
|
|
description [SRV] bkp008-idr
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet2/0/42
|
|
description SHD003_MNGT
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet2/0/43
|
|
description SHD004_MNGT
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet2/0/44
|
|
description SHD007_MNGT
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet2/0/45
|
|
description [SRV] VMW024_ILO
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet2/0/46
|
|
description [SRV] VMW025_ILO
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet2/0/47
|
|
description [SRV] VMW027_ILO
|
|
switchport access vlan 294
|
|
switchport mode access
|
|
!
|
|
interface GigabitEthernet2/0/48
|
|
!
|
|
interface GigabitEthernet2/1/1
|
|
!
|
|
interface GigabitEthernet2/1/2
|
|
!
|
|
interface GigabitEthernet2/1/3
|
|
!
|
|
interface GigabitEthernet2/1/4
|
|
!
|
|
interface TenGigabitEthernet2/1/1
|
|
description [CORE] SW-1-1
|
|
switchport trunk encapsulation dot1q
|
|
switchport mode trunk
|
|
channel-group 1 mode active
|
|
!
|
|
interface TenGigabitEthernet2/1/2
|
|
!
|
|
interface Vlan1
|
|
no ip address
|
|
shutdown
|
|
!
|
|
interface Vlan100
|
|
no ip address
|
|
!
|
|
interface Vlan300
|
|
description --MANAGMENT--
|
|
ip address 10.4.254.253 255.255.255.0
|
|
no ip redirects
|
|
no ip unreachables
|
|
no ip proxy-arp
|
|
!
|
|
ip default-gateway 10.4.254.254
|
|
ip http server
|
|
no ip http secure-server
|
|
!
|
|
!
|
|
logging facility local2
|
|
logging source-interface Vlan300
|
|
logging host 192.168.8.119 transport udp port 5544
|
|
access-list 5 permit 192.168.8.99
|
|
access-list 5 permit 10.2.1.245
|
|
access-list 23 permit any
|
|
access-list 23 deny any log
|
|
!
|
|
snmp-server community lmTUEsk6Yvlv RO
|
|
snmp ifmib ifindex persist
|
|
!
|
|
!
|
|
radius server IZH-RDS002
|
|
address ipv4 10.4.0.248 auth-port 1645 acct-port 1646
|
|
timeout 3
|
|
retransmit 2
|
|
key hykFAA@Hg9X9fsokWh5q8wez#&^a9lIizldHKxlRer3RE7AbsTsJwdB^RESF$eJ0
|
|
!
|
|
radius server P11-RDS003
|
|
address ipv4 10.1.122.248 auth-port 1645 acct-port 1646
|
|
timeout 3
|
|
retransmit 2
|
|
key hykFAA@Hg9X9fsokWh5q8wez#&^a9lIizldHKxlRer3RE7AbsTsJwdB^RESF$eJ0
|
|
!
|
|
!
|
|
!
|
|
line con 0
|
|
logging synchronous
|
|
login authentication CONSOLE
|
|
line vty 0 4
|
|
access-class 23 in
|
|
exec-timeout 120 0
|
|
logging synchronous
|
|
login authentication NPS
|
|
length 0
|
|
transport input ssh
|
|
line vty 5 15
|
|
access-class 23 in
|
|
exec-timeout 120 0
|
|
logging synchronous
|
|
login authentication NPS
|
|
transport input ssh
|
|
!
|
|
ntp server 192.168.8.200
|
|
end |