673 lines
16 KiB
Plaintext
673 lines
16 KiB
Plaintext
Building configuration...
|
|
|
|
Current configuration : 16314 bytes
|
|
!
|
|
! Last configuration change at 04:01:32 MSK Mon Mar 1 1993
|
|
! NVRAM config last updated at 01:00:01 MSK Thu Jul 28 2022
|
|
!
|
|
version 15.2
|
|
no service pad
|
|
service timestamps debug datetime msec localtime show-timezone year
|
|
service timestamps log datetime msec localtime show-timezone year
|
|
no service password-encryption
|
|
!
|
|
hostname IZH-KG-P11-SW-5-1
|
|
!
|
|
boot-start-marker
|
|
boot-end-marker
|
|
!
|
|
logging buffered 512000 informational
|
|
enable secret 5 $1$qCd9$uloO8wrV9.uU.5eUO10f4.
|
|
!
|
|
username netadmin privilege 15 secret 5 $1$9PFX$WQItW0MreSTJia7GjqmgY.
|
|
aaa new-model
|
|
!
|
|
!
|
|
aaa group server radius NPS
|
|
server name IZH-RDS002
|
|
server name P11-RDS003
|
|
load-balance method least-outstanding
|
|
!
|
|
aaa authentication login default group NPS local enable
|
|
aaa authentication login CONSOLE local group NPS
|
|
aaa authorization exec default group NPS local if-authenticated
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
aaa session-id common
|
|
clock timezone MSK 4 0
|
|
system mtu routing 1500
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
no ip source-route
|
|
no ip gratuitous-arps
|
|
!
|
|
!
|
|
ip dhcp snooping vlan 2,12,150-151,351,500
|
|
ip dhcp snooping
|
|
no ip domain-lookup
|
|
ip domain-name komos.ru
|
|
ip host tftp 10.4.0.214
|
|
ip host VM-KG-NET 10.1.12.70
|
|
login on-failure log
|
|
login on-success log
|
|
!
|
|
crypto pki trustpoint TP-self-signed-1196895872
|
|
enrollment selfsigned
|
|
subject-name cn=IOS-Self-Signed-Certificate-1196895872
|
|
revocation-check none
|
|
rsakeypair TP-self-signed-1196895872
|
|
!
|
|
!
|
|
crypto pki certificate chain TP-self-signed-1196895872
|
|
certificate self-signed 01
|
|
3082022B 30820194 A0030201 02020101 300D0609 2A864886 F70D0101 05050030
|
|
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
|
|
69666963 6174652D 31313936 38393538 3732301E 170D3933 30333031 30303031
|
|
32305A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
|
|
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 31393638
|
|
39353837 3230819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
|
|
8100D508 3F8303C6 7334E4B0 9155FD61 31E439DA AECC075B 7A15D8F6 6F27174E
|
|
9E106FD4 521B3E57 9FBD7B6A 424124DE 23DCF537 71D586C6 538F4A22 41839B5A
|
|
872C3B01 D86B8E21 AE5D4815 949B8A98 76E2E146 4ACD120B A12934CC E2368F10
|
|
858F76B3 29870C03 581C48B4 2F345BC9 93A312E5 7BEB0C45 8BF518B5 B755DFF3
|
|
C6E90203 010001A3 53305130 0F060355 1D130101 FF040530 030101FF 301F0603
|
|
551D2304 18301680 1493568B DD2BB2D3 5D43758B FCF5EE44 82EB8134 2B301D06
|
|
03551D0E 04160414 93568BDD 2BB2D35D 43758BFC F5EE4482 EB81342B 300D0609
|
|
2A864886 F70D0101 05050003 818100C5 14B47762 9A9B566A AD5CCEA7 7F537184
|
|
52503777 112BF9ED DDC656C0 C014C491 51FC0885 CBB4AEE4 8B00DC99 0CF4504C
|
|
BEBD25C0 43B936B6 7E7EC2C2 5D8C536B 26F9CFE3 03C64CBE DF426945 AAC7AE40
|
|
6C35EA04 BB4D6688 A3A0BEDF 6475B7A1 33BC62B2 4BB9B3F4 67C28CF8 A9E0F600
|
|
6F426545 B75F7163 BF738EA8 5034DF
|
|
quit
|
|
errdisable recovery cause dtp-flap
|
|
errdisable recovery cause link-flap
|
|
errdisable recovery cause port-mode-failure
|
|
errdisable recovery cause loopback
|
|
errdisable recovery interval 600
|
|
archive
|
|
log config
|
|
logging enable
|
|
logging size 900
|
|
notify syslog contenttype plaintext
|
|
hidekeys
|
|
path tftp://tftp/IZH/KG/P11-SW_L2/$H.$T.conf
|
|
write-memory
|
|
time-period 10080
|
|
!
|
|
spanning-tree mode rapid-pvst
|
|
spanning-tree loopguard default
|
|
no spanning-tree optimize bpdu transmission
|
|
spanning-tree extend system-id
|
|
!
|
|
lldp run
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
!
|
|
interface Loopback7777
|
|
description TK6530m
|
|
no ip address
|
|
shutdown
|
|
downshift disable
|
|
!
|
|
interface Port-channel1
|
|
description [CORE] SW-1-1
|
|
switchport mode trunk
|
|
ip dhcp snooping trust
|
|
!
|
|
interface FastEthernet0/1
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/2
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/3
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/4
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/5
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/6
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/7
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/8
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/9
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/10
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/11
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/12
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/13
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/14
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/15
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/16
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/17
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/18
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/19
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/20
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/21
|
|
description KG-LOCAL-POWER_OFF
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
power inline never
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/22
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/23
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/24
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/25
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/26
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/27
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/28
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/29
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/30
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/31
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/32
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/33
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/34
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/35
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/36
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/37
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/38
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/39
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/40
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/41
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/42
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/43
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/44
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/45
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/46
|
|
description NONE
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
switchport voice vlan 351
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
spanning-tree portfast edge
|
|
!
|
|
interface FastEthernet0/47
|
|
description NONE
|
|
switchport trunk allowed vlan 9,10,12,150,301,500
|
|
switchport trunk native vlan 12
|
|
switchport mode trunk
|
|
no logging event link-status
|
|
no cdp enable
|
|
no snmp trap link-status
|
|
no lldp transmit
|
|
no lldp receive
|
|
!
|
|
interface FastEthernet0/48
|
|
description [WIFI] AP-5-506-TEE
|
|
switchport trunk allowed vlan 9,10,12,150,301,500
|
|
switchport trunk native vlan 12
|
|
switchport mode trunk
|
|
no logging event link-status
|
|
power inline port 2x-mode
|
|
no snmp trap link-status
|
|
no lldp transmit
|
|
no lldp receive
|
|
!
|
|
interface GigabitEthernet0/1
|
|
description [CORE] Po1 SW-1-1
|
|
switchport mode trunk
|
|
logging event trunk-status
|
|
logging event spanning-tree
|
|
channel-group 1 mode on
|
|
ip dhcp snooping trust
|
|
!
|
|
interface GigabitEthernet0/2
|
|
description PORT-CHANNEL
|
|
switchport mode trunk
|
|
logging event trunk-status
|
|
logging event spanning-tree
|
|
channel-group 1 mode on
|
|
ip dhcp snooping trust
|
|
!
|
|
interface GigabitEthernet0/3
|
|
description [WIFI] AP-5-509-ClassRoom
|
|
switchport trunk allowed vlan 9,10,12,150,151,301,500
|
|
switchport trunk native vlan 12
|
|
switchport mode trunk
|
|
no logging event link-status
|
|
no cdp enable
|
|
no snmp trap link-status
|
|
storm-control broadcast level 30.00
|
|
no lldp transmit
|
|
no lldp receive
|
|
!
|
|
interface GigabitEthernet0/4
|
|
description MFU_IN_CROSSROOM
|
|
switchport access vlan 2
|
|
switchport mode access
|
|
no logging event link-status
|
|
no snmp trap link-status
|
|
!
|
|
interface Vlan1
|
|
no ip address
|
|
shutdown
|
|
!
|
|
interface Vlan100
|
|
ip address 10.1.1.51 255.255.255.0
|
|
no ip redirects
|
|
no ip unreachables
|
|
no ip proxy-arp
|
|
!
|
|
ip default-gateway 10.1.1.1
|
|
no ip http server
|
|
no ip http secure-server
|
|
ip tftp source-interface Vlan100
|
|
ip ssh authentication-retries 2
|
|
!
|
|
kron occurrence EveryDay at 1:00 recurring
|
|
policy-list SaveBackup
|
|
!
|
|
kron policy-list SaveBackup
|
|
cli write memory
|
|
!
|
|
logging trap debugging
|
|
logging origin-id hostname
|
|
logging facility local6
|
|
logging source-interface Vlan100
|
|
logging host 192.168.2.25
|
|
logging host 10.4.244.4 transport udp port 515
|
|
access-list 23 permit any
|
|
access-list 23 deny any log
|
|
snmp-server community private RW
|
|
snmp-server community lmTUEsk6Yvlv RO
|
|
snmp-server host 10.1.122.227 lmTUEsk6Yvlv
|
|
snmp mib flash cache
|
|
!
|
|
radius server IZH-RDS002
|
|
address ipv4 10.4.0.248 auth-port 1645 acct-port 1646
|
|
timeout 3
|
|
retransmit 2
|
|
key 7 101F3E4B5C19563C160C6C010516751A2D0A0A34321159181C7075222515524D7C7A7C00407B536324307D470117150D7E3A273C2B4443044F2E3C345B39522405
|
|
!
|
|
radius server P11-RDS003
|
|
address ipv4 10.1.122.248 auth-port 1645 acct-port 1646
|
|
timeout 3
|
|
retransmit 2
|
|
key 7 101F3E4B5C19563C160C6C010516751A2D0A0A34321159181C7075222515524D7C7A7C00407B536324307D470117150D7E3A273C2B4443044F2E3C345B39522405
|
|
!
|
|
!
|
|
privilege exec all level 7 show cdp
|
|
privilege exec all level 7 show running-config
|
|
privilege exec all level 7 show configuration
|
|
privilege exec level 7 show
|
|
!
|
|
line con 0
|
|
logging synchronous
|
|
login authentication CONSOLE
|
|
line vty 0 4
|
|
access-class 23 in
|
|
logging synchronous
|
|
login authentication NPS
|
|
length 0
|
|
transport input ssh
|
|
line vty 5 15
|
|
access-class 23 in
|
|
logging synchronous
|
|
login authentication NPS
|
|
transport input ssh
|
|
!
|
|
ntp source Vlan100
|
|
ntp server 10.1.1.2
|
|
end |