415 lines
9.2 KiB
Plaintext
415 lines
9.2 KiB
Plaintext
!Software Version V200R001C00SPC700
|
|
!Last configuration was updated at 2022-05-26 13:41:48+04:00 by akhmetzyanovrr_adm
|
|
!Last configuration was saved at 2022-05-26 13:41:56+04:00 by akhmetzyanovrr_adm
|
|
#
|
|
clock timezone UL add 04:00:00
|
|
#
|
|
sysname milkhuaw0900
|
|
#
|
|
device board 1 board-type CE6810-24S2Q-LI
|
|
device board 2 board-type CE6810-24S2Q-LI
|
|
#
|
|
drop-profile default
|
|
#
|
|
dcb pfc
|
|
#
|
|
dcb ets-profile default
|
|
#
|
|
dns domain komos.ru
|
|
#
|
|
vlan batch 200 250 300 to 301 350 400 554 to 555
|
|
#
|
|
stp mode rstp
|
|
#
|
|
telnet server disable
|
|
telnet ipv6 server disable
|
|
#
|
|
radius enable
|
|
#
|
|
diffserv domain default
|
|
#
|
|
radius server group rad-serv
|
|
radius server shared-key-cipher %^%#"{4}+Fm|2Gld`[4`u4N%;~No'O%E~JEo^[HJs{Z(+9\cH9D=l-N8W&:h+BP!|a]%'3x>UY,]!nA3gCSH<|UkAWEyaJq9Sj!,b8^C%^%#
|
|
radius server authentication 10.4.0.248 1645 source Vlanif300
|
|
radius server authentication 10.1.122.248 1645 source Vlanif300 secondary
|
|
radius server retransmit 2
|
|
radius server user-name domain-excluded
|
|
#
|
|
vlan 200
|
|
name LAN_Varaksino
|
|
#
|
|
vlan 250
|
|
name LAN_Udm
|
|
#
|
|
vlan 300
|
|
name MGM
|
|
#
|
|
vlan 301
|
|
name vMotion
|
|
#
|
|
vlan 350
|
|
name For_Routers
|
|
#
|
|
vlan 400
|
|
name Management
|
|
#
|
|
vlan 554
|
|
name VRS-IZM_Peering
|
|
#
|
|
acl number 2000
|
|
rule 100 permit
|
|
#
|
|
aaa
|
|
local-user adminssh password irreversible-cipher $1c$<o'x7x6_d>$Ziq30HAS:V{A,2.o';B!h-waR$Dh@5=o)TH7<e4($
|
|
local-user adminssh service-type ssh
|
|
local-user adminssh level 3
|
|
local-user akhmetzyanovrr password irreversible-cipher $1c$';#6)+pfh3$hve_0!RyiT+rkX#3JDt9^~2TG!^rg'"h(S4iINU.$
|
|
local-user akhmetzyanovrr service-type ssh
|
|
local-user akhmetzyanovrr level 3
|
|
local-user netadmin password irreversible-cipher $1c$9+'%L}RSU4$"M'/8eY*V#0S5'4^H]`Rn3BN8h)!_J!whs@tMF\F$
|
|
local-user netadmin service-type ssh
|
|
local-user netadmin level 3
|
|
#
|
|
authentication-scheme default
|
|
authentication-mode local radius
|
|
#
|
|
authorization-scheme default
|
|
#
|
|
accounting-scheme default
|
|
#
|
|
domain default
|
|
radius server group rad-serv
|
|
#
|
|
domain default_admin
|
|
radius server group rad-serv
|
|
#
|
|
stack
|
|
#
|
|
stack member 1 domain 10
|
|
stack member 1 priority 200
|
|
#
|
|
stack member 2 domain 10
|
|
#
|
|
interface Vlanif300
|
|
ip address 10.8.64.190 255.255.255.192
|
|
#
|
|
interface Vlanif400
|
|
ip address 192.168.72.220 255.255.255.192
|
|
#
|
|
interface Vlanif554
|
|
description VRS-IZM Peering
|
|
ip address 172.30.32.10 255.255.255.252
|
|
#
|
|
interface Vlanif555
|
|
description BGP_TRANSIT
|
|
ip address 172.30.30.147 255.255.255.248
|
|
#
|
|
interface MEth0/0/0
|
|
#
|
|
interface Eth-Trunk1
|
|
description Nod_A
|
|
port default vlan 300
|
|
mode lacp-static
|
|
#
|
|
interface Eth-Trunk2
|
|
description Nod_B
|
|
port default vlan 300
|
|
mode lacp-static
|
|
#
|
|
interface Eth-Trunk4
|
|
description [PEER] VRS-IZM Peering
|
|
port link-type trunk
|
|
port trunk allow-pass vlan 554
|
|
stp bpdu-filter enable
|
|
mode lacp-static
|
|
#
|
|
interface Stack-Port1/1
|
|
#
|
|
interface Stack-Port2/1
|
|
#
|
|
interface 10GE1/0/1
|
|
eth-trunk 1
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE1/0/2
|
|
eth-trunk 1
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE1/0/3
|
|
eth-trunk 2
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE1/0/4
|
|
eth-trunk 2
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE1/0/5
|
|
description TO_milkdell0901
|
|
port link-type trunk
|
|
port trunk allow-pass vlan 200 250 300 to 301 400
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE1/0/6
|
|
description TO_milkdell0902
|
|
port link-type trunk
|
|
port trunk allow-pass vlan 200 250 300 to 301 400
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE1/0/7
|
|
description TO_milkdell0903
|
|
port link-type trunk
|
|
port trunk allow-pass vlan 200 250 300 to 301 400
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE1/0/8
|
|
port default vlan 400
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE1/0/9
|
|
#
|
|
interface 10GE1/0/10
|
|
#
|
|
interface 10GE1/0/11
|
|
port default vlan 300
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE1/0/12
|
|
device transceiver 10GBASE-FIBER
|
|
#
|
|
interface 10GE1/0/13
|
|
port default vlan 200
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE1/0/14
|
|
device transceiver 10GBASE-FIBER
|
|
#
|
|
interface 10GE1/0/15
|
|
#
|
|
interface 10GE1/0/16
|
|
#
|
|
interface 10GE1/0/17
|
|
#
|
|
interface 10GE1/0/18
|
|
description Mgmt_NOD_A
|
|
port default vlan 400
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE1/0/19
|
|
description iDr_dell0901
|
|
port default vlan 400
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE1/0/20
|
|
description iDr_dell0902
|
|
port default vlan 400
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE1/0/21
|
|
port default vlan 400
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE1/0/22
|
|
description Men_milkdell0901
|
|
port default vlan 400
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE1/0/23
|
|
description Men_milkdell0902
|
|
port default vlan 400
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE1/0/24
|
|
description [CORE] RT-1-2
|
|
port link-type trunk
|
|
port trunk allow-pass vlan 200 250 300 350 400 555
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE2/0/1
|
|
eth-trunk 1
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE2/0/2
|
|
eth-trunk 1
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE2/0/3
|
|
eth-trunk 2
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE2/0/4
|
|
eth-trunk 2
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE2/0/5
|
|
description TO_milkdell0901
|
|
port link-type trunk
|
|
port trunk allow-pass vlan 200 250 300 to 301 400
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE2/0/6
|
|
description TO_milkdell0902
|
|
port link-type trunk
|
|
port trunk allow-pass vlan 200 250 300 to 301 400
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE2/0/7
|
|
description TO_milkdell0903
|
|
port link-type trunk
|
|
port trunk allow-pass vlan 200 250 300 to 301 400
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE2/0/8
|
|
port default vlan 400
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE2/0/9
|
|
#
|
|
interface 10GE2/0/10
|
|
#
|
|
interface 10GE2/0/11
|
|
port default vlan 300
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE2/0/12
|
|
device transceiver 10GBASE-COPPER
|
|
#
|
|
interface 10GE2/0/13
|
|
description [PEER] ET4 VRS-IZM Peering
|
|
eth-trunk 4
|
|
device transceiver 1000BASE-X
|
|
#
|
|
interface 10GE2/0/14
|
|
#
|
|
interface 10GE2/0/15
|
|
#
|
|
interface 10GE2/0/16
|
|
#
|
|
interface 10GE2/0/17
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE2/0/18
|
|
description Mgmt_NOD_B
|
|
port default vlan 400
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE2/0/19
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE2/0/20
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE2/0/21
|
|
port default vlan 400
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE2/0/22
|
|
description iDr_dell0903
|
|
port default vlan 400
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE2/0/23
|
|
description Men_milkdell0903
|
|
port default vlan 400
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 10GE2/0/24
|
|
description [CORE] RT-1-1
|
|
port link-type trunk
|
|
port trunk allow-pass vlan 200 250 300 350 400 555
|
|
device transceiver 1000BASE-T
|
|
#
|
|
interface 40GE1/0/1
|
|
port mode stack
|
|
stack-port 1/1
|
|
port crc-statistics trigger error-down
|
|
device transceiver 40GBASE-COPPER
|
|
#
|
|
interface 40GE1/0/2
|
|
port mode stack
|
|
stack-port 1/1
|
|
port crc-statistics trigger error-down
|
|
device transceiver 40GBASE-COPPER
|
|
#
|
|
interface 40GE2/0/1
|
|
port mode stack
|
|
stack-port 2/1
|
|
port crc-statistics trigger error-down
|
|
device transceiver 40GBASE-COPPER
|
|
#
|
|
interface 40GE2/0/2
|
|
port mode stack
|
|
stack-port 2/1
|
|
port crc-statistics trigger error-down
|
|
device transceiver 40GBASE-COPPER
|
|
#
|
|
interface NULL0
|
|
#
|
|
bgp 64523
|
|
graceful-restart
|
|
peer 172.30.30.145 as-number 64523
|
|
peer 172.30.30.146 as-number 64523
|
|
peer 172.30.32.9 as-number 64512
|
|
peer 172.30.32.9 description IZH-MLK-IZM-SW-1-1
|
|
#
|
|
ipv4-family unicast
|
|
network 10.8.64.0 255.255.248.0
|
|
peer 172.30.30.145 enable
|
|
peer 172.30.30.145 next-hop-local
|
|
peer 172.30.30.146 enable
|
|
peer 172.30.30.146 next-hop-local
|
|
peer 172.30.32.9 enable
|
|
peer 172.30.32.9 route-policy RP_FROM_IZM-P2P import
|
|
peer 172.30.32.9 route-policy RP_TO_IZM-P2P export
|
|
peer 172.30.32.9 next-hop-local
|
|
#
|
|
route-policy RP_FROM_IZM-P2P permit node 10
|
|
if-match ip-prefix PL_FROM_IZM-P2P
|
|
apply local-preference 1500
|
|
#
|
|
route-policy RP_TO_IZM-P2P permit node 10
|
|
#
|
|
ip ip-prefix PL_FROM_IZM-P2P index 10 permit 10.1.0.0 16 greater-equal 16 less-equal 32
|
|
ip ip-prefix PL_FROM_IZM-P2P index 20 permit 10.4.0.0 16 greater-equal 16 less-equal 32
|
|
ip ip-prefix PL_FROM_IZM-P2P index 30 permit 192.168.0.0 22
|
|
#
|
|
ip route-static 0.0.0.0 0.0.0.0 192.168.72.254
|
|
ip route-static 10.8.64.0 255.255.248.0 NULL0 preference 255
|
|
#
|
|
snmp-agent
|
|
snmp-agent local-engineid 800007DB0384A9C4CEA9F1
|
|
snmp-agent community read cipher %^%#lnlc&>9~X()U%2J9Fc&E[Q#eO4ZLX(M=jdImd>rA8QzSAQcz98/A]*TL~~B%SvF#,8/09A@Sp\1rO"96%^%#
|
|
#
|
|
snmp-agent sys-info location Izhevsk,V. Shosse,178
|
|
snmp-agent sys-info version v2c v3
|
|
#
|
|
lldp enable
|
|
#
|
|
stelnet server enable
|
|
ssh authentication-type default password
|
|
ssh user adminssh
|
|
ssh user adminssh authentication-type password
|
|
ssh user adminssh service-type all
|
|
ssh user akhmetzyanovrr
|
|
ssh user akhmetzyanovrr authentication-type password
|
|
ssh user akhmetzyanovrr service-type all
|
|
ssh user netadmin
|
|
ssh user netadmin authentication-type password
|
|
ssh user netadmin service-type all
|
|
ssh authorization-type default aaa
|
|
#
|
|
ssh server cipher aes256_ctr aes128_ctr
|
|
ssh server hmac sha2_256_96 sha2_256 sha1_96
|
|
ssh server key-exchange dh_group_exchange_sha256 dh_group_exchange_sha1 ecdh_sha2_nistp256 ecdh_sha2_nistp384 ecdh_sha2_nistp521 sm2_kep
|
|
#
|
|
user-interface con 0
|
|
authentication-mode password
|
|
set authentication password cipher $1c$mn646e^9*O$$)Mq,8`H]Rh=Bz!7Qs33TF2b3p$t}DW]H9J50WG-$
|
|
#
|
|
user-interface vty 0 4
|
|
authentication-mode aaa
|
|
user privilege level 3
|
|
protocol inbound ssh
|
|
#
|
|
vm-manager
|
|
#
|
|
return |