Configuracion Juniper
Configuracion Juniper
Configuracion Juniper
===============================================================================
Ethernet Interface
===============================================================================
Description : CAJA PROMOTORA DE VIVIENDA MILITAR - CRE0108
Interface : 4/1/19 Oper Speed : 1 Gbps
Link-level : Ethernet Config Speed : 1 Gbps
Admin State : up Oper Duplex : full
Oper State : up Config Duplex : full
Physical Link : Yes MTU : 1572
Single Fiber Mode : No Min Frame Length : 64 Bytes
IfIndex : 136937472 Hold time up : 0 seconds
Last State Change : 01/28/2018 16:36:22 Hold time down : 0 seconds
Last Cleared Time : N/A DDM Events : Enabled
Phys State Chng Cnt: 81
Transceiver Data
===============================================================================
Transceiver Digital Diagnostic Monitoring (DDM), Externally Calibrated
===============================================================================
Value High Alarm High Warn Low Warn Low Alarm
-------------------------------------------------------------------------------
Temperature (C) +42.7 +100.0 +95.0 -35.0 -40.0
Supply Voltage (V) 3.29 3.70 3.60 3.00 2.90
Tx Bias Current (mA) 6.6 80.0 70.0 0.2 0.1
Tx Output Power (dBm) -5.17 -2.00 -3.00 -9.00 -10.00
Rx Optical Power (avg dBm) -9.55 -2.00 -3.00 -20.00 -21.00
===============================================================================
===============================================================================
Traffic Statistics
===============================================================================
Input Output
-------------------------------------------------------------------------------
Octets 35486586380 870050434070
Packets 422744192 645681899
Errors 1 0
===============================================================================
===============================================================================
Port Statistics
===============================================================================
Input Output
-------------------------------------------------------------------------------
Unicast Packets 420547254 591291951
Multicast Packets 2153243 388924
Broadcast Packets 43695 54001024
Discards 0 0
Unknown Proto Discards 0
===============================================================================
===============================================================================
Ethernet-like Medium Statistics
===============================================================================
Epipe Service
Site 10.50.1.107, (AAG-ORTEZAL-C1, BOGOTA_Bg:BOGOTA AAG-ORTEZAL-C1--ATR2731), MTU:
1514, Terminando, Backbone VPLS ID: 0, ISID: -1
Endpoints
L2 Access Interfaces
SAP 1/2/2:1357 (Dot1 Q), Admin State: Arriba, Oper State: Arriba
Spoke SDP Bindings
SDP- 203:VC- 50850 -> 10.50.1.133 (AAC-ARANDA-C1), Admin State: Arriba, Oper State:
Arriba
Spoke SDP FECs
Site 10.50.1.133, (AAC-ARANDA-C1, BOGOTA_Bg:BOGOTA AAC-ARANDA-C1--ATR2757), MTU:
1514, Terminando, Backbone VPLS ID: 0, ISID: -1
Endpoints
L2 Access Interfaces
SAP 4/1/19:1357 (Dot1 Q), Admin State: Arriba, Oper State: Arriba
Spoke SDP Bindings
SDP- 202:VC- 50850 -> 10.50.1.107 (AAG-ORTEZAL-C1), Admin State: Arriba, Oper
State: Arriba
Spoke SDP FECs
DEMARCADOR
Login:raisecom
Password:
CAJA_CRE0108_BACKUP#sho run
L3
CPE
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show interfaces terse | no-more
Interface Admin Link Proto Local Remote
ge-0/0/0 up up
ge-0/0/0.1357 up up inet 10.163.245.126/30
ge-0/0/0.32767 up up
gr-0/0/0 up up
ip-0/0/0 up up
lsq-0/0/0 up up
lt-0/0/0 up up
mt-0/0/0 up up
sp-0/0/0 up up
sp-0/0/0.0 up up inet
sp-0/0/0.16383 up up inet 10.0.0.1 --> 10.0.0.16
10.0.0.6 --> 0/0
128.0.0.1 --> 128.0.1.16
128.0.0.6 --> 0/0
ge-0/0/1 up down
ge-0/0/1.0 up down eth-switch
ge-0/0/2 up down
ge-0/0/2.0 up down eth-switch
ge-0/0/3 up up
ge-0/0/3.0 up up eth-switch
ge-0/0/4 up down
ge-0/0/4.0 up down eth-switch
run show interfaces descriptions | no-more
ge-0/0/5 up down
ge-0/0/5.0 up down eth-switch
ge-0/0/6 up down
ge-0/0/6.0 up down eth-switch
ge-0/0/7 up down
ge-0/0/7.0 up down eth-switch
ge-0/0/8 up down
ge-0/0/9 up down
ge-0/0/10 up down
ge-0/0/11 up down
ge-0/0/12 up down
ge-0/0/13 up down
ge-0/0/14 up down
ge-0/0/15 up down
fxp2 up up
fxp2.0 up up tnp 0x1
gre up up
ipip up up
irb up up
lo0 up up
lo0.16384 up up inet 127.0.0.1 --> 0/0
lo0.16385 up up inet 10.0.0.1 --> 0/0
10.0.0.16 --> 0/0
128.0.0.1 --> 0/0
128.0.0.4 --> 0/0
128.0.1.16 --> 0/0
lo0.32768 up up
lsi up up
mtun up up
pimd up up
pime up up
pp0 up up
ppd0 up up
ppe0 up up
st0 up up
tap up up
vlan up up
vlan.26 up up inet 21.21.21.4/28
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show interfaces descriptions | no-more
run show arp | no-more
Interface Admin Link Description
ge-0/0/0.1357 up up --- WAN INTRANET BACKUP - CRE0108 ---
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show arp | no-more
MAC Address Address Name Interface
Flags
d8:67:d9:5a:ae:44 10.163.245.125 10.163.245.125 ge-0/0/0.1357
none
00:08:e3:ff:fc:04 21.21.21.2 21.21.21.2 vlan.26
none
ec:3e:f7:e4:f3:90 21.21.21.3 21.21.21.3 vlan.26
none
Total entries: 3
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show version | no-more
Hostname: CAJA_CRE0108_BACKUP
Model: srx240h2
JUNOS Software Release [12.1X44-D35.5]
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show chassis hardware | no-more
Hardware inventory:
Item Version Part number Serial number Description
Chassis BU4215AK0342 SRX240H2
Routing Engine REV 14 750-043609 ACNE7627 RE-SRX240H2
FPC 0 FPC
PIC 0 16x GE Base PIC
Power Supply 0
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show system uptime | no-more
Current time: 2018-06-06 18:24:19 COT
System booted: 2018-03-01 00:56:49 COT (13w6d 17:27 ago)
Protocols started: 2018-03-01 00:59:56 COT (13w6d 17:24 ago)
Last configured: 2018-01-26 22:42:12 COT (18w4d 19:42 ago) by telmexuser
6:24PM up 97 days, 17:28, 1 user, load averages: 0.22, 0.09, 0.02
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show system storage | no-more
Filesystem Size Used Avail Capacity Mounted on
/dev/da0s1a 610M 147M 414M 26% /
devfs 1.0K 1.0K 0B 100% /dev
/dev/md0 390M 390M 0B 100% /junos
/cf 610M 147M 414M 26% /junos/cf
devfs 1.0K 1.0K 0B 100% /junos/dev/
procfs 4.0K 4.0K 0B 100% /proc
/dev/bo0s3e 46M 20K 42M 0% /config
/dev/bo0s3f 618M 7.8M 560M 1% /cf/var
/dev/md1 336M 18M 291M 6% /mfs
/cf/var/jail 618M 7.8M 560M 1% /jail/var
/cf/var/log 618M 7.8M 560M 1% /jail/var/log
devfs 1.0K 1.0K 0B 100% /jail/dev
/dev/md2 63M 4.0K 58M 0% /mfs/var/run/utm
/dev/md3 1.8M 4.0K 1.7M 0% /jail/mfs
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show system virtual-memory | no-more
Type InUse MemUse HighUse Requests Size(s)
cache 2 1K - 2 16384
devbuf 321 1312K - 447
16,32,64,128,256,1024,2048,4096,8192,524288,1048576,2097152,4194304
temp 1815 315K - 1441749
16,32,64,256,512,1024,2048,65536,131072,524288,1048576,2097152,4194304
iflogical 30 7K - 30 32,256,65536,524288
iffamily 34 4K - 34 16,32,1024,2048
rtnexthop 119 16K - 7227 16,32,128,2048,4096,8192,16384,65536
metrics 5 1K - 13 1024
inifmulti 1 1K - 1 64
ingrentry 1 1K - 1 64
rnode 108 3K - 7306 16,32,128,256,8192
rcache 4 8K - 4 2097152
ifdevice 11 9K - 11 16,1048576
ifstat 155 125K - 114097
32,512,2048,16384,32768,524288,2097152,4194304
rtdata 20 1K - 7191 32,128
ipfw 42 23K - 91
16,32,64,128,256,1024,2048,4096,524288,1048576,2097152,4194304
ifmaddr 63 2K - 197 16,32
rtable 160 20K - 14526 16,32,256,512,4096,8192,524288
sysctl 0 0K - 29520933 16,32,64,128,131072,524288,1048576
ifaddr 23 2K - 157 64
socket 2 1K - 2 16
mkey 456 8K - 23646724 16,256
pfe_ipc 0 0K - 735203
16,32,64,128,256,512,1024,2048,4096,8192,32768,65536,262144,524288,1048576,2097152,
4194304
ifstate 3389 122K - 73018
16,64,128,256,512,1024,4096,32768,524288,1048576
itable16 362 71K - 569 4096,131072
itable32 177 12K - 177 128
itable64 2 1K - 2 2048
lr 1 1K - 1 524288
ifservice 1 1K - 1 32
pic 2 1K - 2 128,256
pfestat 102 18K - 1651826 16,32,256,512,1024,2097152
gencfg 646 3044K - 1687746
16,32,64,128,512,1024,2048,8192,524288,1048576,2097152,4194304
idl 1 20K - 323
32,64,2048,16384,262144,1048576,4194304
rtsmsg 0 0K - 1937 4194304
vlan 2 1K - 2 65536
fdbnh 1 1K - 1 32
mesh-group 2 1K - 2 256
vpls_lc_instance 1 2K - 1 2097152
UART 3 2K - 3 128,262144,1048576
USB 90 8K - 15209 16,32,64,128,256,1024,2048,4096,8192
USBdev 6 1K - 15 16,256,1024,524288
module 134 9K - 134 64,128
mtx_pool 1 8K - 1 64,128
DEVFS2 78 2K - 151 16
pgrp 8 1K - 38823 128
session 7 1K - 38822 2048
proc 2 1K - 2 131072
subproc 250 499K - 118181 32768,4194304
cred 27 4K - 45197326 1024
plimit 23 6K - 427020 32768
uidinfo 4 1K - 28161 32,128
DEVFS3 242 29K - 243 1024
DEVFS1 78 18K - 78 32768
sysctloid 779 20K - 779 16,32,64
sysctltmp 0 0K - 3515067 16,32,64,8192
umtx 161 8K - 161 64
bus 223 40K - 382 16,32,64,128,256,512,1048576
bus-sc 19 8K - 55
16,32,64,128,1024,2048,4096,16384,262144,1048576,2097152,4194304
DEVFS_RULE 5 1K - 5 32,131072
DEVFS 48 1K - 49 16,128
devstat 10 21K - 10 16,4194304
eventhandler 62 3K - 62 32,256,512
kobj 36 72K - 41 2097152
NULLFS hash 1 1K - 1 128
rman 36 3K - 40 16,32,256
sbuf 0 0K - 374 16,32,1048576
NULLFS node 8 1K - 1434063 16
NULLFS mount 3 1K - 3 16
taskqueue 5 1K - 5 128
turnstiles 162 11K - 162 128
Unitno 6 1K - 8 16,64
ioctlops 0 0K - 161507312
16,64,256,65536,262144,524288,1048576,2097152,4194304
iov 0 0K - 62161178
16,32,64,128,256,512,1024,2048,262144,4194304
msg 4 25K - 4 1048576,4194304
sem 4 7K - 4 524288,1048576,4194304
shm 9 60K - 10 4194304
ttys 262 35K - 1102 2048,1048576
ptys 1 1K - 1 512
mbuf_tag 0 0K - 26715981 32,128
soname 141 16K - 97936352 16,32,64,256,512,1024
pcb 417 95K - 18544736
16,32,64,128,256,4096,8192,16384,65536,524288,1048576,2097152
BIO buffer 74 148K - 576 2097152
vfscache 1 512K - 1 2097152
cluster_save buffer 0 0K - 2 32
VFS hash 1 256K - 1 32
vnodes 1 1K - 1 2048
mount 181 20K - 243 16,32,64,512,1024,131072,1048576
vnodemarker 0 0K - 4323850 262144
pfs_nodes 25 2K - 25 256
BPF 15 37K - 15 128,32768,4194304
ifl_idx_mgr 1 1K - 1 128
pfs_vncache 40 2K - 94 32
GEOM 142 14K - 732
16,32,128,256,512,1024,2048,16384,524288,1048576
CAM SIM 2 1K - 2 64
ISOFS mount 1 1K - 1 2048
ISOFS node 2014 189K - 2014 512
CAM XPT 15 3K - 81 16,64,524288,1048576
CAM periph 3 1K - 4 256
STP 37 12K - 37 2048,4096,524288
syncache 1 8K - 1 2048,4096,524288
tlv_stat 0 0K - 131630 2048,4096,524288
Aggregator 1 1K - 1 256
Bridge Domain 2 1K - 2 16,131072
p1003.1b 1 1K - 1 16
cdev 25 3K - 25 1024
MD disk 14 9K - 14 16,2097152
MD sectors 10 40K - 10 4194304
file desc 150 33K - 118249 16,4096,16384,524288
sigio 1 1K - 14 32
kenv 79 6K - 98 16,32,64,128,4194304
kqueue 23 11K - 70 32,4096,131072,1048576
proc-args 57 3K - 117575 32,64,128,256,512,1024,2048,4096,8192
zombie 1 1K - 117932 256
ithread 44 3K - 44 16,64,2048
pagedep 1 32K - 1 16,64,2048
inodedep 1 256K - 1 16,64,2048
newblk 1 1K - 1 131072
UFS mount 18 38K - 27 65536,2097152,4194304
KTRACE 101 10K - 101 512
UMAHash 2 2K - 6 131072,524288,1048576
CAM queue 7 1K - 25 16
CAM dev queue 2 1K - 2 128
linker 61 16K - 68
16,32,64,128,8192,16384,65536,131072,262144,1048576,4194304
lockf 52 4K - 5058841 128
VM pgdata 1 128K - 1 128
entropy 1024 48K - 1024 64
ifa_list 12 1K - 79 16
ITEM SIZE LIMIT USED FREE REQUESTS
UMA Kegs: 136, 0, 78, 18, 78
UMA Zones: 392, 0, 78, 3, 78
UMA Slabs: 64, 0, 939, 241, 135216
UMA RCntSlabs: 104, 0, 155, 30, 155
UMA Hash: 128, 0, 6, 24, 8
16 Bucket: 76, 0, 37, 13, 53
32 Bucket: 140, 0, 39, 17, 60
64 Bucket: 268, 0, 29, 13, 71
128 Bucket: 524, 0, 80, 4, 548
VM OBJECT: 136, 0, 3842, 276, 1716598
MAP: 168, 0, 8, 15, 8
KMAP ENTRY: 72, 35828, 32, 180, 271360
MAP ENTRY: 72, 0, 2848, 385, 3561392
PV ENTRY: 28, 322580, 92059, 4207, 42129433
DP fakepg: 88, 0, 0, 0, 0
mt_zone: 768, 0, 237, 3, 237
16: 16, 0, 4631, 241, 258963186
32: 32, 0, 599, 192, 37243081
48: 48, 0, 3554, 190, 38336946
64: 64, 0, 662, 164, 31897343
80: 80, 0, 745, 119, 8790158
96: 96, 0, 2264, 56, 300053
120: 120, 0, 624, 48, 104246401
128: 128, 0, 457, 23, 40260
160: 160, 0, 416, 16, 14637
176: 176, 0, 31, 35, 7166
208: 208, 0, 211, 36, 118192
232: 232, 0, 241, 14, 427336
240: 240, 0, 49, 15, 78806
256: 256, 0, 169, 26, 345
296: 296, 0, 5, 21, 4323886
512: 512, 0, 118, 18, 351
1024: 1024, 0, 127, 13, 1282791
2048: 2048, 0, 331, 53, 143405
4096: 4096, 0, 196, 18, 119145
Files: 80, 0, 776, 88, 152105738
MAC labels: 20, 0, 4836, 65, 94125507
PROC: 616, 0, 116, 16, 118047
THREAD: 524, 0, 144, 17, 144
KSEGRP: 96, 0, 144, 56, 144
UPCALL: 44, 0, 7, 149, 7
SLEEPQUEUE: 32, 0, 162, 177, 162
VMSPACE: 336, 0, 57, 20, 117988
mbuf_packet: 256, 82560, 0, 128, 4563345
mbuf: 256, 82560, 7, 1020, 1088495154
mbuf_cluster: 2048, 20640, 132, 178, 1236900
mbuf_jumbo_pagesize: 4096, 0, 0, 0, 0
mbuf_jumbo_9k: 9216, 0, 0, 0, 0
mbuf_jumbo_16k: 16384, 0, 0, 0, 0
ACL UMA zone: 388, 0, 0, 0, 0
g_bio: 144, 0, 0, 189, 66822
ata_request: 208, 0, 0, 0, 0
ata_composite: 192, 0, 0, 0, 0
GENCFG: 72, 1000004, 270, 48, 845
VNODE: 280, 0, 2862, 22, 1437242
VNODEPOLL: 72, 0, 0, 0, 0
S VFS Cache: 68, 0, 2669, 75, 4176
L VFS Cache: 291, 0, 30, 22, 34
NAMEI: 1024, 0, 0, 12, 278887913
NFSMOUNT: 488, 0, 0, 0, 0
NFSNODE: 472, 0, 0, 0, 0
PIPE: 404, 0, 48, 15, 78454
KNOTE: 72, 0, 90, 69, 254716349
socket: 376, 20640, 454, 16, 23646722
unpcb: 144, 20655, 217, 53, 13523710
ipq: 52, 216, 0, 0, 0
udp_inpcb: 264, 20640, 19, 26, 45
tcp_inpcb: 264, 20640, 128, 22, 1686600
tcpcb: 508, 20640, 47, 9, 1686600
tcptw: 60, 4158, 0, 126, 3
syncache: 128, 15360, 0, 60, 19
tcpreass: 20, 1352, 0, 0, 0
sackhole: 20, 0, 0, 0, 0
ripcb: 264, 20640, 9, 21, 10
SWAPMETA: 280, 133672, 0, 0, 0
FFS inode: 144, 0, 688, 14, 955
FFS1 dinode: 128, 0, 688, 32, 955
FFS2 dinode: 256, 0, 0, 0, 0
md2: 512, 0, 1922, 6, 1922
md3: 512, 0, 18, 6, 18
1979305573 cpu context switches
840457547 device interrupts
207593178 software interrupts
0 traps
238366828 system calls
60 kernel threads created
79175 fork() calls
38812 vfork() calls
0 rfork() calls
0 swap pager pageins
0 swap pager pages paged in
0 swap pager pageouts
0 swap pager pages paged out
21798 vnode pager pageins
21840 vnode pager pages paged in
634 vnode pager pageouts
6242 vnode pager pages paged out
0 page daemon wakeups
0 pages examined by the page daemon
18765 pages reactivated
4544814 copy-on-write faults
46 copy-on-write optimized faults
2546182 zero fill pages zeroed
2338486 zero fill pages prezeroed
148 intransit blocking page faults
11273894 total VM faults taken
0 pages affected by kernel thread creation
3424345 pages affected by fork()
1748464 pages affected by vfork()
0 pages affected by rfork()
7972779 pages freed
0 pages freed by daemon
6548798 pages freed by exiting process
41794 pages active
25414 pages inactive
41050 pages in VM cache
256313 pages wired down
140224 pages free
4096 bytes per page
0 swap pages used
0 peak swap pages used
695942138 total name lookups
cache hits (90% pos + 9% neg) system 0% per-directory
deletions 0%, falsehits 0%, toolong 0%
interrupt total rate
clock 2771896810 328
uart 3196627055 378
IPI 20603470 2
Totaldinode: 5989127335 709
vm.kmem_map_free: 196288512
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show route summary | no-more
Autonomous system number: 64839
Router ID: 10.163.245.126
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show cli directory | no-more
Current directory: /cf/var/home/telmexuser
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show route protocol static | no-more
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show system services dhcp binding | no-more
warning: dhcp subsystem not running - not needed by configuration.
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show bgp summary | no-more
Groups: 2 Peers: 2 Down peers: 0
Table Tot Paths Act Paths Suppressed History Damp State Pending
inet.0 79 39 0 0 0 0
Peer AS InPkt OutPkt OutQ Flaps Last Up/Dwn
State|#Active/Received/Accepted/Damped...
10.163.245.125 14080 844202 937141 0 0 13w6d17h
39/40/40/0 0/0/0/0
21.21.21.3 64839 312634 312708 0 0 13w6d17h
0/39/39/0 0/0/0/0
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show vrrp brief | no-more
Interface State Group VR state VR Mode Timer Type Address
vlan.26 up 2 backup Active D 2.855 lcl 21.21.21.4
vip 21.21.21.1
mas 21.21.21.3
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show vrrp summary | no-more
Interface State Group VR state VR Mode Type Address
vlan.26 up 2 backup Active lcl 21.21.21.4
vip 21.21.21.1
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show lldp neighbors | no-more
warning: lldpd-service subsystem not running - not needed by configuration.
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security ike active-peer | no-more
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security ike security-associations | no-
more
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security ike security-associations detail
| no-more
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security ipsec security-associations | no-
more
Total active tunnels: 0
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security ipsec security-associations
detail | no-more
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security ipsec statistics | no-more
ESP Statistics:
Encrypted bytes: 0
Decrypted bytes: 0
Encrypted packets: 0
Decrypted packets: 0
AH Statistics:
Input bytes: 0
Output bytes: 0
Input packets: 0
Output packets: 0
Errors:
AH authentication failures: 0, Replay errors: 0
ESP authentication failures: 0, ESP decryption failures: 0
Bad headers: 0, Bad trailers: 0
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ipsec statistics
| no-more
ESP Statistics:
Encrypted bytes: 0
Decrypted bytes: 0
Encrypted packets: 0
Decrypted packets: 0
AH Statistics:
Input bytes: 0
Output bytes: 0
Input packets: 0
Output packets: 0
Errors:
AH authentication failures: 0, Replay errors: 0
ESP authentication failures: 0, ESP decryption failures: 0
Bad headers: 0, Bad trailers: 0
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ike security-
associations | no-more
error: the gkmd instance gkmd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ipsec statistics
| no-more
ESP Statistics:
Encrypted bytes: 0
Decrypted bytes: 0
Encrypted packets: 0
Decrypted packets: 0
AH Statistics:
Input bytes: 0
Output bytes: 0
Input packets: 0
Output packets: 0
Errors:
AH authentication failures: 0, Replay errors: 0
ESP authentication failures: 0, ESP decryption failures: 0
Bad headers: 0, Bad trailers: 0
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ipsec security-
associations | no-more
error: the gkmd instance gkmd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ike security-
associations | no-more
error: the gkmd instance gkmd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ipsec security-
associations | no-more
error: the gkmd instance gkmd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ipsec security-
associations detail | no-more
error: the gkmd instance gkmd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member kek security-
associations | no-more
error: the gkmd instance gkmd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ike security-
associations | no-more
error: the gkmd instance gkmd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn server ipsec security-
associations | no-more
error: the gksd instance gksd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn server registered-
members | no-more
error: the gksd instance gksd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn server ike security-
associations | no-more
error: the gksd instance gksd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn server ipsec security-
associations | no-more
error: the gksd instance gksd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn server registered-
members | no-more
error: the gksd instance gksd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn server ipsec security-
associations | no-more
error: the gksd instance gksd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn server registered-
members | no-more
error: the gksd instance gksd is not running
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security dynamic-policies | no-more
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show configuration | no-more
## Last commit: 2018-01-26 22:42:12 COT by telmexuser
version 12.1X44-D35.5;
system {
host-name CAJA_CRE0108_BACKUP;
time-zone America/Bogota;
root-authentication {
encrypted-password "$1$WemwPsaP$qjEYysh6JVR4auF3KDNQS/"; ## SECRET-DATA
}
login {
message
"\n\n\n\t*************************************************************\n\t*
ATENCION: Este equipo es propiedad de TELMEX Colombia. *\n\t* El uso no
autorizado esta estrictamente prohibido. *\n\t* Todos los usuarios son
legalmente responsables de sus *\n\t* acciones sobre el sistema y toda
actividad sera
registrada*\n\t*************************************************************\n\n\n"
;
user telmexuser {
uid 2000;
class super-user;
authentication {
encrypted-password "$1$v3XVTWsN$OQ8KfTPdq33r5IY.sf5ID1"; ## SECRET-
DATA
}
}
}
services {
ssh;
telnet;
xnm-clear-text;
web-management {
http {
interface [ vlan.100 vlan.3 ];
}
https {
system-generated-certificate;
interface vlan.100;
}
}
}
syslog {
archive size 100k files 3;
user * {
any emergency;
}
file messages {
any critical;
authorization info;
}
file interactive-commands {
interactive-commands error;
}
}
max-configurations-on-flash 5;
max-configuration-rollbacks 5;
license {
autoupdate {
url https://ae1.juniper.net/junos/key_retrieval;
}
}
}
interfaces {
ge-0/0/0 {
vlan-tagging;
unit 1357 {
description "--- WAN INTRANET BACKUP - CRE0108 ---";
vlan-id 1357;
family inet {
address 10.163.245.126/30;
}
}
}
ge-0/0/1 {
unit 0 {
family ethernet-switching {
vlan {
members LAN;
}
}
}
}
ge-0/0/2 {
unit 0 {
family ethernet-switching {
vlan {
members LAN;
}
}
}
}
ge-0/0/3 {
unit 0 {
family ethernet-switching {
vlan {
members LAN;
}
}
}
}
ge-0/0/4 {
unit 0 {
family ethernet-switching {
vlan {
members LAN;
}
}
}
}
ge-0/0/5 {
unit 0 {
family ethernet-switching {
vlan {
members LAN;
}
}
}
}
ge-0/0/6 {
unit 0 {
family ethernet-switching {
vlan {
members LAN;
}
}
}
}
ge-0/0/7 {
unit 0 {
family ethernet-switching {
vlan {
members LAN;
}
}
}
}
vlan {
unit 26 {
family inet {
address 21.21.21.4/28 {
vrrp-group 2 {
virtual-address 21.21.21.1;
preempt;
accept-data;
}
}
}
}
}
}
snmp {
community CRpWE3677TeLmEx {
authorization read-write;
}
community CpE3677TeLmEx {
authorization read-only;
}
}
routing-options {
static {
route 172.19.0.0/24 next-hop 21.21.21.2;
route 172.17.0.0/28 next-hop 21.21.21.2;
}
autonomous-system 64839;
}
protocols {
bgp {
group CRE0108 {
type external;
hold-time 30;
export Rutas-Export;
peer-as 14080;
neighbor 10.163.245.125;
}
group IBGP {
type internal;
export IBGP;
peer-as 64839;
neighbor 21.21.21.3;
}
}
}
policy-options {
policy-statement IBGP {
term 1 {
from protocol bgp;
then {
local-preference 50;
next-hop self;
accept;
}
}
}
policy-statement Rutas-Export {
term 1 {
from {
protocol [ direct static ];
route-filter 21.21.21.0/28 exact;
route-filter 172.19.0.0/24 exact;
route-filter 172.17.0.0/28 exact;
}
then accept;
}
}
}
security {
screen {
ids-option untrust-screen {
ip {
source-route-option;
tear-drop;
}
tcp {
syn-flood {
alarm-threshold 1024;
attack-threshold 200;
source-threshold 1024;
destination-threshold 2048;
timeout 20;
}
land;
}
}
}
policies {
from-zone LAN to-zone WAN {
policy SALIDA {
match {
source-address any;
destination-address any;
application any;
}
then {
permit;
}
}
}
from-zone WAN to-zone LAN {
policy ENTRADA {
match {
source-address any;
destination-address any;
application any;
}
then {
permit;
}
}
}
from-zone LAN to-zone LAN {
policy TROUGHPUT {
match {
source-address any;
destination-address any;
application any;
}
then {
permit;
}
}
}
}
zones {
security-zone LAN {
host-inbound-traffic {
system-services {
all;
}
protocols {
all;
}
}
interfaces {
vlan.26;
}
}
security-zone WAN {
screen untrust-screen;
host-inbound-traffic {
system-services {
all;
}
protocols {
all;
}
}
interfaces {
ge-0/0/0.1357;
}
}
security-zone untrust {
host-inbound-traffic {
system-services {
snmp;
}
}
}
}
}
vlans {
LAN {
vlan-id 26;
l3-interface vlan.26;
}
}
[edit]
telmexuser@CAJA_CRE0108_BACKUP# show | display set | no-more
set version 12.1X44-D35.5
set system host-name CAJA_CRE0108_BACKUP
set system time-zone America/Bogota
set system root-authentication encrypted-password
"$1$WemwPsaP$qjEYysh6JVR4auF3KDNQS/"
set system login message
"\n\n\n\t*************************************************************\n\t*
ATENCION: Este equipo es propiedad de TELMEX Colombia. *\n\t* El uso no
autorizado esta estrictamente prohibido. *\n\t* Todos los usuarios son
legalmente responsables de sus *\n\t* acciones sobre el sistema y toda
actividad sera
registrada*\n\t*************************************************************\n\n\n"
set system login user telmexuser uid 2000
set system login user telmexuser class super-user
set system login user telmexuser authentication encrypted-password
"$1$v3XVTWsN$OQ8KfTPdq33r5IY.sf5ID1"
set system services ssh
set system services telnet
set system services xnm-clear-text
set system services web-management http interface vlan.100
set system services web-management http interface vlan.3
set system services web-management https system-generated-certificate
set system services web-management https interface vlan.100
set system syslog archive size 100k
set system syslog archive files 3
set system syslog user * any emergency
set system syslog file messages any critical
set system syslog file messages authorization info
set system syslog file interactive-commands interactive-commands error
set system max-configurations-on-flash 5
set system max-configuration-rollbacks 5
set system license autoupdate url https://ae1.juniper.net/junos/key_retrieval
set interfaces ge-0/0/0 vlan-tagging
set interfaces ge-0/0/0 unit 1357 description "--- WAN INTRANET BACKUP - CRE0108
---"
set interfaces ge-0/0/0 unit 1357 vlan-id 1357
set interfaces ge-0/0/0 unit 1357 family inet address 10.163.245.126/30
set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members LAN
set interfaces ge-0/0/2 unit 0 family ethernet-switching vlan members LAN
set interfaces ge-0/0/3 unit 0 family ethernet-switching vlan members LAN
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members LAN
set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members LAN
set interfaces ge-0/0/6 unit 0 family ethernet-switching vlan members LAN
set interfaces ge-0/0/7 unit 0 family ethernet-switching vlan members LAN
set interfaces vlan unit 26 family inet address 21.21.21.4/28 vrrp-group 2 virtual-
address 21.21.21.1
set interfaces vlan unit 26 family inet address 21.21.21.4/28 vrrp-group 2 preempt
set interfaces vlan unit 26 family inet address 21.21.21.4/28 vrrp-group 2 accept-
data
set snmp community CRpWE3677TeLmEx authorization read-write
set snmp community CpE3677TeLmEx authorization read-only
set routing-options static route 172.19.0.0/24 next-hop 21.21.21.2
set routing-options static route 172.17.0.0/28 next-hop 21.21.21.2
set routing-options autonomous-system 64839
set protocols bgp group CRE0108 type external
set protocols bgp group CRE0108 hold-time 30
set protocols bgp group CRE0108 export Rutas-Export
set protocols bgp group CRE0108 peer-as 14080
set protocols bgp group CRE0108 neighbor 10.163.245.125
set protocols bgp group IBGP type internal
set protocols bgp group IBGP export IBGP
set protocols bgp group IBGP peer-as 64839
set protocols bgp group IBGP neighbor 21.21.21.3
set policy-options policy-statement IBGP term 1 from protocol bgp
set policy-options policy-statement IBGP term 1 then local-preference 50
set policy-options policy-statement IBGP term 1 then next-hop self
set policy-options policy-statement IBGP term 1 then accept
set policy-options policy-statement Rutas-Export term 1 from protocol direct
set policy-options policy-statement Rutas-Export term 1 from protocol static
set policy-options policy-statement Rutas-Export term 1 from route-filter
21.21.21.0/28 exact
set policy-options policy-statement Rutas-Export term 1 from route-filter
172.19.0.0/24 exact
set policy-options policy-statement Rutas-Export term 1 from route-filter
172.17.0.0/28 exact
set policy-options policy-statement Rutas-Export term 1 then accept
set security screen ids-option untrust-screen ip source-route-option
set security screen ids-option untrust-screen ip tear-drop
set security screen ids-option untrust-screen tcp syn-flood alarm-threshold 1024
set security screen ids-option untrust-screen tcp syn-flood attack-threshold 200
set security screen ids-option untrust-screen tcp syn-flood source-threshold 1024
set security screen ids-option untrust-screen tcp syn-flood destination-threshold
2048
set security screen ids-option untrust-screen tcp syn-flood timeout 20
set security screen ids-option untrust-screen tcp land
set security policies from-zone LAN to-zone WAN policy SALIDA match source-address
any
set security policies from-zone LAN to-zone WAN policy SALIDA match destination-
address any
set security policies from-zone LAN to-zone WAN policy SALIDA match application any
set security policies from-zone LAN to-zone WAN policy SALIDA then permit
set security policies from-zone WAN to-zone LAN policy ENTRADA match source-address
any
set security policies from-zone WAN to-zone LAN policy ENTRADA match destination-
address any
set security policies from-zone WAN to-zone LAN policy ENTRADA match application
any
set security policies from-zone WAN to-zone LAN policy ENTRADA then permit
set security policies from-zone LAN to-zone LAN policy TROUGHPUT match source-
address any
set security policies from-zone LAN to-zone LAN policy TROUGHPUT match destination-
address any
set security policies from-zone LAN to-zone LAN policy TROUGHPUT match application
any
set security policies from-zone LAN to-zone LAN policy TROUGHPUT then permit
set security zones security-zone LAN host-inbound-traffic system-services all
set security zones security-zone LAN host-inbound-traffic protocols all
set security zones security-zone LAN interfaces vlan.26
set security zones security-zone WAN screen untrust-screen
set security zones security-zone WAN host-inbound-traffic system-services all
set security zones security-zone WAN host-inbound-traffic protocols all
set security zones security-zone WAN interfaces ge-0/0/0.1357
set security zones security-zone untrust host-inbound-traffic system-services snmp
set vlans LAN vlan-id 26
set vlans LAN l3-interface vlan.26
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run request system configuration rescue save
run show security group-vpn member ipsec statistics index XXXXXX | no-more
run show security group-vpn member ipsec statistics index XXXXX | no-more
run show route protocol bgp | no-more
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ipsec statistics
index XXXXXX
^
Invalid numeric value: 'XXXXXX' at 'XXXXXX'
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ipsec statistics
index XXXXXX|
^
Invalid numeric value: 'XXXXXX'.
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ipsec statistics
index XXXXXX|no-more
^
Invalid numeric value: 'XXXXXX'.
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ipsec statistics
index XXXXX
^
Invalid numeric value: 'XXXXX' at 'XXXXX'
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ipsec statistics
index XXXXX|
^
Invalid numeric value: 'XXXXX'.
telmexuser@CAJA_CRE0108_BACKUP# run show security group-vpn member ipsec statistics
index XXXXX|no-more
^
Invalid numeric value: 'XXXXX'.
[edit]
telmexuser@CAJA_CRE0108_BACKUP# run show route protocol bgp | no-more
[edit]
telmexuser@CAJA_CRE0108_BACKUP#