NJ
NJ
! Chassis:
system name "NHJ-JED-DC-CoreSW"
system location "NARCISUSS88-JED"
! Configuration:
configuration error-file-limit 2
! Capability Manager:
! Virtual Flow Control:
! LFP:
! Interface:
interfaces port 1/1/13 autoneg disable
! Port_Manager:
! Link Aggregate:
linkagg lacp agg 1 size 2 admin-state enable
linkagg lacp agg 1 actor admin-key 1
linkagg lacp agg 2 size 2 admin-state enable
linkagg lacp agg 2 actor admin-key 2
linkagg lacp agg 3 size 2 admin-state enable
linkagg lacp agg 3 actor admin-key 3
linkagg lacp agg 4 size 2 admin-state enable
linkagg lacp agg 4 actor admin-key 4
linkagg lacp agg 5 size 2 admin-state enable
linkagg lacp agg 5 actor admin-key 5
linkagg lacp agg 6 size 2 admin-state enable
linkagg lacp agg 6 actor admin-key 6
linkagg lacp agg 7 size 2 admin-state enable
linkagg lacp agg 7 actor admin-key 7
linkagg lacp agg 8 size 2 admin-state enable
linkagg lacp agg 8 actor admin-key 8
linkagg lacp agg 9 size 2 admin-state enable
linkagg lacp agg 9 actor admin-key 9
linkagg lacp agg 12 size 2 admin-state enable
linkagg lacp agg 12 actor admin-key 12
linkagg lacp agg 127 size 16 hash tunnel-protocol admin-state enable
linkagg lacp agg 127 name "Created by Auto-Fabric on Wed May 8 13:57:50 2019"
linkagg lacp agg 127 actor admin-key 65535
linkagg lacp port 1/1/1 actor admin-key 1
linkagg lacp port 1/1/2 actor admin-key 2
linkagg lacp port 1/1/3 actor admin-key 3
linkagg lacp port 1/1/4 actor admin-key 4
linkagg lacp port 1/1/5 actor admin-key 5
linkagg lacp port 1/1/6 actor admin-key 6
linkagg lacp port 1/1/7 actor admin-key 7
linkagg lacp port 1/1/8 actor admin-key 8
linkagg lacp port 1/1/9 actor admin-key 9
linkagg lacp port 1/1/12 actor admin-key 12
linkagg lacp port 2/1/1 actor admin-key 1
linkagg lacp port 2/1/2 actor admin-key 2
linkagg lacp port 2/1/3 actor admin-key 3
linkagg lacp port 2/1/4 actor admin-key 4
linkagg lacp port 2/1/5 actor admin-key 5
linkagg lacp port 2/1/6 actor admin-key 6
linkagg lacp port 2/1/7 actor admin-key 7
linkagg lacp port 2/1/8 actor admin-key 8
linkagg lacp port 2/1/9 actor admin-key 9
linkagg lacp port 2/1/12 actor admin-key 12
! VLAN:
vlan 1 admin-state disable
vlan 5-6 admin-state enable
vlan 5 name "RoutingControl"
vlan 6 name "MPLS"
vlan 10-16 admin-state enable
vlan 10 name "NW MGMT"
vlan 11 name "Server Farm"
vlan 12 name "IPTV"
vlan 13 name "CCTV"
vlan 14 name "AP MGMT"
vlan 15 name "Admin LAN"
vlan 16 name "Guest-Wifi"
vlan 24 admin-state enable
vlan 24 name "Voice"
vlan 26-29 admin-state enable
vlan 26 name "Mobile-Voice"
vlan 27 name "AV"
vlan 28 name "BMS & LGT"
vlan 29 name "GRMS"
vlan 35 admin-state enable
vlan 35 name "Internet LAN"
spb bvlan 4000-4015 admin-state enable
spb bvlan 4000-4015 name "AutoFabric 4/17/2019 14:12:54"
vlan 6 members port 1/1/15 untagged
vlan 6 members port 2/1/13 untagged
vlan 11 members port 1/1/14 untagged
vlan 12 members port 1/1/17 untagged
vlan 24 members port 1/1/16 untagged
vlan 10 members linkagg 1-9 tagged
vlan 10 members linkagg 12 tagged
vlan 11 members linkagg 1-9 tagged
vlan 11 members linkagg 12 tagged
vlan 12 members linkagg 1-9 tagged
vlan 12 members linkagg 12 tagged
vlan 13 members linkagg 1-9 tagged
vlan 13 members linkagg 12 tagged
vlan 14 members linkagg 1-9 tagged
vlan 14 members linkagg 12 tagged
vlan 15 members linkagg 1-9 tagged
vlan 15 members linkagg 12 tagged
vlan 16 members port 1/1/13 tagged
vlan 16 members linkagg 1-9 tagged
vlan 16 members linkagg 12 tagged
vlan 24 members linkagg 1-9 tagged
vlan 24 members linkagg 12 tagged
vlan 26 members linkagg 1-9 tagged
vlan 26 members linkagg 12 tagged
vlan 27 members linkagg 1-9 tagged
vlan 27 members linkagg 12 tagged
vlan 28 members linkagg 1-9 tagged
vlan 28 members linkagg 12 tagged
vlan 29 members linkagg 1-9 tagged
vlan 29 members linkagg 12 tagged
vlan 35 members linkagg 1-9 tagged
vlan 35 members linkagg 12 tagged
! PVLAN:
! Spanning Tree:
spantree vlan 1 admin-state enable
spantree vlan 5 admin-state enable
spantree vlan 6 admin-state enable
spantree vlan 10 admin-state enable
spantree vlan 11 admin-state enable
spantree vlan 12 admin-state enable
spantree vlan 13 admin-state enable
spantree vlan 14 admin-state enable
spantree vlan 15 admin-state enable
spantree vlan 16 admin-state enable
spantree vlan 24 admin-state enable
spantree vlan 26 admin-state enable
spantree vlan 27 admin-state enable
spantree vlan 28 admin-state enable
spantree vlan 29 admin-state enable
spantree vlan 35 admin-state enable
spantree vlan 4000 admin-state disable
spantree vlan 4001 admin-state disable
spantree vlan 4002 admin-state disable
spantree vlan 4003 admin-state disable
spantree vlan 4004 admin-state disable
spantree vlan 4005 admin-state disable
spantree vlan 4006 admin-state disable
spantree vlan 4007 admin-state disable
spantree vlan 4008 admin-state disable
spantree vlan 4009 admin-state disable
spantree vlan 4010 admin-state disable
spantree vlan 4011 admin-state disable
spantree vlan 4012 admin-state disable
spantree vlan 4013 admin-state disable
spantree vlan 4014 admin-state disable
spantree vlan 4015 admin-state disable
! DA-UNP:
! Bridging:
! Port Mirroring:
port-monitoring 1 source port 1/1/15 file /flash/non_issue_state.enc size 256
timeout 0 bidirectional capture-type full enable
port-monitoring 1 disable
! Port Mapping:
! IP:
ip interface "GRMS" address 10.101.29.1 mask 255.255.255.0 vlan 29 ifindex 1
ip interface "NW MGMT" address 10.101.10.1 mask 255.255.255.0 vlan 10 ifindex 2
ip interface "Server Farm" address 10.101.11.1 mask 255.255.255.0 vlan 11 ifindex 3
ip interface "IPTV" address 10.101.12.1 mask 255.255.255.0 vlan 12 ifindex 4
ip interface "CCTV" address 10.101.13.1 mask 255.255.255.0 vlan 13 ifindex 5
ip interface "AP MGMT" address 10.101.14.1 mask 255.255.255.0 vlan 14 ifindex 6
ip interface "Admin LAN" address 10.101.15.1 mask 255.255.255.0 vlan 15 ifindex 7
ip interface "Guest-Wifi" address 10.101.16.1 mask 255.255.248.0 vlan 16 ifindex 8
ip interface "Voice" address 10.101.24.1 mask 255.255.254.0 vlan 24 ifindex 9
ip interface "Mobile-Voice" address 10.101.26.1 mask 255.255.255.0 vlan 26 ifindex
10
ip interface "AV" address 10.101.27.1 mask 255.255.255.0 vlan 27 ifindex 11
ip interface "BMS & LGT" address 10.101.28.1 mask 255.255.255.0 vlan 28 ifindex 12
ip interface "Internet LAN" address 10.101.35.1 mask 255.255.255.240 vlan 35
ifindex 13
ip interface "MPLS Trffic" address 10.101.6.1 mask 255.255.255.0 vlan 6 ifindex 14
ip interface "RoutingControl" address 10.101.5.1 mask 255.255.255.0 vlan 5 ifindex
15
ip dos type unicast-ip-mcast-mac admin-state disable
! IPv6:
! IPSec:
! IPMS:
ip multicast admin-state enable
ip multicast querying enable
ip multicast querier-forwarding enable
! AAA:
aaa authentication default "local"
aaa authentication console "local"
aaa authentication telnet "local"
aaa authentication ftp "local"
aaa authentication snmp "local"
! NTP:
! QOS:
policy service SIP_Service source udp-port 5059-5060
policy network group NG1 10.101.5.0 mask 255.255.255.0 10.101.6.0 mask
255.255.255.0 10.101.10.0 mask 255.255.255.0 10.101.11.0 mask 255.255.255.0
10.101.12.0 mask 255.255.255.0
policy network group NG1 10.101.13.0 mask 255.255.255.0 10.101.14.0 mask
255.255.255.0 10.101.15.0 mask 255.255.255.0 10.101.16.0 mask 255.255.255.0
10.101.24.0 mask 255.255.254.0
policy network group NG1 10.101.26.0 mask 255.255.255.0 10.101.27.0 mask
255.255.255.0 10.101.28.0 mask 255.255.255.0 10.101.29.0 mask 255.255.255.0
policy network group NG2 10.101.11.0 mask 255.255.255.0 10.101.15.0 mask
255.255.255.0 10.101.24.0 mask 255.255.254.0
policy network group SIP-SUBNET 10.101.24.0 mask 255.255.254.0
policy condition InterVlanRouting source network group NG2 destination network
group NG1
policy condition SIP-SUBNET source network group SIP-SUBNET destination ip Any
policy condition toTopNetFW source network group NG2 destination ip Any
policy action ALLOW
policy action toFireWall permanent gateway-ip 10.101.6.2
policy rule SIP-RULE disable precedence 800 condition SIP-SUBNET action toFireWall
policy rule InternalTraffic precedence 600 condition InterVlanRouting action ALLOW
policy rule ExternalTraffic precedence 500 condition toTopNetFW action toFireWall
qos apply
! Policy Manager:
! VLAN Stacking:
! ERP:
! MVRP:
! LLDP:
! UDLD:
! Server Load Balance:
! High Availability Vlan:
! Session Manager:
session cli timeout 100
session prompt default "NHJ-JED-CoreSW -->"
! Web:
! Trap Manager:
snmp station 10.101.10.5 162 "snmpuser" v3 enable
! Health Monitor:
! System Service:
swlog appid MIP_GATEWAY subapp all level error
swlog appid ipni subapp 7 level off
system timezone AST
! SNMP:
snmp security authentication all
! BFD:
! IP Route Manager:
ip router router-id 10.101.36.2
ip static-route 0.0.0.0/0 gateway 10.101.11.2 metric 1
ip static-route 10.101.11.0/24 gateway 10.101.6.2 metric 1
ip static-route 10.101.15.0/24 gateway 10.101.6.2 metric 1
ip static-route 10.141.40.224/32 gateway 10.101.24.18 metric 1
ip static-route 10.170.9.0/24 gateway 10.101.24.18 metric 1
ip static-route 10.101.24.0/23 gateway 10.101.24.18 metric 1
! VRRP:
! UDP Relay:
! RIP:
! OSPF:
ip load ospf
! IP Multicast:
! DVMRP:
! IPMR:
! RIPng:
! OSPF3:
! BGP:
! ISIS:
! Module:
! LAN Power:
! RDP:
! DHL:
! Ethernet-OAM:
! SAA:
! SPB-ISIS:
spb isis bvlan 4000 ect-id 1
spb isis bvlan 4001 ect-id 2
spb isis bvlan 4002 ect-id 3
spb isis bvlan 4003 ect-id 4
spb isis bvlan 4004 ect-id 5
spb isis bvlan 4005 ect-id 6
spb isis bvlan 4006 ect-id 7
spb isis bvlan 4007 ect-id 8
spb isis bvlan 4008 ect-id 9
spb isis bvlan 4009 ect-id 10
spb isis bvlan 4010 ect-id 11
spb isis bvlan 4011 ect-id 12
spb isis bvlan 4012 ect-id 13
spb isis bvlan 4013 ect-id 14
spb isis bvlan 4014 ect-id 15
spb isis bvlan 4015 ect-id 16
spb isis control-bvlan 4000
spb isis interface linkagg 12
spb isis interface linkagg 127
! SVCMGR:
service stats disable
! LDP:
! EVB:
! APP-FINGERPRINT:
! FCOE:
! QMR:
! OPENFLOW:
! Dynamic auto-fabric:
auto-fabric interface 1/1/12 admin-state disable
! SIP Snooping:
! DHCP Server:
dhcp-server enable
! DHCPv6 Relay:
! DHCPv6 Snooping:
! DHCPv6 Server:
! DHCP Message Service:
! DHCP Active Lease Service:
! Virtual Chassis Split Protection:
! DHCP Snooping:
! APP-MONITORING:
! Loopback Detection:
! VM-SNOOPING:
! PPPOE-IA:
! Security:
! Zero Configuration:
! MAC Security:
! OVC:
! EFM-OAM:
! ALARM-MANAGER:
! DEVICE-PROFILE:
! PTP:
! IP DHCP RELAY:
ip dhcp relay admin-state enable
ip dhcp relay per-interface-mode
ip dhcp relay interface Voice destination 10.101.24.10
ip dhcp relay interface Voice admin-state enable
! TEST-OAM:
! LOOPBACK TEST:
! UDP6 RELAY:
! MGMT AGENT: