Advertisement
Guest User

Untitled

a guest
Nov 24th, 2017
141
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 15.30 KB | None | 0 0
  1. no spanning-tree
  2. !
  3. vlan database
  4. vlan 50,249,1108,1149,3458
  5. exit
  6. !
  7. loopback-detection enable
  8. loopback-detection interval 10
  9. !
  10. errdisable recovery interval 60
  11. errdisable recovery cause loopback-detection
  12. errdisable recovery cause port-security
  13. errdisable recovery cause dot1x-src-address
  14. errdisable recovery cause acl-deny
  15. errdisable recovery cause stp-bpdu-guard
  16. errdisable recovery cause stp-loopback-guard
  17. errdisable recovery cause unidirectional-link
  18. errdisable recovery cause storm-control
  19. errdisable recovery cause l2pt-guard
  20. !
  21. ip dhcp relay address 10.10.10.144
  22. ip dhcp relay enable
  23. ip dhcp information option
  24. ip dhcp relay information option format-type option pv delimeter space
  25. ip dhcp information option format-type option pv delimeter space
  26. !
  27. ip igmp snooping
  28. ip igmp snooping vlan 1149
  29. !
  30. ip access-list extended 1
  31. permit udp any any any bootps ace-priority 20
  32. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  33. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  34. deny ip any any ace-priority 80
  35. exit
  36. !
  37. ip access-list extended 2
  38. permit udp any any any bootps ace-priority 20
  39. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  40. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  41. deny ip any any ace-priority 80
  42. exit
  43. !
  44. ip access-list extended 3
  45. permit udp any any any bootps ace-priority 20
  46. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  47. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  48. deny ip any any ace-priority 80
  49. exit
  50. !
  51. ip access-list extended 4
  52. permit udp any any any bootps ace-priority 20
  53. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  54. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  55. deny ip any any ace-priority 80
  56. exit
  57. !
  58. ip access-list extended 5
  59. permit udp any any any bootps ace-priority 20
  60. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  61. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  62. deny ip any any ace-priority 80
  63. exit
  64. !
  65. ip access-list extended 6
  66. permit udp any any any bootps ace-priority 20
  67. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  68. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  69. deny ip any any ace-priority 80
  70. exit
  71. !
  72. ip access-list extended 7
  73. permit udp any any any bootps ace-priority 20
  74. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  75. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  76. deny ip any any ace-priority 80
  77. exit
  78. !
  79. ip access-list extended 8
  80. permit udp any any any bootps ace-priority 20
  81. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  82. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  83. deny ip any any ace-priority 80
  84. exit
  85. !
  86. ip access-list extended 9
  87. permit udp any any any bootps ace-priority 20
  88. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  89. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  90. deny ip any any ace-priority 80
  91. exit
  92. !
  93. ip access-list extended 10
  94. permit udp any any any bootps ace-priority 20
  95. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  96. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  97. deny ip any any ace-priority 80
  98. exit
  99. !
  100. ip access-list extended 11
  101. permit udp any any any bootps ace-priority 20
  102. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  103. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  104. deny ip any any ace-priority 80
  105. exit
  106. !
  107. ip access-list extended 12
  108. permit udp any any any bootps ace-priority 20
  109. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  110. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  111. deny ip any any ace-priority 80
  112. exit
  113. !
  114. ip access-list extended 13
  115. permit udp any any any bootps ace-priority 20
  116. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  117. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  118. deny ip any any ace-priority 80
  119. exit
  120. !
  121. ip access-list extended 14
  122. permit udp any any any bootps ace-priority 20
  123. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  124. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  125. deny ip any any ace-priority 80
  126. exit
  127. !
  128. ip access-list extended 15
  129. permit udp any any any bootps ace-priority 20
  130. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  131. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  132. deny ip any any ace-priority 80
  133. exit
  134. !
  135. ip access-list extended 16
  136. permit udp any any any bootps ace-priority 20
  137. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  138. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  139. deny ip any any ace-priority 80
  140. exit
  141. !
  142. ip access-list extended 17
  143. permit udp any any any bootps ace-priority 20
  144. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  145. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  146. deny ip any any ace-priority 80
  147. exit
  148. !
  149. ip access-list extended 18
  150. permit udp any any any bootps ace-priority 20
  151. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  152. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  153. deny ip any any ace-priority 80
  154. exit
  155. !
  156. ip access-list extended 19
  157. permit udp any any any bootps ace-priority 20
  158. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  159. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  160. deny ip any any ace-priority 80
  161. exit
  162. !
  163. ip access-list extended 20
  164. permit udp any any any bootps ace-priority 20
  165. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  166. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  167. deny ip any any ace-priority 80
  168. exit
  169. !
  170. ip access-list extended 21
  171. permit udp any any any bootps ace-priority 20
  172. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  173. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  174. deny ip any any ace-priority 80
  175. exit
  176. !
  177. ip access-list extended 22
  178. permit udp any any any bootps ace-priority 20
  179. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  180. permit ip 10.222.0.0 0.0.255.255 any ace-priority 60
  181. deny ip any any ace-priority 80
  182. exit
  183. !
  184. ip access-list extended 23
  185. permit udp any any any bootps ace-priority 20
  186. permit ip 10.220.0.0 0.0.255.255 any ace-priority 40
  187. exit
  188. !
  189. !
  190. hostname MES-10.170.108.226
  191. !
  192. encrypted radius-server host 10.10.10.3 timeout 2 key CPzJEbLlNb3ebb88+X8FLFZ3ekeomvMRTtwLMeH3o8E=
  193. !
  194. management access-list vty
  195. permit ip-source 10.10.0.0 mask 255.255.0.0
  196. permit ip-source 10.201.52.0 mask 255.255.255.0
  197. permit ip-source 10.170.0.0 mask 255.255.0.0
  198. permit ip-source 10.114.139.0 mask 255.255.255.0
  199. exit
  200. !
  201. management access-class vty
  202. !
  203. logging host 10.10.10.3
  204. no logging console
  205. logging file informational
  206. !
  207. line telnet
  208. exec-timeout 60
  209. exit
  210. !
  211. line ssh
  212. exec-timeout 60
  213. exit
  214. !
  215. username admin password encrypted f3107e9e34e8582925197d707d9650587ad27742 privilege 15
  216. !
  217. ip ssh server
  218. !
  219. snmp-server server
  220. encrypted snmp-server community hXKI/nU2kUzqKGixTrnUEJk2X9/GnPd4ihiuEf9vIco= ro view Default
  221. !
  222. !
  223. aaa authentication login default radius local
  224. !
  225. no ip http server
  226. !
  227. clock timezone MSK +3
  228. !
  229. sntp server 10.10.10.3
  230. !
  231. no ip domain lookup
  232. ip domain name ip-home.net
  233. ip name-server 10.10.10.3
  234. !
  235. backup server tftp://10.10.10.200
  236. backup path /
  237. backup time-period 86400
  238. backup auto
  239. !
  240. interface gigabitethernet1/0/1
  241. loopback-detection enable
  242. bridge multicast unregistered filtering
  243. port security mode max-addresses
  244. port security discard
  245. service-acl input 1
  246. switchport access vlan 3458
  247. switchport access multicast-tv vlan 1149
  248. lldp notifications enable
  249. switchport forbidden default-vlan
  250. exit
  251. !
  252. interface gigabitethernet1/0/2
  253. loopback-detection enable
  254. bridge multicast unregistered filtering
  255. port security mode max-addresses
  256. port security discard
  257. service-acl input 2
  258. switchport access vlan 3458
  259. switchport access multicast-tv vlan 1149
  260. lldp notifications enable
  261. switchport forbidden default-vlan
  262. exit
  263. !
  264. interface gigabitethernet1/0/3
  265. loopback-detection enable
  266. bridge multicast unregistered filtering
  267. port security mode max-addresses
  268. port security discard
  269. service-acl input 3
  270. switchport access vlan 3458
  271. switchport access multicast-tv vlan 1149
  272. lldp notifications enable
  273. switchport forbidden default-vlan
  274. exit
  275. !
  276. interface gigabitethernet1/0/4
  277. loopback-detection enable
  278. bridge multicast unregistered filtering
  279. port security mode max-addresses
  280. port security discard
  281. service-acl input 4
  282. switchport access vlan 3458
  283. switchport access multicast-tv vlan 1149
  284. lldp notifications enable
  285. switchport forbidden default-vlan
  286. exit
  287. !
  288. interface gigabitethernet1/0/5
  289. loopback-detection enable
  290. bridge multicast unregistered filtering
  291. port security mode max-addresses
  292. port security discard
  293. service-acl input 5
  294. switchport access vlan 3458
  295. switchport access multicast-tv vlan 1149
  296. lldp notifications enable
  297. switchport forbidden default-vlan
  298. exit
  299. !
  300. interface gigabitethernet1/0/6
  301. loopback-detection enable
  302. bridge multicast unregistered filtering
  303. port security mode max-addresses
  304. port security discard
  305. service-acl input 6
  306. switchport access vlan 3458
  307. switchport access multicast-tv vlan 1149
  308. lldp notifications enable
  309. switchport forbidden default-vlan
  310. exit
  311. !
  312. interface gigabitethernet1/0/7
  313. loopback-detection enable
  314. bridge multicast unregistered filtering
  315. port security mode max-addresses
  316. port security discard
  317. service-acl input 7
  318. switchport access vlan 3458
  319. switchport access multicast-tv vlan 1149
  320. lldp notifications enable
  321. switchport forbidden default-vlan
  322. exit
  323. !
  324. interface gigabitethernet1/0/8
  325. loopback-detection enable
  326. bridge multicast unregistered filtering
  327. port security mode max-addresses
  328. port security discard
  329. service-acl input 8
  330. switchport access vlan 3458
  331. switchport access multicast-tv vlan 1149
  332. lldp notifications enable
  333. switchport forbidden default-vlan
  334. exit
  335. !
  336. interface gigabitethernet1/0/9
  337. loopback-detection enable
  338. bridge multicast unregistered filtering
  339. port security mode max-addresses
  340. port security discard
  341. service-acl input 9
  342. switchport access vlan 3458
  343. switchport access multicast-tv vlan 1149
  344. lldp notifications enable
  345. switchport forbidden default-vlan
  346. exit
  347. !
  348. interface gigabitethernet1/0/10
  349. loopback-detection enable
  350. bridge multicast unregistered filtering
  351. port security mode max-addresses
  352. port security discard
  353. service-acl input 10
  354. switchport access vlan 3458
  355. switchport access multicast-tv vlan 1149
  356. lldp notifications enable
  357. switchport forbidden default-vlan
  358. exit
  359. !
  360. interface gigabitethernet1/0/11
  361. loopback-detection enable
  362. bridge multicast unregistered filtering
  363. port security mode max-addresses
  364. port security discard
  365. service-acl input 11
  366. switchport access vlan 3458
  367. switchport access multicast-tv vlan 1149
  368. lldp notifications enable
  369. switchport forbidden default-vlan
  370. exit
  371. !
  372. interface gigabitethernet1/0/12
  373. loopback-detection enable
  374. bridge multicast unregistered filtering
  375. port security mode max-addresses
  376. port security discard
  377. service-acl input 12
  378. switchport access vlan 3458
  379. switchport access multicast-tv vlan 1149
  380. lldp notifications enable
  381. switchport forbidden default-vlan
  382. exit
  383. !
  384. interface gigabitethernet1/0/13
  385. loopback-detection enable
  386. bridge multicast unregistered filtering
  387. port security mode max-addresses
  388. port security discard
  389. service-acl input 13
  390. switchport access vlan 3458
  391. switchport access multicast-tv vlan 1149
  392. lldp notifications enable
  393. switchport forbidden default-vlan
  394. exit
  395. !
  396. interface gigabitethernet1/0/14
  397. loopback-detection enable
  398. bridge multicast unregistered filtering
  399. port security mode max-addresses
  400. port security discard
  401. service-acl input 14
  402. switchport access vlan 3458
  403. switchport access multicast-tv vlan 1149
  404. lldp notifications enable
  405. switchport forbidden default-vlan
  406. exit
  407. !
  408. interface gigabitethernet1/0/15
  409. loopback-detection enable
  410. bridge multicast unregistered filtering
  411. port security mode max-addresses
  412. port security discard
  413. service-acl input 15
  414. switchport access vlan 3458
  415. switchport access multicast-tv vlan 1149
  416. lldp notifications enable
  417. switchport forbidden default-vlan
  418. exit
  419. !
  420. interface gigabitethernet1/0/16
  421. loopback-detection enable
  422. bridge multicast unregistered filtering
  423. port security mode max-addresses
  424. port security discard
  425. service-acl input 16
  426. switchport access vlan 3458
  427. switchport access multicast-tv vlan 1149
  428. lldp notifications enable
  429. switchport forbidden default-vlan
  430. exit
  431. !
  432. interface gigabitethernet1/0/17
  433. loopback-detection enable
  434. bridge multicast unregistered filtering
  435. port security mode max-addresses
  436. port security discard
  437. service-acl input 17
  438. switchport access vlan 3458
  439. switchport access multicast-tv vlan 1149
  440. lldp notifications enable
  441. switchport forbidden default-vlan
  442. exit
  443. !
  444. interface gigabitethernet1/0/18
  445. loopback-detection enable
  446. bridge multicast unregistered filtering
  447. port security mode max-addresses
  448. port security discard
  449. service-acl input 18
  450. switchport access vlan 3458
  451. switchport access multicast-tv vlan 1149
  452. lldp notifications enable
  453. switchport forbidden default-vlan
  454. exit
  455. !
  456. interface gigabitethernet1/0/19
  457. loopback-detection enable
  458. bridge multicast unregistered filtering
  459. port security mode max-addresses
  460. port security discard
  461. service-acl input 19
  462. switchport access vlan 3458
  463. switchport access multicast-tv vlan 1149
  464. lldp notifications enable
  465. switchport forbidden default-vlan
  466. exit
  467. !
  468. interface gigabitethernet1/0/20
  469. loopback-detection enable
  470. bridge multicast unregistered filtering
  471. port security mode max-addresses
  472. port security discard
  473. service-acl input 20
  474. switchport access vlan 3458
  475. switchport access multicast-tv vlan 1149
  476. lldp notifications enable
  477. switchport forbidden default-vlan
  478. exit
  479. !
  480. interface gigabitethernet1/0/21
  481. loopback-detection enable
  482. bridge multicast unregistered filtering
  483. port security mode max-addresses
  484. port security discard
  485. service-acl input 21
  486. switchport access vlan 3458
  487. switchport access multicast-tv vlan 1149
  488. lldp notifications enable
  489. switchport forbidden default-vlan
  490. exit
  491. !
  492. interface gigabitethernet1/0/22
  493. loopback-detection enable
  494. bridge multicast unregistered filtering
  495. port security mode max-addresses
  496. port security discard
  497. service-acl input 22
  498. switchport access vlan 3458
  499. switchport access multicast-tv vlan 1149
  500. lldp notifications enable
  501. switchport forbidden default-vlan
  502. exit
  503. !
  504. interface gigabitethernet1/0/23
  505. loopback-detection enable
  506. bridge multicast unregistered filtering
  507. port security mode max-addresses
  508. port security discard
  509. switchport access vlan 3458
  510. switchport access multicast-tv vlan 1149
  511. lldp notifications enable
  512. switchport forbidden default-vlan
  513. exit
  514. !
  515. interface gigabitethernet1/0/24
  516. loopback-detection enable
  517. bridge multicast unregistered filtering
  518. port security mode max-addresses
  519. switchport mode trunk
  520. switchport trunk allowed vlan add 50
  521. lldp notifications enable
  522. switchport forbidden default-vlan
  523. exit
  524. !
  525. interface tengigabitethernet1/0/1
  526. switchport mode trunk
  527. switchport trunk allowed vlan add 1108,1149,3458
  528. exit
  529. !
  530. interface tengigabitethernet1/0/2
  531. switchport mode trunk
  532. switchport trunk allowed vlan add 1108,1149,3458
  533. exit
  534. !
  535. interface tengigabitethernet1/0/3
  536. switchport mode trunk
  537. switchport trunk allowed vlan add 1108,1149,3458
  538. exit
  539. !
  540. interface tengigabitethernet1/0/4
  541. switchport mode trunk
  542. switchport trunk allowed vlan add 1108,1149,3458
  543. switchport forbidden default-vlan
  544. exit
  545. !
  546. interface vlan 50
  547. ip address 10.10.10.180 255.255.255.0
  548. exit
  549. !
  550. interface vlan 1108
  551. ip address 10.170.108.226 255.255.255.0
  552. exit
  553. !
  554. interface vlan 3458
  555. ip dhcp relay enable
  556. exit
  557. !
  558. !
  559. ip default-gateway 10.10.10.254
  560. !
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement