Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ## Last commit: 2023-11-14 18:09:17 CST by admin
- version 12.3R12.4;
- groups {
- MDC-TACACS {
- system {
- tacplus-server {
- 10.20.11.2 {
- secret "fake secret"; ## SECRET-DATA
- timeout 2;
- }
- }
- }
- }
- }
- system {
- host-name mdc-sw1-prod;
- domain-name mgmt.mdc.com;
- time-zone America/Chicago;
- authentication-order tacplus;
- root-authentication {
- encrypted-password "fake password"; ## SECRET-DATA
- }
- name-server {
- 10.20.11.2;
- }
- accounting {
- events [ login change-log interactive-commands ];
- destination {
- tacplus {
- server {
- 10.20.11.2;
- }
- }
- }
- }
- login {
- message "\n########################################################################\n# THIS SYSTEM IS RESTRICTED TO AUTHORIZED USAGE! #\n# #\n# Unauthorized usage will be subject to criminal penalties, fines, #\n# damages and/or disciplinary action. If you are not authorized to use #\n# this system, you must exit immediately. If you are authorized to #\n# use this system, you must do so in compliance with all laws, #\n# regulations, conduct rules, and company security policies applicable #\n# to this system. This system, including any hardware components, #\n# software, workstations, and storage spaces is subject to monitoring #\n# and search without advanced notice. Users should have no expectation #\n# of privacy in their use of any aspect of this system. #\n########################################################################\n\n";
- retry-options {
- tries-before-disconnect 3;
- backoff-threshold 2;
- lockout-period 5;
- }
- user admin {
- full-name Administrator;
- uid 2000;
- class super-user;
- authentication {
- encrypted-password "fake password"; ## SECRET-DATA
- }
- }
- user remote {
- uid 2001;
- class superuser;
- }
- }
- services {
- ssh {
- root-login deny;
- protocol-version v2;
- }
- web-management {
- http {
- interface vlan.1016;
- }
- }
- dhcp {
- traceoptions {
- file dhcp_logfile;
- level all;
- flag all;
- }
- }
- }
- syslog {
- user * {
- any emergency;
- }
- host 10.20.11.2 {
- any any;
- }
- file messages {
- any notice;
- authorization info;
- }
- file interactive-commands {
- interactive-commands any;
- }
- time-format year millisecond;
- }
- ntp;
- }
- chassis {
- auto-image-upgrade;
- }
- interfaces {
- ge-0/0/0 {
- unit 0 {
- family ethernet-switching {
- port-mode trunk;
- vlan {
- members all;
- }
- }
- }
- }
- ge-0/0/1 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/2 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/3 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/4 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/5 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/6 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/7 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/8 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/9 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/10 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/11 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/12 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/13 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/14 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/15 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/16 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/17 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/18 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/19 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/20 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/21 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/22 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/23 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/24 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/25 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/26 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/27 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/28 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/29 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/30 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/31 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/32 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/33 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/34 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/35 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/36 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/37 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/38 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/39 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/40 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/41 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/42 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/43 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/44 {
- disable;
- unit 0 {
- description Access;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3616;
- }
- }
- }
- }
- ge-0/0/45 {
- unit 0 {
- description VLAN2328;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN2328;
- }
- }
- }
- }
- ge-0/0/46 {
- unit 0 {
- description VLAN3516;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN3516;
- }
- }
- }
- }
- ge-0/0/47 {
- unit 0 {
- description VLAN2116;
- family ethernet-switching {
- port-mode access;
- vlan {
- members VLAN2116;
- }
- }
- }
- }
- ge-0/1/0 {
- unit 0 {
- description Trunk;
- family ethernet-switching {
- port-mode trunk;
- vlan {
- members all;
- }
- native-vlan-id 999;
- }
- }
- }
- ge-0/1/1 {
- unit 0 {
- description Trunk;
- family ethernet-switching {
- port-mode trunk;
- vlan {
- members all;
- }
- native-vlan-id 999;
- }
- }
- }
- ge-0/1/2 {
- ether-options {
- 802.3ad ae3;
- }
- }
- ge-0/1/3 {
- ether-options {
- 802.3ad ae3;
- }
- }
- ae3 {
- description "LACP Core 1";
- aggregated-ether-options {
- lacp {
- active;
- }
- }
- unit 0 {
- family ethernet-switching {
- port-mode trunk;
- vlan {
- members all;
- }
- native-vlan-id 999;
- }
- }
- }
- me0 {
- unit 0 {
- family inet {
- address 10.192.0.5/24;
- }
- }
- }
- vlan {
- unit 0 {
- family inet {
- dhcp {
- vendor-id Juniper-ex2200-48p-4g;
- }
- }
- }
- unit 1016 {
- family inet {
- address 10.10.16.6/24;
- }
- }
- }
- }
- snmp {
- description "MDC Edge Switch 1";
- location "MDC 327 Rack 1";
- filter-duplicates;
- community fakeRO {
- authorization read-only;
- }
- community fakeRW {
- authorization read-write;
- }
- trap-group PRTG {
- version v2;
- categories {
- authentication;
- chassis;
- link;
- remote-operations;
- routing;
- startup;
- rmon-alarm;
- configuration;
- }
- targets {
- 10.20.11.2;
- }
- }
- }
- routing-options {
- static {
- route 0.0.0.0/0 next-hop 10.10.16.1;
- }
- }
- protocols {
- lacp {
- traceoptions {
- file lacp.log;
- flag all;
- }
- }
- igmp-snooping {
- vlan all;
- }
- rstp;
- lldp {
- interface all;
- }
- lldp-med {
- interface all;
- }
- }
- ethernet-switching-options {
- secure-access-port {
- interface ge-0/0/46.0 {
- mac-limit 1 action drop;
- allowed-mac A:B:C:D:E:F;
- }
- vlan VLAN1016 {
- no-arp-inspection;
- no-examine-dhcp;
- }
- vlan all {
- arp-inspection;
- examine-dhcp;
- }
- }
- storm-control {
- interface all;
- }
- }
- vlans {
- VLAN1016 {
- description Network-Mgmt;
- vlan-id 1016;
- l3-interface vlan.1016;
- }
- VLAN1316 {
- description VoIP-Active;
- vlan-id 1316;
- }
- VLAN1320 {
- description VoIP-Deadend;
- vlan-id 1320;
- }
- VLAN2020 {
- description Security-Devices;
- vlan-id 2020;
- }
- VLAN2116 {
- description Printers;
- vlan-id 2116;
- }
- VLAN2328 {
- description IoT;
- vlan-id 2328;
- }
- VLAN3310 {
- description Trusted-Wired;
- vlan-id 3310;
- }
- VLAN3516 {
- description ITS-Admins;
- vlan-id 3516;
- }
- VLAN3524 {
- description ITS-Staff;
- vlan-id 3524;
- }
- VLAN3616 {
- description Guest-Wired;
- vlan-id 3616;
- }
- VLAN3638 {
- description Access-Restrict;
- vlan-id 3638;
- }
- VLAN999 {
- description Native;
- vlan-id 999;
- }
- default {
- l3-interface vlan.0;
- }
- }
- poe {
- interface all;
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement