Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ## Last commit: 2025-03-11 11:48:48 CDT by me
- version 23.4R2-S3.9;
- system {
- host-name MDCCR;
- root-authentication {
- encrypted-password ""; ## SECRET-DATA
- }
- login {
- retry-options {
- tries-before-disconnect 3;
- backoff-threshold 2;
- lockout-period 5;
- }
- class read-only-remote {
- idle-timeout 10;
- login-alarms;
- permissions [ view view-configuration ];
- }
- class service-accounts {
- idle-timeout 5;
- login-alarms;
- permissions [ secret view view-configuration ];
- allow-commands "(request system power-off.*|show configuration \| display set \| no-more)";
- }
- class super-user-local {
- login-alarms;
- permissions all;
- }
- class super-user-remote {
- idle-timeout 10;
- login-alarms;
- permissions all;
- }
- user admin {
- full-name Administrator;
- uid 2000;
- class super-user-local;
- authentication {
- encrypted-password ""; ## SECRET-DATA
- }
- }
- user remote-admin {
- full-name "Remote Admins";
- uid 2001;
- class super-user-remote;
- }
- user remote-read-only {
- full-name "Remote Read-Only Users";
- uid 2002;
- class read-only-remote;
- }
- user service-accounts {
- full-name "Service Accounts";
- uid 2003;
- class service-accounts;
- }
- message "\n########################################################################\n# THIS SYSTEM IS RESTRICTED TO AUTHORIZED USAGE! #\n# #\n# Unauthorized usage will be subject to criminal penalties, fines, #\n# damages and/or disciplinary action. If you are not authorized to use #\n# this system, you must exit immediately. If you are authorized to #\n# use this system, you must do so in compliance with all laws, #\n# regulations, conduct rules, and company security policies applicable #\n# to this system. This system, including any hardware components, #\n# software, workstations, and storage spaces is subject to monitoring #\n# and search without advanced notice. Users should have no expectation #\n# of privacy in their use of any aspect of this system. #\n########################################################################\n\n";
- }
- services {
- inactive: netconf {
- ssh;
- rfc-compliant;
- yang-compliant;
- }
- ssh {
- root-login deny;
- protocol-version v2;
- max-sessions-per-connection 2;
- sftp-server;
- connection-limit 10;
- }
- telnet {
- connection-limit 2;
- }
- inactive: web-management {
- https {
- local-certificate MDC-Management;
- }
- }
- }
- auto-snapshot;
- domain-name mgmt.mdc.com;
- domain-search [ mgmt.mdc.com wlc.mdc.com ad.mdc.com mdc.com ];
- time-zone America/Chicago;
- management-instance;
- authentication-order radius;
- name-server {
- 10.20.11.1;
- 10.20.11.2;
- }
- radius-server {
- 10.20.11.1 {
- secret ""; ## SECRET-DATA
- timeout 2;
- }
- 10.20.11.2 {
- secret ""; ## SECRET-DATA
- timeout 2;
- }
- }
- accounting {
- events [ login change-log interactive-commands ];
- destination {
- radius {
- server {
- 10.20.11.1 secret ""; ## SECRET-DATA
- }
- }
- }
- }
- syslog {
- archive {
- size 100k;
- files 3;
- }
- user * {
- any emergency;
- }
- host 10.20.10.9 {
- any info;
- match "!(identification string from 10.20.10.1|identification string from 10.20.10.2|exited, status 255|tvp_drv_syspld_read|MAIL)";
- }
- host 10.20.10.4 {
- firewall any;
- }
- file alert {
- any alert;
- }
- inactive: file auth-log {
- authorization any;
- change-log any;
- match "!(identification string from 10.20.10.1|identification string from 10.20.10.2)";
- }
- file commands {
- any info;
- match UI_CMDLINE_READ_LINE;
- archive {
- size 1m;
- files 1;
- }
- }
- file critical {
- any critical;
- }
- file default-log-message {
- any any;
- match "!(identification string from 10.20.10.1|identification string from 10.20.10.2)";
- }
- file emergency {
- any emergency;
- }
- file error {
- any error;
- }
- inactive: file filter {
- any any;
- match PFE_FW_SYSLOG_IP;
- archive {
- size 1m;
- files 1;
- }
- }
- file info {
- any info;
- match "!(max power 30000 poe mode 2|identification string from 10.20.10.1|identification string from 10.20.10.2|exited, status 255|MAIL)";
- }
- file interactive-commands {
- interactive-commands any;
- archive {
- size 2m;
- files 5;
- }
- }
- file login {
- any info;
- match "(UI_AUTH_EVENT|UI_LOGIN_EVENT|SSHD_LOGIN_FAILED|UI_DBASE_LOGIN_EVENT)";
- archive {
- size 1m;
- files 1;
- }
- }
- file messages {
- any critical;
- authorization any;
- match "!(identification string from 10.20.10.1|identification string from 10.20.10.2)";
- archive {
- size 2m;
- files 5;
- }
- explicit-priority;
- }
- file notice {
- any notice;
- match "!exited, status 255";
- }
- file snapshot {
- archive {
- size 2m;
- files 1;
- }
- }
- file syslog-event-daemon-info {
- daemon info;
- match "!exited, status 255";
- }
- time-format year millisecond;
- }
- processes {
- dhcp-service {
- inactive: traceoptions {
- file dhcp_logfile size 10m;
- level all;
- flag packet;
- }
- }
- }
- ntp {
- server 132.163.96.1;
- server 132.163.96.2;
- }
- inactive: phone-home {
- server https://redirect.juniper.net;
- rfc-compliant;
- }
- }
- chassis {
- config-button no-clear;
- redundancy {
- graceful-switchover;
- }
- aggregated-devices {
- ethernet {
- device-count 4;
- }
- }
- alarm {
- management-ethernet {
- link-down ignore;
- }
- }
- inactive: auto-image-upgrade;
- }
- security {
- certificates {
- local {
- MDC-Management {
- ""; ## SECRET-DATA
- }
- }
- }
- }
- interfaces {
- ge-0/0/0 {
- description 013-3416;
- unit 0 {
- family ethernet-switching {
- interface-mode access;
- vlan {
- members VLAN3416;
- }
- storm-control default;
- }
- }
- }
- ge-0/0/1 {
- description 113-160;
- unit 0 {
- family ethernet-switching {
- interface-mode access;
- vlan {
- members VLAN160;
- }
- storm-control default;
- }
- }
- }
- ge-0/0/2 {
- description "014-MDCBR-0-0 INT-Infra-User";
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN1001 VLAN1682 VLAN1684 ];
- }
- storm-control default;
- }
- }
- }
- ge-0/0/3 {
- description "114-MDCBR-0-1 EXT-User";
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN1681 VLAN1683 ];
- }
- storm-control default;
- }
- }
- }
- ge-0/0/4 {
- description "015-MDCBR-1-0 INT-Infra-User";
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN1001 VLAN1682 VLAN1684 ];
- }
- storm-control default;
- }
- }
- }
- ge-0/0/5 {
- description "115-MDCBR-1-1 EXT-User";
- native-vlan-id 998;
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN1681 VLAN1683 ];
- }
- storm-control default;
- }
- }
- }
- ge-0/0/6 {
- description 016-MDCAP01;
- unit 0 {
- family ethernet-switching {
- interface-mode access;
- vlan {
- members VLAN1020;
- }
- storm-control default;
- }
- }
- }
- ge-0/0/7 {
- description 116-MDCMONAP;
- unit 0 {
- family ethernet-switching {
- interface-mode access;
- vlan {
- members VLAN1020;
- }
- storm-control default;
- }
- }
- }
- ge-0/0/8 {
- description 017-LabBR-AE3-8;
- ether-options {
- 802.3ad ae3;
- }
- }
- ge-0/0/9 {
- description 117-LabBR-AE3-9;
- ether-options {
- 802.3ad ae3;
- }
- }
- ge-0/0/10 {
- description 018-WLC1-AE2-10;
- ether-options {
- 802.3ad ae2;
- }
- }
- ge-0/0/11 {
- description 118-WLC1-AE2-11;
- ether-options {
- 802.3ad ae2;
- }
- }
- ge-0/0/12 {
- description 019-WLC1-AE2-12;
- ether-options {
- 802.3ad ae2;
- }
- }
- ge-0/0/13 {
- description 119-WLC1-AE2-13;
- ether-options {
- 802.3ad ae2;
- }
- }
- ge-0/0/14 {
- description 020-WLC1-AE2-14;
- ether-options {
- 802.3ad ae2;
- }
- }
- ge-0/0/15 {
- description 120-MDCR1UPS;
- unit 0 {
- family ethernet-switching {
- interface-mode access;
- vlan {
- members VLAN1015;
- }
- storm-control default;
- }
- }
- }
- ge-0/0/16 {
- description 021-MDCMS8101;
- native-vlan-id 2011;
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN2010 VLAN2011 VLAN2538 ];
- }
- storm-control default;
- }
- }
- }
- ge-0/0/17 {
- description 121-MDCMS8100;
- native-vlan-id 2011;
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN1010 VLAN1200 VLAN2010 VLAN2011 VLAN2538 ];
- }
- storm-control default;
- }
- }
- }
- ge-0/0/18 {
- description "022-MDCBR-0-2 IO-Trunk";
- native-vlan-id 998;
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN201 VLAN998 ];
- }
- storm-control default;
- }
- }
- }
- ge-0/0/19 {
- description "122-MDCBR-1-2 IO-Trunk";
- native-vlan-id 998;
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN201 VLAN998 ];
- }
- storm-control default;
- }
- }
- }
- ge-0/0/20 {
- description 023-WLC1-MGT;
- unit 0 {
- family ethernet-switching {
- interface-mode access;
- vlan {
- members VLAN1010;
- }
- storm-control default;
- }
- }
- }
- ge-0/0/21 {
- description 123-MDCINT0-MGT;
- unit 0 {
- family ethernet-switching {
- interface-mode access;
- vlan {
- members VLAN1010;
- }
- storm-control default;
- }
- }
- }
- ge-0/0/22 {
- description 024-MDCBR2-MGT;
- unit 0 {
- family ethernet-switching {
- interface-mode access;
- vlan {
- members VLAN1010;
- }
- storm-control default;
- }
- }
- }
- ge-0/0/23 {
- description 124-MDCBR1-MGT;
- unit 0 {
- family ethernet-switching {
- interface-mode access;
- vlan {
- members VLAN1010;
- }
- storm-control default;
- }
- }
- }
- ge-0/2/0 {
- disable;
- }
- xe-0/2/0 {
- description MDCBR1-AE0-0;
- ether-options {
- 802.3ad ae0;
- }
- }
- ge-0/2/1 {
- disable;
- }
- xe-0/2/1 {
- description MDCBR1-AE0-1;
- ether-options {
- 802.3ad ae0;
- }
- }
- ge-0/2/2 {
- disable;
- }
- xe-0/2/2 {
- description MDCBR1-IO-Trunk;
- native-vlan-id 998;
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN201 VLAN998 ];
- }
- storm-control default;
- }
- }
- }
- ge-0/2/3 {
- disable;
- }
- xe-0/2/3 {
- description Internet-Lumen;
- native-vlan-id 998;
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN201 VLAN998 ];
- }
- storm-control default;
- }
- }
- }
- ae0 {
- description MDCBR1-Uplink;
- native-vlan-id 999;
- aggregated-ether-options {
- lacp {
- passive;
- periodic fast;
- }
- }
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN160 VLAN161 VLAN999 VLAN1000 VLAN1001 VLAN1010 VLAN1015 VLAN1016 VLAN1020 VLAN1200 VLAN2010 VLAN2011 VLAN2020 VLAN2021 VLAN2022 VLAN2023 VLAN2116 VLAN2117 VLAN2316 VLAN2328 VLAN2329 VLAN2531 VLAN2538 VLAN3400 VLAN3410 VLAN3416 VLAN3424 VLAN3700 VLAN3710 VLAN3716 VLAN3724 VLAN3732 ];
- }
- storm-control default;
- }
- }
- }
- inactive: ae1 {
- description MDCBR2-Uplink;
- native-vlan-id 999;
- aggregated-ether-options {
- lacp {
- passive;
- periodic fast;
- }
- }
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN160 VLAN161 VLAN999 VLAN1000 VLAN1001 VLAN1010 VLAN1015 VLAN1016 VLAN1020 VLAN1200 VLAN2010 VLAN2011 VLAN2020 VLAN2021 VLAN2022 VLAN2023 VLAN2116 VLAN2117 VLAN2316 VLAN2328 VLAN2329 VLAN2531 VLAN2538 VLAN3400 VLAN3410 VLAN3416 VLAN3424 VLAN3700 VLAN3710 VLAN3716 VLAN3724 VLAN3732 ];
- }
- storm-control default;
- }
- }
- }
- ae2 {
- description WLC1-Uplink;
- native-vlan-id 999;
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN161 VLAN999 VLAN1020 VLAN2021 VLAN2023 VLAN2117 VLAN2329 VLAN3700 VLAN3710 VLAN3716 VLAN3724 VLAN3732 VLAN1681 VLAN1682 ];
- }
- storm-control default;
- }
- }
- }
- ae3 {
- description LabBR-Uplink;
- native-vlan-id 999;
- aggregated-ether-options {
- lacp {
- passive;
- periodic fast;
- }
- }
- unit 0 {
- family ethernet-switching {
- interface-mode trunk;
- vlan {
- members [ VLAN999 VLAN1000 ];
- }
- storm-control default;
- }
- }
- }
- irb {
- inactive: unit 0 {
- family inet {
- dhcp {
- vendor-id Juniper-ex3400-24p-;
- }
- }
- family inet6 {
- dhcpv6-client {
- client-type stateful;
- client-ia-type ia-na;
- client-identifier duid-type duid-ll;
- vendor-id Juniper:ex3400-24p:;
- }
- }
- }
- unit 1016 {
- description Infra-Network-Core;
- family inet {
- address 10.10.16.253/24;
- }
- }
- }
- lo0 {
- unit 0 {
- family inet {
- filter {
- input Protect-RE;
- }
- address 127.0.0.1/32;
- }
- }
- }
- vme {
- unit 0 {
- family inet {
- inactive: dhcp {
- vendor-id Juniper-ex3400-24p-;
- }
- address 10.10.10.252/24;
- }
- family inet6 {
- inactive: dhcpv6-client {
- client-type stateful;
- client-ia-type ia-na;
- client-identifier duid-type duid-ll;
- vendor-id Juniper:ex3400-24p:;
- }
- }
- }
- }
- }
- snmp {
- description "MDC Core Router";
- location "";
- contact "";
- filter-duplicates;
- community "" {
- authorization read-only;
- clients {
- 10.20.10.0/30;
- }
- }
- community "" {
- authorization read-write;
- clients {
- 10.20.10.0/30;
- }
- }
- trap-group PRTG {
- version v2;
- categories {
- authentication;
- chassis;
- link;
- remote-operations;
- routing;
- startup;
- rmon-alarm;
- vrrp-events;
- configuration;
- }
- targets {
- 10.20.10.1;
- 10.20.10.2;
- }
- }
- health-monitor {
- interval 30;
- rising-threshold 80;
- falling-threshold 20;
- }
- }
- forwarding-options {
- storm-control-profiles default {
- all;
- }
- }
- class-of-service {
- classifiers {
- dscp CLASSIFIER-DSCP {
- forwarding-class FC-AF {
- loss-priority low code-points 100010;
- }
- forwarding-class FC-BE {
- loss-priority low code-points [ 000000 000001 000010 000011 000100 000101 000110 000111 001000 001001 001010 001011 001100 001101 001110 001111 010000 010001 010010 010011 010100 010101 010110 010111 011000 011001 011010 011011 011100 011101 011110 011111 100000 100001 100011 100100 100101 100110 100111 101000 101001 101010 101011 101100 101101 101111 110001 110010 110011 110100 110101 110110 110111 111000 111001 111010 111011 111100 111101 111110 111111 ];
- }
- forwarding-class FC-EF {
- loss-priority low code-points 101110;
- }
- forwarding-class FC-NC {
- loss-priority low code-points 110000;
- }
- }
- }
- forwarding-classes {
- class FC-AF queue-num 1;
- class FC-BE queue-num 0;
- class FC-EF queue-num 3;
- class FC-NC queue-num 2;
- }
- interfaces {
- ge-* {
- scheduler-map SCHEDMAP-ALL;
- unit 0 {
- classifiers {
- dscp CLASSIFIER-DSCP;
- }
- rewrite-rules {
- dscp RWR-ALL;
- }
- }
- }
- xe-* {
- scheduler-map SCHEDMAP-ALL;
- unit 0 {
- classifiers {
- dscp CLASSIFIER-DSCP;
- }
- rewrite-rules {
- dscp RWR-ALL;
- }
- }
- }
- ae* {
- scheduler-map SCHEDMAP-ALL;
- unit 0 {
- classifiers {
- dscp CLASSIFIER-DSCP;
- }
- rewrite-rules {
- dscp RWR-ALL;
- }
- }
- }
- }
- rewrite-rules {
- dscp RWR-ALL {
- forwarding-class FC-AF {
- loss-priority low code-point 100010;
- }
- forwarding-class FC-BE {
- loss-priority low code-point 000000;
- }
- forwarding-class FC-EF {
- loss-priority low code-point 101110;
- }
- forwarding-class FC-NC {
- loss-priority low code-point 110000;
- }
- }
- }
- scheduler-maps {
- SCHEDMAP-ALL {
- forwarding-class FC-AF scheduler SCHED-AF;
- forwarding-class FC-BE scheduler SCHED-BE;
- forwarding-class FC-EF scheduler SCHED-EF;
- forwarding-class FC-NC scheduler SCHED-NC;
- }
- }
- schedulers {
- SCHED-AF {
- transmit-rate percent 30;
- buffer-size percent 30;
- priority low;
- }
- SCHED-BE {
- transmit-rate {
- remainder;
- }
- buffer-size {
- remainder;
- }
- priority low;
- }
- SCHED-EF {
- shaping-rate percent 10;
- buffer-size percent 10;
- priority strict-high;
- }
- SCHED-NC {
- transmit-rate percent 5;
- buffer-size percent 5;
- priority low;
- }
- }
- }
- firewall {
- family inet {
- filter Protect-RE {
- term Permit-Loopback-All {
- from {
- source-address {
- 127.0.0.1/32;
- }
- }
- then accept;
- }
- term Permit-SSH {
- from {
- source-address {
- 10.10.10.0/24;
- 10.10.16.0/24;
- 10.20.10.0/24;
- 10.20.11.0/30;
- 10.34.16.0/23;
- 10.37.16.0/23;
- }
- protocol tcp;
- destination-port 22;
- }
- then accept;
- }
- term Permit-Telnet {
- from {
- source-address {
- 10.20.10.3/32;
- }
- protocol tcp;
- destination-port 23;
- }
- then {
- count TELNET-COUNTER;
- log;
- syslog;
- accept;
- }
- }
- term Permit-HTTPS {
- from {
- source-address {
- 10.20.10.0/24;
- 10.20.11.0/30;
- 10.34.16.0/23;
- 10.37.16.0/23;
- }
- protocol tcp;
- destination-port 443;
- }
- then accept;
- }
- term Permit-RADIUS {
- from {
- source-address {
- 10.20.11.0/30;
- }
- protocol udp;
- source-port [ 1812 1813 ];
- }
- then accept;
- }
- term Permit-SNMP {
- from {
- source-address {
- 10.20.10.0/30;
- }
- protocol udp;
- destination-port [ 161 162 ];
- }
- then accept;
- }
- term Permit-NTP {
- from {
- source-address {
- 10.20.11.0/30;
- 132.163.96.0/30;
- }
- protocol udp;
- destination-port 123;
- }
- then accept;
- }
- term Permit-DNS {
- from {
- source-address {
- 10.20.11.0/30;
- }
- protocol udp;
- source-port 53;
- }
- then accept;
- }
- term Permit-ICMP-Ping {
- from {
- source-address {
- 10.10.10.0/24;
- 10.10.16.0/24;
- 10.20.10.0/24;
- 10.20.11.0/30;
- 10.34.16.0/23;
- 10.37.16.0/23;
- }
- protocol icmp;
- icmp-type [ echo-reply echo-request ];
- }
- then accept;
- }
- term Permit-Syslog {
- from {
- source-address {
- 10.20.10.4/32;
- 10.20.10.9/32;
- }
- protocol udp;
- destination-port 514;
- }
- then accept;
- }
- term Silent-Deny-LNCB {
- from {
- destination-address {
- 224.0.0.0/24;
- }
- }
- then {
- discard;
- }
- }
- term Default-Deny {
- then {
- count DEFAULT-DENY-COUNTER;
- log;
- syslog;
- discard;
- }
- }
- }
- }
- }
- routing-instances {
- mgmt_junos {
- routing-options {
- static {
- route 0.0.0.0/0 next-hop 10.10.10.254;
- }
- }
- description MGT-VRF;
- }
- }
- routing-options {
- static {
- route 0.0.0.0/0 next-hop 10.10.16.254;
- }
- }
- protocols {
- inactive: router-advertisement {
- interface vme.0 {
- managed-configuration;
- }
- interface irb.0 {
- managed-configuration;
- }
- }
- lldp {
- interface all;
- interface xe-0/2/3 {
- disable;
- }
- }
- lldp-med {
- interface all;
- interface xe-0/2/3 {
- disable;
- }
- }
- inactive: igmp-snooping {
- vlan all;
- }
- rstp {
- bridge-priority 4k;
- interface ge-0/0/0 {
- edge;
- }
- interface ge-0/0/1 {
- edge;
- }
- interface ge-0/0/2;
- interface ge-0/0/3;
- interface ge-0/0/4;
- interface ge-0/0/5;
- interface ge-0/0/6 {
- edge;
- }
- interface ge-0/0/7 {
- edge;
- }
- interface ge-0/0/15 {
- edge;
- }
- interface ge-0/0/18;
- interface ge-0/0/19;
- interface ge-0/0/20 {
- edge;
- }
- interface ge-0/0/21 {
- edge;
- }
- interface ge-0/0/22 {
- edge;
- }
- interface ge-0/0/23 {
- edge;
- }
- interface all;
- bpdu-block-on-edge;
- }
- vstp {
- interface all;
- }
- }
- switch-options {
- voip {
- interface access-ports {
- vlan VLAN2316;
- }
- }
- }
- poe {
- interface all;
- interface ge-0/0/8 {
- disable;
- }
- interface ge-0/0/9 {
- disable;
- }
- interface ge-0/0/10 {
- disable;
- }
- interface ge-0/0/11 {
- disable;
- }
- interface ge-0/0/12 {
- disable;
- }
- interface ge-0/0/13 {
- disable;
- }
- interface ge-0/0/14 {
- disable;
- }
- interface ge-0/0/15 {
- disable;
- }
- interface ge-0/0/16 {
- disable;
- }
- interface ge-0/0/17 {
- disable;
- }
- interface ge-0/0/18 {
- disable;
- }
- interface ge-0/0/19 {
- disable;
- }
- interface ge-0/0/20 {
- disable;
- }
- interface ge-0/0/21 {
- disable;
- }
- interface ge-0/0/22 {
- disable;
- }
- interface ge-0/0/23 {
- disable;
- }
- interface ge-0/0/6 {
- priority high;
- }
- interface ge-0/0/3 {
- disable;
- }
- interface ge-0/0/4 {
- disable;
- }
- interface ge-0/0/5 {
- disable;
- }
- interface ge-0/0/2 {
- disable;
- }
- }
- vlans {
- VLAN1000 {
- description WAN-Lab;
- vlan-id 1000;
- }
- VLAN1001 {
- description WAN-Production;
- vlan-id 1001;
- }
- VLAN1010 {
- description Infra-Network-OOBM;
- vlan-id 1010;
- }
- VLAN1015 {
- description Infra-Network-Power;
- vlan-id 1015;
- }
- VLAN1016 {
- description Infra-Network-Core;
- vlan-id 1016;
- l3-interface irb.1016;
- }
- VLAN1020 {
- description Infra-Network-Wireless;
- vlan-id 1020;
- }
- VLAN1200 {
- description Infra-Server-OOBM;
- vlan-id 1200;
- }
- VLAN160 {
- description MDC-EXT;
- vlan-id 160;
- }
- VLAN161 {
- description MDC-EXT-WLAN;
- vlan-id 161;
- }
- VLAN1681 {
- description MDC-EXT-TEST-WLAN;
- vlan-id 1681;
- }
- VLAN1682 {
- description MDC-INT-TEST-WLAN;
- vlan-id 1682;
- }
- VLAN1683 {
- description MDC-EXT-TEST;
- vlan-id 1683;
- }
- VLAN1684 {
- description MDC-INT-TEST;
- vlan-id 1684;
- }
- VLAN201 {
- description Internet-Lumen;
- vlan-id 201;
- }
- VLAN2010 {
- description Infra-Server-VMs;
- vlan-id 2010;
- }
- VLAN2011 {
- description Infra-Server-Core;
- vlan-id 2011;
- }
- VLAN2020 {
- description INT-IoT-Security;
- vlan-id 2020;
- }
- VLAN2021 {
- description INT-IoT-Security-WLAN;
- vlan-id 2021;
- }
- VLAN2022 {
- description INT-IoT-Facilities;
- vlan-id 2022;
- }
- VLAN2023 {
- description INT-IoT-Facilities-WLAN;
- vlan-id 2023;
- }
- VLAN2116 {
- description INT-IoT-Printers;
- vlan-id 2116;
- }
- VLAN2117 {
- description INT-IoT-Printers;
- vlan-id 2117;
- }
- VLAN2316 {
- description INT-IoT-Telecom;
- vlan-id 2316;
- }
- VLAN2328 {
- description EXT-IoT;
- vlan-id 2328;
- }
- VLAN2329 {
- description EXT-IoT-WLAN;
- vlan-id 2329;
- }
- VLAN2531 {
- description DMZ-Network;
- vlan-id 2531;
- }
- VLAN2538 {
- description DMZ-Server;
- vlan-id 2538;
- }
- VLAN3400 {
- description EXT-User-Untrust;
- vlan-id 3400;
- }
- VLAN3410 {
- description INT-User-Trust;
- vlan-id 3410;
- }
- VLAN3416 {
- description INT-User-IT-Admins;
- vlan-id 3416;
- }
- VLAN3424 {
- description INT-User-IT-Staff;
- vlan-id 3424;
- }
- VLAN3700 {
- description EXT-User-Untrust-WLAN;
- vlan-id 3700;
- }
- VLAN3710 {
- description INT-User-Trust-WLAN;
- vlan-id 3710;
- }
- VLAN3716 {
- description INT-User-IT-Admins-WLAN;
- vlan-id 3716;
- }
- VLAN3724 {
- description INT-User-IT-Staff-WLAN;
- vlan-id 3724;
- }
- VLAN3732 {
- description EXT-User-Untrust-RLAN;
- vlan-id 3732;
- }
- VLAN998 {
- description DMZ-Network-WAN;
- vlan-id 998;
- }
- VLAN999 {
- description Native;
- vlan-id 999;
- }
- inactive: default {
- vlan-id 1;
- l3-interface irb.0;
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement