Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- set version 12.1X45.5
- set system host-name godnet
- set system time-zone GMT+4
- set system authentication-order password
- set system root-authentication encrypted-password "$1$VefloaO/$sKiqNrllv5T5n6e.TdXMT0"
- set system name-server 10.0.1.254
- set system name-server 8.8.8.8
- set system name-server 8.8.4.4
- set system services ssh
- set system services telnet
- set system services xnm-clear-text
- set system services web-management http interface vlan.1
- set system services web-management http interface vlan.2
- set system services web-management http interface vlan.3
- set system services web-management http interface fxp2.0
- set system services web-management http interface lo0.16384
- set system services web-management http interface ge-0/0/0.0
- set system services web-management http interface ge-0/0/15.0
- set system services web-management https system-generated-certificate
- set system services dhcp pool 192.168.11.0/24 address-range low 192.168.11.1
- set system services dhcp pool 192.168.11.0/24 address-range high 192.168.11.253
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.10
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.11
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.20
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.22
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.30
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.33
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.40
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.44
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.50
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.55
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.60
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.66
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.70
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.77
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.80
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.88
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.90
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.99
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.100
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.110
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.111
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.120
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.122
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.130
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.133
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.140
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.144
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.150
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.155
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.160
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.170
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.180
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.190
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.200
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.210
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.220
- set system services dhcp pool 192.168.11.0/24 exclude-address 192.168.11.222
- set system services dhcp pool 192.168.11.0/24 maximum-lease-time 86400
- set system services dhcp pool 192.168.11.0/24 name-server 10.0.1.254
- set system services dhcp pool 192.168.11.0/24 name-server 8.8.8.8
- set system services dhcp pool 192.168.11.0/24 wins-server 192.168.11.11
- set system services dhcp pool 192.168.11.0/24 router 192.168.11.254
- set system services dhcp pool 192.168.11.0/24 propagate-settings vlan.1
- set system services dhcp pool 192.168.22.0/24 address-range low 192.168.22.1
- set system services dhcp pool 192.168.22.0/24 address-range high 192.168.22.253
- set system services dhcp pool 192.168.22.0/24 maximum-lease-time 86400
- set system services dhcp pool 192.168.22.0/24 router 192.168.22.254
- set system services dhcp pool 192.168.22.0/24 propagate-settings vlan.2
- set system services dhcp pool 192.168.33.0/24 address-range low 192.168.33.1
- set system services dhcp pool 192.168.33.0/24 address-range high 192.168.33.253
- set system services dhcp pool 192.168.33.0/24 maximum-lease-time 86400
- set system services dhcp pool 192.168.33.0/24 name-server BBB.BBB.52.252
- set system services dhcp pool 192.168.33.0/24 name-server 8.8.8.8
- set system services dhcp pool 192.168.33.0/24 router 192.168.33.254
- set system services dhcp pool 192.168.33.0/24 propagate-settings vlan.3
- set system syslog archive size 100k
- set system syslog archive files 3
- set system syslog user * any emergency
- set system syslog file messages any critical
- set system syslog file messages authorization info
- set system syslog file interactive-commands interactive-commands error
- set system max-configurations-on-flash 5
- set system max-configuration-rollbacks 20
- set system license autoupdate url https://ae1.juniper.net/junos/key_retrieval
- set interfaces ge-0/0/0 unit 0 family inet filter input rf158
- set interfaces ge-0/0/0 unit 0 family inet address AAA.AAA.246.153/29 arp AAA.AAA.246.154 mac 00:00:00:00:01:54
- set interfaces ge-0/0/0 unit 0 family inet address AAA.AAA.246.153/29 arp AAA.AAA.246.154 publish
- set interfaces ge-0/0/0 unit 0 family inet address AAA.AAA.246.153/29 arp AAA.AAA.246.155 mac 00:00:00:00:01:55
- set interfaces ge-0/0/0 unit 0 family inet address AAA.AAA.246.153/29 arp AAA.AAA.246.155 publish
- set interfaces ge-0/0/0 unit 0 family inet address AAA.AAA.246.153/29 arp AAA.AAA.246.156 mac 00:00:00:00:01:56
- set interfaces ge-0/0/0 unit 0 family inet address AAA.AAA.246.153/29 arp AAA.AAA.246.156 publish
- set interfaces ge-0/0/1 unit 0 family inet address AAA.AAA.242.225/29 arp AAA.AAA.242.226 mac 00:00:00:00:02:26
- set interfaces ge-0/0/1 unit 0 family inet address AAA.AAA.242.225/29 arp AAA.AAA.242.226 publish
- set interfaces ge-0/0/2 unit 0 family inet address BBB.BBB.50.129/29 arp BBB.BBB.50.130 mac 00:27:0d:a7:4d:21
- set interfaces ge-0/0/2 unit 0 family inet address BBB.BBB.50.129/29 arp BBB.BBB.50.130 publish
- set interfaces ge-0/0/2 unit 0 family inet address BBB.BBB.50.129/29 arp BBB.BBB.50.131 mac 00:02:63:d8:8f:02
- set interfaces ge-0/0/2 unit 0 family inet address BBB.BBB.50.129/29 arp BBB.BBB.50.131 publish
- set interfaces ge-0/0/3 unit 0 family ethernet-switching vlan members unset
- set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members server
- set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members minedu
- set interfaces ge-0/0/6 unit 0 family ethernet-switching vlan members buhedu
- set interfaces ge-0/0/7 unit 0 family ethernet-switching vlan members unset
- set interfaces ge-0/0/8 unit 0 family ethernet-switching vlan members unset
- set interfaces ge-0/0/9 unit 0 family ethernet-switching vlan members unset
- set interfaces ge-0/0/10 unit 0 family ethernet-switching vlan members unset
- set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members unset
- set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members unset
- set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members unset
- set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members wifi
- set interfaces ge-0/0/15 unit 0 family inet address 192.168.26.237/24
- set interfaces vlan unit 0 family inet address 192.168.1.254/24
- set interfaces vlan unit 1 family inet address 192.168.11.254/24
- set interfaces vlan unit 2 family inet address 192.168.22.254/24
- set interfaces vlan unit 3 family inet address 192.168.33.254/24
- set interfaces vlan unit 4 family inet address 192.168.44.254/24
- set routing-options interface-routes rib-group inet rib158
- set routing-options static route 0.0.0.0/0 next-hop AAA.AAA.246.153
- set routing-options rib-groups rib158 import-rib inet.0
- set routing-options rib-groups rib158 import-rib ri158.inet.0
- set protocols stp
- set security certificates local remote "r-sys-adm\n "
- set security address-book global address srv-ad-1 192.168.11.11/32
- set security address-book global address srv-ad-2 192.168.11.22/32
- set security address-book global address srv-vmc 192.168.11.88/32
- set security address-book global address srv-nod-minedu 192.168.11.99/32
- set security address-book global address srv-igor 192.168.11.122/32
- set security address-book global address srv-net 192.168.11.0/24
- set security address-book global address minedu-net 192.168.22.0/24
- set security address-book global address buhedu-net 192.168.33.0/24
- set security address-book global address old-net 192.168.26.0/24
- set security address-book global address wifi-net 192.168.44.0/24
- set security alg dns disable
- set security alg ike-esp-nat enable
- set security flow allow-dns-reply
- set security flow tcp-session no-syn-check
- set security nat source pool ip153 address AAA.AAA.246.153/32
- set security nat source pool ip154 address AAA.AAA.246.154/32
- set security nat source pool ip155 address AAA.AAA.246.155/32
- set security nat source pool ip156 address AAA.AAA.246.156/32
- set security nat source pool ip225 address AAA.AAA.242.225/32
- set security nat source pool ip226 address AAA.AAA.242.226/32
- set security nat source pool ip129 address BBB.BBB.50.129/32
- set security nat source pool ip130 address BBB.BBB.50.130/32
- set security nat source pool ip131 address BBB.BBB.50.131/32
- set security nat source rule-set srv11-to-153 from zone server
- set security nat source rule-set srv11-to-153 to zone isp1
- set security nat source rule-set srv11-to-153 rule rule1 match source-address 192.168.26.11/32
- set security nat source rule-set srv11-to-153 rule rule1 match source-address 192.168.26.88/32
- set security nat source rule-set srv11-to-153 rule rule1 match destination-address 0.0.0.0/0
- set security nat source rule-set srv11-to-153 rule rule1 then source-nat pool ip153
- set security policies from-zone server to-zone isp1 policy srv-to-isp1 match source-address srv-net
- set security policies from-zone server to-zone isp1 policy srv-to-isp1 match destination-address any
- set security policies from-zone server to-zone isp1 policy srv-to-isp1 match application any
- set security policies from-zone server to-zone isp1 policy srv-to-isp1 then permit
- set security zones security-zone isp1 interfaces ge-0/0/0.0 host-inbound-traffic system-services ssh
- set security zones security-zone isp1 interfaces ge-0/0/0.0 host-inbound-traffic system-services ping
- set security zones security-zone isp1 interfaces ge-0/0/0.0 host-inbound-traffic system-services https
- set security zones security-zone isp1 interfaces ge-0/0/0.0 host-inbound-traffic system-services http
- set security zones security-zone isp1 interfaces ge-0/0/0.0 host-inbound-traffic system-services dns
- set security zones security-zone isp2 interfaces ge-0/0/1.0 host-inbound-traffic system-services ssh
- set security zones security-zone isp2 interfaces ge-0/0/1.0 host-inbound-traffic system-services ping
- set security zones security-zone isp2 interfaces ge-0/0/1.0 host-inbound-traffic system-services https
- set security zones security-zone isp2 interfaces ge-0/0/1.0 host-inbound-traffic system-services http
- set security zones security-zone isp2 interfaces ge-0/0/1.0 host-inbound-traffic system-services dns
- set security zones security-zone isp3 interfaces ge-0/0/2.0 host-inbound-traffic system-services ssh
- set security zones security-zone isp3 interfaces ge-0/0/2.0 host-inbound-traffic system-services ping
- set security zones security-zone isp3 interfaces ge-0/0/2.0 host-inbound-traffic system-services https
- set security zones security-zone isp3 interfaces ge-0/0/2.0 host-inbound-traffic system-services http
- set security zones security-zone isp3 interfaces ge-0/0/2.0 host-inbound-traffic system-services dns
- set security zones security-zone server interfaces vlan.1 host-inbound-traffic system-services all
- set security zones security-zone minedu interfaces vlan.2 host-inbound-traffic system-services all
- set security zones security-zone buhedu interfaces vlan.3 host-inbound-traffic system-services all
- set security zones security-zone wifi interfaces vlan.4 host-inbound-traffic system-services all
- set security zones security-zone oldnet host-inbound-traffic system-services all
- set security zones security-zone oldnet host-inbound-traffic protocols all
- set security zones security-zone oldnet interfaces ge-0/0/15.0 host-inbound-traffic system-services all
- set security zones security-zone oldnet interfaces ge-0/0/15.0 host-inbound-traffic system-services dhcp except
- set security zones security-zone oldnet interfaces ge-0/0/15.0 host-inbound-traffic system-services dns except
- set security zones security-zone oldnet interfaces ge-0/0/15.0 host-inbound-traffic protocols all
- set firewall filter rf158 term tr158-1 from source-address 0.0.0.0/0
- set firewall filter rf158 term tr158-1 then routing-instance ri158
- set routing-instances ri158 instance-type forwarding
- set routing-instances ri158 routing-options static route 0.0.0.0/0 next-hop AAA.AAA.246.158
- set applications application rdp protocol tcp
- set applications application rdp destination-port 3389
- set vlans buhedu vlan-id 33
- set vlans buhedu l3-interface vlan.3
- set vlans minedu vlan-id 22
- set vlans minedu l3-interface vlan.2
- set vlans server vlan-id 11
- set vlans server l3-interface vlan.1
- set vlans unset vlan-id 2
- set vlans unset l3-interface vlan.0
- set vlans wifi vlan-id 4
- set vlans wifi l3-interface vlan.4
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement