diff options
Diffstat (limited to 'examples/tg15/netconf/rs1.south.cfg')
-rw-r--r-- | examples/tg15/netconf/rs1.south.cfg | 926 |
1 files changed, 926 insertions, 0 deletions
diff --git a/examples/tg15/netconf/rs1.south.cfg b/examples/tg15/netconf/rs1.south.cfg new file mode 100644 index 0000000..7f58e0f --- /dev/null +++ b/examples/tg15/netconf/rs1.south.cfg @@ -0,0 +1,926 @@ +## Last commit: 2014-12-26 13:32:27 CET by technet +version 14.1X53-D15.2; +system { + host-name rs1.south; + auto-snapshot; + time-zone Europe/Oslo; + authentication-order [ tacplus password ]; + root-authentication { + } + name-server { + 2a02:ed02:1ee7::66; + 2a02:ed02:1337::2; + } + login { + user technet { + uid 2000; + class super-user; + authentication { + } + } + } + services { + ssh; + } + syslog { + user * { + any emergency; + } + host 185.12.59.18 { + any info; + authorization info; + port 515; + } + file messages { + any notice; + authorization info; + } + file interactive-commands { + interactive-commands any; + } + } + commit synchronize; + ntp; +} +chassis { + aggregated-devices { + ethernet { + device-count 32; + } + } +} +interfaces { + interface-range sflow { + member-range ge-0/0/0 to ge-0/0/47; + member-range xe-0/1/0 to xe-0/1/3; + } + ge-0/0/0 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/1 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/2 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/3 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/4 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/5 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/6 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/7 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/8 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/9 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/10 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/11 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/12 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/13 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/14 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/15 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/16 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/17 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/18 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/19 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members south_event; + } + } + } + } + ge-0/0/20 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members south_event; + } + } + } + } + ge-0/0/21 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members south_event; + } + } + } + } + ge-0/0/22 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members south_event; + } + } + } + } + ge-0/0/23 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members south_event; + } + } + } + } + ge-0/0/24 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/25 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/26 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/27 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/28 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/29 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/30 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/31 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/32 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/33 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/34 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/35 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/36 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/37 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/38 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/39 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members clients; + } + } + } + } + ge-0/0/42 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members event_spesial2; + } + } + } + } + ge-0/0/43 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members event_spesial2; + } + } + } + } + ge-0/0/44 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members event_spesial2; + } + } + } + } + ge-0/0/45 { + description "sw1-south access / ae0"; + ether-options { + 802.3ad ae0; + } + inactive: unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members mgmt; + } + } + } + } + ge-0/0/46 { + description "sw1-coreshop access / ae1"; + unit 0 { + family ethernet-switching { + port-mode trunk; + vlan { + members [ clients mgmt ]; + } + } + } + } + ge-0/0/47 { + unit 0 { + family ethernet-switching { + port-mode access; + vlan { + members southcam; + } + } + } + } + xe-0/1/0 { + description "rs1.tele xe-1/2/0"; + unit 0 { + family inet { + address 151.216.128.11/31; + } + family inet6 { + address 2a02:ed02:fffe::11/127; + } + } + } + xe-0/1/1 { + description "rs1.log xe-0/1/0"; + unit 0 { + family inet { + address 151.216.128.12/31; + } + family inet6 { + address 2a02:ed02:fffe::12/127; + } + } + } + ae0 { + description "sw1-south ae0"; + aggregated-ether-options { + lacp { + active; + } + } + unit 0 { + family ethernet-switching { + port-mode trunk; + vlan { + members [ mgmt clients ]; + } + } + } + } + ae1 { + description "sw1-coreshop ae1"; + aggregated-ether-options { + lacp { + active; + } + } + unit 0 { + family ethernet-switching { + port-mode trunk; + vlan { + members [ mgmt clients ]; + } + } + } + } + lo0 { + unit 0 { + family inet { + filter { + input v4-mgmt; + } + address 151.216.255.12/32; + } + family inet6 { + filter { + input v6-mgmt; + } + address 2a02:ed02:ffff::12/128; + } + } + } + vlan { + unit 234 { + description sw1-south; + family inet { + address 151.216.234.1/24; + } + family inet6 { + address 2a02:ed02:234::1/64; + } + } + unit 666 { + family inet { + address 151.216.183.97/27; + } + family inet6 { + address 2a02:ed02:1836::1/64; + } + } + unit 2490 { + family inet { + address 151.216.249.1/26; + } + family inet6 { + address 2a02:ed02:249a::1/64; + } + } + unit 2500 { + family inet { + address 10.20.50.1/24; + } + } + } +} +snmp { + community <removed> { + client-list-name mgmt; + } +} +forwarding-options { + helpers { + bootp { + interface { + vlan.234 { + server 185.12.59.66; + server 185.12.59.2; + } + vlan.2490 { + server 185.12.59.66; + server 185.12.59.2; + } + vlan.2500 { + server 185.12.59.66; + server 185.12.59.2; + } + vlan.666 { + server 185.12.59.11; + source-address-giaddr; + dhcp-option82 { + circuit-id { + prefix hostname; + } + } + } + } + } + } +} +protocols { + + + + igmp { + interface vlan.65 { + group-policy v4-multicast; + } + } + + + + mld { + interface vlan.65 { + group-policy v6-multicast; + } + } + router-advertisement { + interface vlan.65 { + max-advertisement-interval 30; + managed-configuration; + } + interface vlan.234 { + min-advertisement-interval 15; + managed-configuration; + } + } + + + + ospf { + export [ redistribute-direct redistribute-static ]; + reference-bandwidth 1000g; + area 0.0.0.0 { + interface xe-0/1/0.0; + interface xe-0/1/1.0; + } + } + + + + ospf3 { + export [ redistribute-direct redistribute-static ]; + reference-bandwidth 1000g; + area 0.0.0.0 { + interface xe-0/1/0.0; + interface xe-0/1/1.0; + } + } + pim { + rp { + static { + address 2a02:ed02:ffff::11; + address 151.216.255.11; + } + } + interface xe-0/1/0.0 { + family inet; + family inet6; + } + interface xe-0/1/1.0 { + family inet; + family inet6; + } + } + sflow { + agent-id 151.216.255.12; + polling-interval 3600; + sample-rate { + ingress 10000; + egress 10000; + } + source-ip 151.216.255.12; + collector <removed>; + interfaces sflow; + } + lldp { + interface all; + } + lldp-med { + interface all; + } +} +policy-options { + prefix-list v4-mgmt { + /* NOC clients */ + 151.216.254.0/24; + /* Servers */ + 185.12.59.0/26; + } + prefix-list v6-mgmt { + /* NOC clients */ + 2a02:ed02:254::/64; + /* Servers */ + 2a02:ed02:1337::/64; + } + prefix-list mgmt { + /* NOC clients */ + 151.216.254.0/24; + /* Servers */ + 185.12.59.0/26; + /* NOC clients */ + 2a02:ed02:254::/64; + /* Servers */ + 2a02:ed02:1337::/64; + } + + policy-statement redistribute-direct { + from protocol direct; + then { + external { + type 1; + } + accept; + } + } + policy-statement redistribute-static { + from protocol static; + then { + external { + type 1; + } + accept; + } + } + policy-statement v4-multicast { + term accept-our { + from { + route-filter 233.139.58.0/24 orlonger; + source-address-filter 185.12.59.0/26 orlonger; + source-address-filter 151.216.254.0/24 orlonger; + } + then accept; + } + term reject-all { + then reject; + } + } + policy-statement v6-multicast { + term accept-our { + from { + route-filter ff35:2001:67c:2e44::/120 orlonger; + source-address-filter 2a02:ed02:1337::/64 orlonger; + source-address-filter 2a02:ed02:252::/64 orlonger; + } + } + term reject-all { + then reject; + } + } +} +firewall { + family inet { + filter v4-mgmt { + term accept-ssh { + from { + source-prefix-list { + v4-mgmt; + } + destination-port 22; + } + then accept; + } + term discard-ssh { + from { + destination-port 22; + } + then { + discard; + } + } + term accept-all { + then accept; + } + } + } + family inet6 { + filter v6-mgmt { + term accept-ssh { + from { + source-prefix-list { + v6-mgmt; + } + destination-port 22; + } + then accept; + } + term discard-ssh { + from { + destination-port 22; + } + then discard; + } + term accept-all { + then accept; + } + } + } + + + + filter v4-event { + term accept-event { + from { + source-address { + 10.20.0.0/16; + } + } + then accept; + } + term accept-noc { + from { + source-address { + 185.12.59.0/26; + 185.12.59.64/27; + } + } + then accept; + } + term reject-tg { + from { + source-address { + 185.12.59.0/24; + 151.216.128.0/17; + } + } + then { + discard; + } + } + term accept-all { + then accept; + } + } +} +vlans { + clients { + vlan-id 234; + l3-interface vlan.234; + } + event_spesial2 { + description "Event Spesialnett 2"; + vlan-id 2510; + interface { + ge-0/0/42.0; + ge-0/0/43.0; + ge-0/0/44.0; + } + } + mgmt { + vlan-id 666; + l3-interface vlan.666; + } + south_event { + vlan-id 2500; + l3-interface vlan.2500; + } + southcam { + vlan-id 2490; + l3-interface vlan.2490; + } +} +poe { + interface all; + interface ge-0/0/47; + interface ge-0/0/9; + interface ge-0/0/10; +} |