## Last changed: 2016-03-24 13:39:24 CET version 14.1X53-D15.2; groups { SET_AE_DEFAULTS { interfaces { { aggregated-ether-options { lacp { active; } } } } } SET_OSPF_DEFAULTS { protocols { ospf { reference-bandwidth 1000g; area <*> { interface ; } } ospf3 { reference-bandwidth 1000g; area <*> { interface ; } } } } SET_RA_DEFAULTS { protocols { router-advertisement { interface { max-advertisement-interval 15; managed-configuration; } } } } } system { host-name distro1; auto-snapshot; domain-name infra.gathering.org; time-zone Europe/Oslo; authentication-order tacplus; root-authentication { encrypted-password ""; } name-server { 185.110.149.2; 185.110.148.2; 2a06:5841:149a::2; 2a06:5841:1337::2; } tacplus-server { 134.90.150.164 { secret ""; source-address 185.110.148.101; } } login { user technet { uid 2000; class super-user; authentication { encrypted-password ""; } } } services { ssh { root-login deny; no-tcp-forwarding; client-alive-count-max 2; client-alive-interval 300; connection-limit 5; rate-limit 5; } netconf { ssh { connection-limit 3; rate-limit 3; } } } syslog { user * { any emergency; } host 185.110.148.17 { any info; authorization info; port 515; } file messages { any notice; authorization info; } file interactive-commands { interactive-commands any; } } archival { configuration { transfer-on-commit; archive-sites { "scp://user@host/some/folder/" password ""; } } } commit synchronize; ntp { server 2001:700:100:2::6; } } chassis { aggregated-devices { ethernet { device-count 32; } } alarm { management-ethernet { link-down ignore; } } auto-image-upgrade; } security { ssh-known-hosts { host 134.90.150.164 { ecdsa-sha2-nistp256-key ; } } } interfaces { apply-groups SET_AE_DEFAULTS; interface-range aps { member-range ge-0/0/36 to ge-0/0/47; member-range ge-1/0/36 to ge-1/0/47; member-range ge-2/0/36 to ge-2/0/47; description "Management/klientnett AP-er"; unit 0 { family ethernet-switching { vlan { members aps_mgmt; } } } } interface-range all-ports { member-range ge-0/0/0 to ge-0/0/47; member-range ge-1/0/0 to ge-1/0/47; member-range ge-2/0/0 to ge-2/0/47; member-range xe-0/1/0 to xe-0/1/3; member-range xe-1/1/0 to xe-1/1/3; member-range xe-2/1/0 to xe-2/1/3; } ge-0/0/0 { description "e5-2 access / ae0"; ether-options { 802.3ad ae0; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/1 { description "e7-1 access / ae1"; ether-options { 802.3ad ae1; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/2 { description "e7-2 access / ae2"; ether-options { 802.3ad ae2; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/3 { description "e9-1 access / ae3"; ether-options { 802.3ad ae3; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/4 { description "e9-2 access / ae4"; ether-options { 802.3ad ae4; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/5 { description "e11-1 access / ae5"; ether-options { 802.3ad ae5; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/6 { description "e11-2 access / ae6"; ether-options { 802.3ad ae6; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/7 { description "e13-1 access / ae7"; ether-options { 802.3ad ae7; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/8 { description "e13-2 access / ae8"; ether-options { 802.3ad ae8; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/9 { description "e15-1 access / ae9"; ether-options { 802.3ad ae9; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/10 { description "e15-2 access / ae10"; ether-options { 802.3ad ae10; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/11 { description "e17-1 access / ae11"; ether-options { 802.3ad ae11; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/12 { description "e17-2 access / ae12"; ether-options { 802.3ad ae12; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/13 { description "e19-1 access / ae13"; ether-options { 802.3ad ae13; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/14 { description "e19-2 access / ae14"; ether-options { 802.3ad ae14; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/15 { description "e21-1 access / ae15"; ether-options { 802.3ad ae15; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/16 { description "e21-2 access / ae16"; ether-options { 802.3ad ae16; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/17 { description "e23-1 access / ae17"; ether-options { 802.3ad ae17; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } ge-0/0/18 { description "e23-2 access / ae18"; ether-options { 802.3ad ae18; } inactive: unit 0 { family ethernet-switching { port-mode access; vlan { members mgmt; } } } } xe-0/1/0 { description "Uplink mot coregw"; ether-options { 802.3ad ae31; } } ge-1/0/0 { description "e5-2 ae0"; ether-options { 802.3ad ae0; } } ge-1/0/1 { description "e7-1 ae1"; ether-options { 802.3ad ae1; } } ge-1/0/2 { description "e7-2 ae2"; ether-options { 802.3ad ae2; } } ge-1/0/3 { description "e9-1 ae3"; ether-options { 802.3ad ae3; } } ge-1/0/4 { description "e9-2 ae4"; ether-options { 802.3ad ae4; } } ge-1/0/5 { description "e11-1 ae5"; ether-options { 802.3ad ae5; } } ge-1/0/6 { description "e11-2 ae6"; ether-options { 802.3ad ae6; } } ge-1/0/7 { description "e13-1 ae7"; ether-options { 802.3ad ae7; } } ge-1/0/8 { description "e13-2 ae8"; ether-options { 802.3ad ae8; } } ge-1/0/9 { description "e15-1 ae9"; ether-options { 802.3ad ae9; } } ge-1/0/10 { description "e15-2 ae10"; ether-options { 802.3ad ae10; } } ge-1/0/11 { description "e17-1 ae11"; ether-options { 802.3ad ae11; } } ge-1/0/12 { description "e17-2 ae12"; ether-options { 802.3ad ae12; } } ge-1/0/13 { description "e19-1 ae13"; ether-options { 802.3ad ae13; } } ge-1/0/14 { description "e19-2 ae14"; ether-options { 802.3ad ae14; } } ge-1/0/15 { description "e21-1 ae15"; ether-options { 802.3ad ae15; } } ge-1/0/16 { description "e21-2 ae16"; ether-options { 802.3ad ae16; } } ge-1/0/17 { description "e23-1 ae17"; ether-options { 802.3ad ae17; } } ge-1/0/18 { description "e23-2 ae18"; ether-options { 802.3ad ae18; } } xe-1/1/0 { description "Uplink mot coregw"; ether-options { 802.3ad ae31; } } ge-2/0/0 { description "e5-2 ae0"; ether-options { 802.3ad ae0; } } ge-2/0/1 { description "e7-1 ae1"; ether-options { 802.3ad ae1; } } ge-2/0/2 { description "e7-2 ae2"; ether-options { 802.3ad ae2; } } ge-2/0/3 { description "e9-1 ae3"; ether-options { 802.3ad ae3; } } ge-2/0/4 { description "e9-2 ae4"; ether-options { 802.3ad ae4; } } ge-2/0/5 { description "e11-1 ae5"; ether-options { 802.3ad ae5; } } ge-2/0/6 { description "e11-2 ae6"; ether-options { 802.3ad ae6; } } ge-2/0/7 { description "e13-1 ae7"; ether-options { 802.3ad ae7; } } ge-2/0/8 { description "e13-2 ae8"; ether-options { 802.3ad ae8; } } ge-2/0/9 { description "e15-1 ae9"; ether-options { 802.3ad ae9; } } ge-2/0/10 { description "e15-2 ae10"; ether-options { 802.3ad ae10; } } ge-2/0/11 { description "e17-1 ae11"; ether-options { 802.3ad ae11; } } ge-2/0/12 { description "e17-2 ae12"; ether-options { 802.3ad ae12; } } ge-2/0/13 { description "e19-1 ae13"; ether-options { 802.3ad ae13; } } ge-2/0/14 { description "e19-2 ae14"; ether-options { 802.3ad ae14; } } ge-2/0/15 { description "e21-1 ae15"; ether-options { 802.3ad ae15; } } ge-2/0/16 { description "e21-2 ae16"; ether-options { 802.3ad ae16; } } ge-2/0/17 { description "e23-1 ae17"; ether-options { 802.3ad ae17; } } ge-2/0/18 { description "e23-2 ae18"; ether-options { 802.3ad ae18; } } ae0 { description "e5-2 ae0"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e5-2 ]; } } } } ae1 { description "e7-1 ae1"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e7-1 ]; } } } } ae2 { description "e7-2 ae2"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e7-2 ]; } } } } ae3 { description "e9-1 ae3"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e9-1 ]; } } } } ae4 { description "e9-2 ae4"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e9-2 ]; } } } } ae5 { description "e11-1 ae5"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e11-1 ]; } } } } ae6 { description "e11-2 ae6"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e11-2 ]; } } } } ae7 { description "e13-1 ae7"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e13-1 ]; } } } } ae8 { description "e13-2 ae8"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e13-2 ]; } } } } ae9 { description "e15-1 ae9"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e15-1 ]; } } } } ae10 { description "e15-2 ae10"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e15-2 ]; } } } } ae11 { description "e17-1 ae11"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e17-1 ]; } } } } ae12 { description "e17-2 ae12"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e17-2 ]; } } } } ae13 { description "e19-1 ae13"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e19-1 ]; } } } } ae14 { description "e19-2 ae14"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e19-2 ]; } } } } ae15 { description "e21-1 ae15"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e21-1 ]; } } } } ae16 { description "e21-2 ae16"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e21-2 ]; } } } } ae17 { description "e23-1 ae17"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e23-1 ]; } } } } ae18 { description "e23-2 ae18"; unit 0 { family ethernet-switching { port-mode trunk; vlan { members [ mgmt e23-2 ]; } } } } ae31 { description "Uplink mot coregw"; unit 0 { family inet { address 185.110.148.155/31; } family inet6; } } lo0 { unit 0 { family inet { filter { input protect-mgmt-v4; } address 185.110.148.101/32; } family inet6 { filter { input protect-mgmt-v6; } address 2a06:5841:148b::101/128; } } } vlan { unit 666 { description "mgmt til aksesswitcher/fapfapfap"; family inet { address 88.92.54.65/26; } } unit 777 { description "mgmt til AP-ene"; family inet { address 88.92.51.65/26; } } unit 1052 { family inet { address 88.92.1.1/26; } family inet6 { address 2a06:5840:1a::1/64; } } unit 1071 { family inet { address 88.92.1.193/26; } family inet6 { address 2a06:5840:1d::1/64; } } unit 1072 { family inet { address 88.92.2.1/26; } family inet6 { address 2a06:5840:2a::1/64; } } unit 1091 { family inet { address 88.92.2.193/26; } family inet6 { address 2a06:5840:2d::1/64; } } unit 1092 { family inet { address 88.92.3.1/26; } family inet6 { address 2a06:5840:3a::1/64; } } unit 1111 { family inet { address 88.92.3.193/26; } family inet6 { address 2a06:5840:3d::1/64; } } unit 1112 { family inet { address 88.92.4.1/26; } family inet6 { address 2a06:5840:4a::1/64; } } unit 1131 { family inet { address 88.92.4.193/26; } family inet6 { address 2a06:5840:4d::1/64; } } unit 1132 { family inet { address 88.92.5.1/26; } family inet6 { address 2a06:5840:5a::1/64; } } unit 1151 { family inet { address 88.92.5.193/26; } family inet6 { address 2a06:5840:5d::1/64; } } unit 1152 { family inet { address 88.92.6.1/26; } family inet6 { address 2a06:5840:6a::1/64; } } unit 1171 { family inet { address 88.92.6.193/26; } family inet6 { address 2a06:5840:6d::1/64; } } unit 1172 { family inet { address 88.92.7.1/26; } family inet6 { address 2a06:5840:7a::1/64; } } unit 1191 { family inet { address 88.92.7.193/26; } family inet6 { address 2a06:5840:7d::1/64; } } unit 1192 { family inet { address 88.92.8.1/26; } family inet6 { address 2a06:5840:8a::1/64; } } unit 1211 { family inet { address 88.92.8.193/26; } family inet6 { address 2a06:5840:8d::1/64; } } unit 1212 { family inet { address 88.92.9.1/26; } family inet6 { address 2a06:5840:9a::1/64; } } unit 1231 { family inet { address 88.92.9.193/26; } family inet6 { address 2a06:5840:9d::1/64; } } unit 1232 { family inet { address 88.92.10.1/26; } family inet6 { address 2a06:5840:10a::1/64; } } } } snmp { community { authorization read-only; client-list-name mgmt; } community { authorization read-only; client-list-name mgmt-nms; } } forwarding-options { inactive: helpers { bootp { dhcp-option82 { circuit-id { prefix hostname; } } server 185.110.148.22; interface { vlan.666; } } } dhcp-relay { inactive: dhcpv6 { group edge-switches { active-server-group v6-edge-switches; overrides; interface vlan.777; interface vlan.1052; interface vlan.1071; interface vlan.1072; interface vlan.1091; interface vlan.1092; interface vlan.1111; interface vlan.1112; interface vlan.1131; interface vlan.1132; interface vlan.1151; interface vlan.1152; interface vlan.1171; interface vlan.1172; interface vlan.1191; interface vlan.1192; interface vlan.1211; interface vlan.1212; interface vlan.1231; interface vlan.1232; } server-group { v6-edge-switches { 2a06:5841:149a::2; } } } server-group { v4-edge-switches { 185.110.149.2; 185.110.148.2; } fapfapfap-group { 185.110.148.22; } } group edge-switches { active-server-group v4-edge-switches; overrides { trust-option-82; } interface vlan.777; interface vlan.1052; interface vlan.1071; interface vlan.1072; interface vlan.1091; interface vlan.1092; interface vlan.1111; interface vlan.1112; interface vlan.1131; interface vlan.1132; interface vlan.1151; interface vlan.1152; interface vlan.1171; interface vlan.1172; interface vlan.1191; interface vlan.1192; interface vlan.1211; interface vlan.1212; interface vlan.1231; interface vlan.1232; } group fapfapfap { active-server-group fapfapfap-group; relay-option-82 { circuit-id { prefix { host-name; } include-irb-and-l2; } } interface vlan.666; } } } event-options { policy ae0down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae0$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/0 unit 0"; "deactivate interfaces ge-0/0/0 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 went down so removed ge-0/0/0 from bundle"; } } } } policy ae0up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae0$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/0 unit 0"; "activate interfaces ge-0/0/0 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/0 to bundle"; } } } } policy ae1down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae1$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/1 unit 0"; "deactivate interfaces ge-0/0/1 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae1 went down so removed ge-0/0/1 from bundle"; } } } } policy ae1up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae1$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/1 unit 0"; "activate interfaces ge-0/0/1 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/1 to bundle"; } } } } policy ae2down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae2$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/2 unit 0"; "deactivate interfaces ge-0/0/2 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae2 went down so removed ge-0/0/2 from bundle"; } } } } policy ae2up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae2$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/2 unit 0"; "activate interfaces ge-0/0/2 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/2 to bundle"; } } } } policy ae3down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae3$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/3 unit 0"; "deactivate interfaces ge-0/0/3 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae3 went down so removed ge-0/0/3 from bundle"; } } } } policy ae3up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae3$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/3 unit 0"; "activate interfaces ge-0/0/3 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/3 to bundle"; } } } } policy ae4down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae4$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/4 unit 0"; "deactivate interfaces ge-0/0/4 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae4 went down so removed ge-0/0/4 from bundle"; } } } } policy ae4up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae4$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/4 unit 0"; "activate interfaces ge-0/0/4 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/4 to bundle"; } } } } policy ae5down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae5$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/5 unit 0"; "deactivate interfaces ge-0/0/5 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae5 went down so removed ge-0/0/5 from bundle"; } } } } policy ae5up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae5$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/5 unit 0"; "activate interfaces ge-0/0/5 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/5 to bundle"; } } } } policy ae6down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae6$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/6 unit 0"; "deactivate interfaces ge-0/0/6 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae6 went down so removed ge-0/0/6 from bundle"; } } } } policy ae6up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae6$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/6 unit 0"; "activate interfaces ge-0/0/6 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/6 to bundle"; } } } } policy ae7down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae7$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/7 unit 0"; "deactivate interfaces ge-0/0/7 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae7 went down so removed ge-0/0/7 from bundle"; } } } } policy ae7up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae7$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/7 unit 0"; "activate interfaces ge-0/0/7 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/7 to bundle"; } } } } policy ae8down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae8$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/8 unit 0"; "deactivate interfaces ge-0/0/8 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae8 went down so removed ge-0/0/8 from bundle"; } } } } policy ae8up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae8$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/8 unit 0"; "activate interfaces ge-0/0/8 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/8 to bundle"; } } } } policy ae9down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae9$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/9 unit 0"; "deactivate interfaces ge-0/0/9 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae9 went down so removed ge-0/0/9 from bundle"; } } } } policy ae9up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae9$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/9 unit 0"; "activate interfaces ge-0/0/9 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/9 to bundle"; } } } } policy ae10down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae10$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/10 unit 0"; "deactivate interfaces ge-0/0/10 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae10 went down so removed ge-0/0/10 from bundle"; } } } } policy ae10up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae10$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/10 unit 0"; "activate interfaces ge-0/0/10 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/10 to bundle"; } } } } policy ae11down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae11$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/11 unit 0"; "deactivate interfaces ge-0/0/11 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae11 went down so removed ge-0/0/11 from bundle"; } } } } policy ae11up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae11$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/11 unit 0"; "activate interfaces ge-0/0/11 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/11 to bundle"; } } } } policy ae12down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae12$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/12 unit 0"; "deactivate interfaces ge-0/0/12 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae12 went down so removed ge-0/0/12 from bundle"; } } } } policy ae12up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae12$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/12 unit 0"; "activate interfaces ge-0/0/12 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/12 to bundle"; } } } } policy ae13down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae13$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/13 unit 0"; "deactivate interfaces ge-0/0/13 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae13 went down so removed ge-0/0/13 from bundle"; } } } } policy ae13up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae13$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/13 unit 0"; "activate interfaces ge-0/0/13 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/13 to bundle"; } } } } policy ae14down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae14$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/14 unit 0"; "deactivate interfaces ge-0/0/14 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae14 went down so removed ge-0/0/14 from bundle"; } } } } policy ae14up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae14$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/14 unit 0"; "activate interfaces ge-0/0/14 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/14 to bundle"; } } } } policy ae15down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae15$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/15 unit 0"; "deactivate interfaces ge-0/0/15 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae15 went down so removed ge-0/0/15 from bundle"; } } } } policy ae15up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae15$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/15 unit 0"; "activate interfaces ge-0/0/15 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/15 to bundle"; } } } } policy ae16down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae16$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/16 unit 0"; "deactivate interfaces ge-0/0/16 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae16 went down so removed ge-0/0/16 from bundle"; } } } } policy ae16up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae16$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/16 unit 0"; "activate interfaces ge-0/0/16 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/16 to bundle"; } } } } policy ae17down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae17$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/17 unit 0"; "deactivate interfaces ge-0/0/17 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae17 went down so removed ge-0/0/17 from bundle"; } } } } policy ae17up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae17$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/17 unit 0"; "activate interfaces ge-0/0/17 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/17 to bundle"; } } } } policy ae18down { events snmp_trap_link_down; attributes-match { snmp_trap_link_down.interface-name matches "ae18$"; } then { change-configuration { retry count 10 interval 10; commands { "activate interfaces ge-0/0/18 unit 0"; "deactivate interfaces ge-0/0/18 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae18 went down so removed ge-0/0/18 from bundle"; } } } } policy ae18up { events snmp_trap_link_up; attributes-match { snmp_trap_link_up.interface-name matches "ae18$"; } then { change-configuration { retry count 10 interval 10; commands { "deactivate interfaces ge-0/0/18 unit 0"; "activate interfaces ge-0/0/18 ether-options"; } user-name technet; commit-options { log "Autoconfig-script: ae0 came up so added ge-0/0/18 to bundle"; } } } } } protocols { apply-groups [ SET_OSPF_DEFAULTS SET_RA_DEFAULTS ]; mld; inactive: router-advertisement { interface vlan.1052; interface vlan.1071; interface vlan.1072; interface vlan.1091; interface vlan.1092; interface vlan.1111; interface vlan.1112; interface vlan.1131; interface vlan.1132; interface vlan.1151; interface vlan.1152; interface vlan.1171; interface vlan.1172; interface vlan.1191; interface vlan.1192; interface vlan.1211; interface vlan.1212; interface vlan.1231; interface vlan.1232; } ospf { export [ static-to-ospf direct-to-ospf ]; area 0.0.0.0 { interface ae31.0; } } ospf3 { export [ static-to-ospf direct-to-ospf ]; area 0.0.0.0 { interface ae31.0; } } pim { rp { static { address 2a06:5841:148b::67; address 185.110.148.67; } } } sflow { agent-id 185.110.148.101; sample-rate { ingress 10000; egress 10000; } source-ip 185.110.148.101; collector ; interfaces all-ports; } igmp-snooping { vlan all; } rstp; lldp { management-address 185.110.148.101; interface all; } lldp-med { interface all; } } policy-options { prefix-list mgmt-v4 { /* KANDU PA-nett (brukt på servere, infra etc) */ 185.110.148.0/22; } prefix-list mgmt-v6 { /* KANDU PA-nett (den delen som er brukt på servere, infra etc) */ 2a06:5841::/32; } prefix-list mgmt { 185.110.148.0/22; 2a06:5841::/32; } prefix-list mgmt-v4-nms { 185.110.148.11/32; 185.110.148.12/32; } prefix-list mgmt-v6-nms { 2a06:5841:1337::11/128; 2a06:5841:1337::12/128; } prefix-list mgmt-nms { 185.110.148.11/32; 185.110.148.12/32; 185.110.150.10/32; 2a06:5841:1337::11/128; 2a06:5841:1337::12/128; } prefix-list icmp_unthrottled-v4 { 185.110.148.0/22; 193.212.22.0/30; } prefix-list icmp_unthrottled-v6 { 2001:4600:9:300::290/126; 2a06:5841::/32; } policy-statement direct-to-ospf { from protocol direct; then { external { type 1; } accept; } } policy-statement static-to-ospf { from protocol static; then { external { type 1; } accept; } } } firewall { family inet { filter protect-mgmt-v4 { term accept-ssh { from { source-prefix-list { mgmt-v4; } destination-port 22; } then accept; } term discard-ssh { from { destination-port 22; } then { discard; } } term snmp-nms { from { source-prefix-list { mgmt-v4-nms; } destination-port snmp; } then accept; } term snmp-throttle { from { source-prefix-list { mgmt-v4; } destination-port snmp; } then accept; } term icmp-trusted { from { source-prefix-list { icmp_unthrottled-v4; } protocol icmp; } then accept; } term icmp-throttled { from { protocol icmp; } then accept; } term accept-all { then accept; } } } family inet6 { filter protect-mgmt-v6 { term accept-ssh { from { source-prefix-list { mgmt-v6; } destination-port 22; } then accept; } term discard-ssh { from { destination-port 22; } then discard; } term snmp-nms { from { source-prefix-list { mgmt-v6-nms; } destination-port snmp; } then accept; } term snmp-throttle { from { source-prefix-list { mgmt-v6; } destination-port snmp; } then accept; } term icmp-trusted { from { source-prefix-list { icmp_unthrottled-v6; } next-header icmp6; } then accept; } term icmp-throttled { from { next-header icmp6; } then accept; } term accept-all { then accept; } } } } virtual-chassis { preprovisioned; member 0 { role routing-engine; serial-number ; } member 1 { role routing-engine; serial-number ; } member 2 { role line-card; serial-number ; } } ethernet-switching-options { storm-control { interface all; } } vlans { aps_mgmt { vlan-id 777; l3-interface vlan.777; } e11-1 { vlan-id 1111; l3-interface vlan.1111; } e11-2 { vlan-id 1112; l3-interface vlan.1112; } e13-1 { vlan-id 1131; l3-interface vlan.1131; } e13-2 { vlan-id 1132; l3-interface vlan.1132; } e15-1 { vlan-id 1151; l3-interface vlan.1151; } e15-2 { vlan-id 1152; l3-interface vlan.1152; } e17-1 { vlan-id 1171; l3-interface vlan.1171; } e17-2 { vlan-id 1172; l3-interface vlan.1172; } e19-1 { vlan-id 1191; l3-interface vlan.1191; } e19-2 { vlan-id 1192; l3-interface vlan.1192; } e21-1 { vlan-id 1211; l3-interface vlan.1211; } e21-2 { vlan-id 1212; l3-interface vlan.1212; } e23-1 { vlan-id 1231; l3-interface vlan.1231; } e23-2 { vlan-id 1232; l3-interface vlan.1232; } e5-2 { vlan-id 1052; l3-interface vlan.1052; } e7-1 { vlan-id 1071; l3-interface vlan.1071; } e7-2 { vlan-id 1072; l3-interface vlan.1072; } e9-1 { vlan-id 1091; l3-interface vlan.1091; } e9-2 { vlan-id 1092; l3-interface vlan.1092; } mgmt { vlan-id 666; l3-interface vlan.666; } } poe { interface all; }