You are on page 1of 39

## Last commit: 2017-08-03 14:20:28 CEST by bjbd6177

version 12.3X50-D30.2;
groups {
VrrpMaster {
interfaces {
<*> {
unit <*> {
family inet {
address <*> {
vrrp-group <*> {
priority 150;
fast-interval 1000;
preempt {
hold-time 380;
}
accept-data;
}
}
}
}
}
}
}
VrrpBackup {
interfaces {
<*> {
unit <*> {
family inet {
address <*> {
vrrp-group <*> {
priority 110;
fast-interval 1000;
preempt {
hold-time 380;
}
accept-data;
}
}
}
}
}
}
}
Port_AE_N3 {
interfaces {
<ae*> {
description Port_AE;
vlan-tagging;
mtu 9162;
aggregated-ether-options {
lacp {
active;
periodic fast;
}
}
}
}
}
PortAe {
interfaces {
<ae*> {
description "Port AE - description manquante";
mtu 9162;
aggregated-ether-options {
lacp {
active;
periodic fast;
}
}
}
}
}
PortNotUsed {
interfaces {
<*> {
description NonUtilisee;
disable;
}
}
}
PortOSPF {
interfaces {
<*> {
description "Port OSPF - description manquante";
mtu 9162;
hold-time up 270000 down 0;
}
}
}
PortAeMCLAG {
interfaces {
<*> {
description "Port AE_MC-LAG - description manquante";
mtu 9162;
aggregated-ether-options {
lacp {
active;
periodic fast;
}
mc-ae {
mode active-active;
init-delay-time 300;
}
}
unit 0 {
family ethernet-switching {
port-mode trunk;
}
}
}
}
}
PortAeActiveMCLAG {
interfaces {
<*> {
aggregated-ether-options {
flow-control;
mc-ae {
chassis-id 0;
status-control active;
}
}
}
}
}
PortAeStandbyMCLAG {
interfaces {
<*> {
aggregated-ether-options {
flow-control;
mc-ae {
chassis-id 1;
status-control standby;
}
}
}
}
}
PortMCLAG {
interfaces {
<*> {
description "Port MC-LAG - description manquante";
hold-time up 300000 down 0;
}
}
}
PortAeMCLAGVlans {
interfaces {
<*> {
unit 0 {
family ethernet-switching {
port-mode trunk;
vlan {
members 1102;
}
}
}
}
}
}
PortAeMCLAGVlansICCP {
interfaces {
<*> {
unit 0 {
family ethernet-switching {
vlan {
members 498;
}
}
}
}
}
}
PortAeICCP {
interfaces {
<ae*> {
description "Port AE - description manquante";
mtu 9162;
aggregated-ether-options {
lacp {
active;
periodic slow;
}
}
}
}
}
PortICCP {
interfaces {
<*> {
description "Port ICCP - description manquante";
hold-time up 0 down 7000;
}
}
}
Port_Access {
interfaces {
<*> {
description "Port Access - description manquante ";
mtu 9162;
hold-time up 5000 down 0;
unit 0 {
family ethernet-switching {
port-mode access;
}
}
}
}
}
Port_Trunk {
interfaces {
<*> {
description "Port Trunk - description manquante ";
mtu 9162;
hold-time up 5000 down 0;
unit 0 {
family ethernet-switching {
port-mode trunk;
}
}
}
}
}
}
system {
host-name L3SRND1DOSPRD03;
time-zone Europe/Paris;
no-redirects;
arp {
passive-learning;
purging;
gratuitous-arp-on-ifup;
}
authentication-order [ tacplus password ];
ports {
console log-out-on-disconnect;
}
root-authentication {
encrypted-password "$1$CV2vLVfi$ZaEE99jjOCgxz8fFzisEp."; ## SECRET-DATA
}
tacplus-server {
10.114.138.98 {
secret "$9$eaZMWXxNdgoGCtWxNb2g5Qz39t1Ic"; ## SECRET-DATA
timeout 1;
single-connection;
source-address 10.109.128.146;
}
10.114.134.67 {
secret "$9$wb2gaJGDmfzylgJGi.m0B1RSl8LN"; ## SECRET-DATA
timeout 1;
single-connection;
source-address 10.109.128.146;
}
}
accounting {
events [ login change-log interactive-commands ];
destination {
tacplus;
}
}
login {
announcement L3SRND1DOSPRD03;
message "ATTENTION:\nQuiconque accederait ou tenterait d'acceder a ce
Systeme d'Information,\nsans y avoir ete autorise expressement et ce, en toute
connaissance de\ncause, - ou encore qui s'y maintiendrait apres y etre
entre\ninvolontairement\ns'exposerait aux sanctions prevues a l'article 323-1 du
Nouveau Code Penal,\nsoit un an de prison et 15 244 Euros d'amende.\n";
class admin-reseaux {
idle-timeout 10;
permissions all;
}
class readonly {
idle-timeout 10;
permissions view;
}
class remote_access {
idle-timeout 45;
permissions all;
}
user admndc {
uid 2000;
class super-user;
authentication {
encrypted-password "$1$Z2XCYYhT$SHaz07y8Wm3Orj2dZGxSr1"; ## SECRET-
DATA
}
}
user archi {
uid 2001;
class readonly;
authentication {
encrypted-password "$1$X7NHbsyZ$qnljo4KmdijAUMxwAS6ok0"; ## SECRET-
DATA
}
}
user readonly {
uid 2002;
class readonly;
}
user remote_user {
uid 2003;
class remote_access;
}
}
services {
ftp;
ssh {
root-login deny;
protocol-version v2;
}
netconf {
ssh {
connection-limit 2;
rate-limit 4;
}
}
dhcp {
traceoptions {
file dhcp_logfile;
level all;
flag all;
}
}
}
syslog {
archive size 100m files 10;
user * {
any emergency;
}
host 10.114.138.46 {
authorization info;
daemon warning;
kernel notice;
user warning;
match "!(.*krt_decode_ifmismatch.*|.*/usr/sbin/sshd.*|.*aggregated-
ether-options link-spsage.*|.*aggregated-ether-options has no.*|.*dynamic-
profiles.*)";
explicit-priority;
}
file messages {
any notice;
authorization info;
daemon any;
kernel any;
archive world-readable;
explicit-priority;
}
file interactive-commands {
interactive-commands any;
}
file cli-commands {
interactive-commands any;
explicit-priority;
}
file Updown {
any info;
match .*SNMP_TRAP_LINK.*;
archive size 10m files 5;
}
time-format millisecond;
source-address 10.109.128.146;
}
commit synchronize;
ntp {
boot-server 10.114.138.89;
server 10.114.138.89 prefer;
server 10.114.134.61;
source-address 10.109.128.146;
}
}
chassis {
##
## Warning: configuration block ignored: unsupported platform (qfx3500s)
##
redundancy {
graceful-switchover;
}
aggregated-devices {
ethernet {
device-count 51;
}
}
fpc 0 {
pic 2 {
xle {
port-range 0 3;
}
}
}
alarm {
management-ethernet {
link-down ignore;
}
}
auto-image-upgrade;
}
interfaces {
xe-0/0/0 {
apply-groups PortMCLAG;
description ns_opdossn250_sfp;
ether-options {
802.3ad ae1;
}
}
xe-0/0/1 {
apply-groups PortMCLAG;
description ns_opdossn251_sfp;
ether-options {
802.3ad ae2;
}
}
xe-0/0/2 {
apply-groups PortMCLAG;
description ns_opdossn252_sfp;
ether-options {
802.3ad ae3;
}
}
xe-0/0/3 {
apply-groups PortMCLAG;
description ns_opdossn253_sfp;
ether-options {
802.3ad ae4;
}
}
xe-0/0/4 {
apply-groups PortMCLAG;
description ns_opdossn254_sfp;
ether-options {
802.3ad ae5;
}
}
xe-0/0/5 {
apply-groups PortMCLAG;
description ns_opdossn255_sfp;
ether-options {
802.3ad ae6;
}
}
xe-0/0/6 {
apply-groups PortMCLAG;
description ns_opdossn256_sfp;
ether-options {
802.3ad ae7;
}
}
xe-0/0/7 {
apply-groups PortMCLAG;
description ns_opdossn257_sfp;
ether-options {
802.3ad ae8;
}
}
xe-0/0/8 {
apply-groups PortMCLAG;
description ns_opdossn258_sfp;
ether-options {
802.3ad ae9;
}
}
xe-0/0/9 {
apply-groups PortMCLAG;
description ns_opdossn259_sfp;
ether-options {
802.3ad ae10;
}
}
xe-0/0/10 {
apply-groups PortMCLAG;
description ns_opdossn260_sfp;
ether-options {
802.3ad ae11;
}
}
xe-0/0/11 {
apply-groups PortMCLAG;
description ns_opdossn261_sfp;
ether-options {
802.3ad ae12;
}
}
xe-0/0/12 {
apply-groups PortMCLAG;
description ns_opdossn262_sfp;
ether-options {
802.3ad ae13;
}
}
xe-0/0/13 {
apply-groups PortMCLAG;
description ns_opdossn263_sfp;
ether-options {
802.3ad ae14;
}
}
xe-0/0/14 {
apply-groups PortMCLAG;
description ns_opdossn264_sfp;
ether-options {
802.3ad ae15;
}
}
xe-0/0/15 {
apply-groups PortMCLAG;
description ns_opdossn265_sfp;
ether-options {
802.3ad ae16;
}
}
xe-0/0/16 {
apply-groups PortMCLAG;
description ns_opdossn266_sfp;
ether-options {
802.3ad ae17;
}
}
xe-0/0/17 {
apply-groups PortMCLAG;
description ns_opdossn267_sfp;
ether-options {
802.3ad ae18;
}
}
xe-0/0/18 {
apply-groups PortMCLAG;
description ns_opdossn268_sfp;
ether-options {
802.3ad ae19;
}
}
xe-0/0/19 {
apply-groups PortMCLAG;
description ns_opdossn269_sfp;
ether-options {
802.3ad ae20;
}
}
xe-0/0/20 {
apply-groups PortMCLAG;
description ns_opdossn270_sfp;
ether-options {
802.3ad ae21;
}
}
xe-0/0/21 {
apply-groups PortMCLAG;
description ns_opdossn271_sfp;
ether-options {
802.3ad ae22;
}
}
xe-0/0/22 {
apply-groups PortMCLAG;
description ns_opdossn272_sfp;
ether-options {
802.3ad ae23;
}
}
xe-0/0/23 {
apply-groups PortMCLAG;
description ns_opdossn273_sfp;
ether-options {
802.3ad ae24;
}
}
xe-0/0/24 {
apply-groups PortMCLAG;
description ns_opdossn274_sfp;
ether-options {
802.3ad ae25;
}
}
xe-0/0/25 {
apply-groups PortMCLAG;
description ns_opdossn275_sfp;
ether-options {
802.3ad ae26;
}
}
xe-0/0/26 {
apply-groups PortMCLAG;
description ns_opdossn276_sfp;
ether-options {
802.3ad ae27;
}
}
xe-0/0/27 {
apply-groups PortMCLAG;
description ns_opdossn277_sfp;
ether-options {
802.3ad ae28;
}
}
xe-0/0/28 {
apply-groups PortMCLAG;
description ns_opdossn278_sfp;
ether-options {
802.3ad ae29;
}
}
xe-0/0/29 {
apply-groups PortMCLAG;
description ns_opdossn279_sfp;
ether-options {
802.3ad ae30;
}
}
xe-0/0/30 {
apply-groups PortMCLAG;
description ns_opdossn280_sfp;
ether-options {
802.3ad ae31;
}
}
xe-0/0/31 {
apply-groups PortMCLAG;
description ns_opdossn281_sfp;
ether-options {
802.3ad ae32;
}
}
xe-0/0/32 {
apply-groups PortMCLAG;
description ns_opdossn282_sfp;
ether-options {
802.3ad ae33;
}
}
xe-0/0/33 {
apply-groups PortMCLAG;
description ns_opdossn283_sfp;
ether-options {
802.3ad ae34;
}
}
xe-0/0/34 {
apply-groups PortMCLAG;
description ns_opdossn284_sfp;
ether-options {
802.3ad ae35;
}
}
xe-0/0/35 {
apply-groups PortMCLAG;
description ns_opdossn285_sfp;
ether-options {
802.3ad ae36;
}
}
xe-0/0/36 {
apply-groups PortMCLAG;
description ns_opdossn286_sfp;
ether-options {
802.3ad ae37;
}
}
xe-0/0/37 {
apply-groups PortMCLAG;
description ns_opdossn287_sfp;
ether-options {
802.3ad ae38;
}
}
xe-0/0/38 {
apply-groups PortMCLAG;
description ns_opdossn288_sfp;
ether-options {
802.3ad ae39;
}
}
xe-0/0/39 {
apply-groups PortMCLAG;
description ns_opdossn289_sfp;
ether-options {
802.3ad ae40;
}
}
xe-0/0/40 {
apply-groups PortMCLAG;
description ns_opdossn290_sfp;
ether-options {
802.3ad ae41;
}
}
xe-0/0/41 {
apply-groups PortMCLAG;
description ns_opdossn291_sfp;
ether-options {
802.3ad ae42;
}
}
xe-0/0/42 {
apply-groups PortMCLAG;
description ns_opdossn292_sfp;
ether-options {
802.3ad ae43;
}
}
xe-0/0/43 {
apply-groups PortMCLAG;
description ns_opdossn293_sfp;
ether-options {
802.3ad ae44;
}
}
xe-0/0/44 {
apply-groups PortMCLAG;
description ns_opdossn294_sfp;
ether-options {
802.3ad ae45;
}
}
xe-0/0/45 {
apply-groups PortMCLAG;
description ns_opdossn295_sfp;
ether-options {
802.3ad ae46;
}
}
xe-0/0/46 {
apply-groups PortNotUsed;
description ns_mirroring;
}
xe-0/0/47 {
apply-groups PortNotUsed;
description ns_mirroring;
}
xle-0/2/0 {
apply-groups PortOSPF;
description L3SDND1DOSPRD01_et-0/0/6;
vlan-tagging;
unit 1905 {
description innd1dosprdstn05;
vlan-id 1905;
family inet {
address 10.79.1.50/30;
}
}
unit 1925 {
description innd1dosadmstn05;
vlan-id 1925;
family inet {
address 10.79.5.2/30;
}
}
}
xle-0/2/1 {
apply-groups PortOSPF;
description L3SDND1DOSPRD02_et-0/0/6;
vlan-tagging;
unit 1907 {
description innd1dosprdstn07;
vlan-id 1907;
family inet {
address 10.79.1.58/30;
}
}
unit 1927 {
description innd1dosadmstn07;
vlan-id 1927;
family inet {
address 10.79.5.10/30;
}
}
}
xle-0/2/2 {
apply-groups PortICCP;
description L3SRND1DOSPRD04_xle-0/2/2;
ether-options {
802.3ad ae50;
}
}
xle-0/2/3 {
apply-groups PortICCP;
description L3SRND1DOSPRD04_xle-0/2/3;
ether-options {
802.3ad ae50;
}
}
ae1 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn250;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:01;
admin-key 1;
}
mc-ae {
mc-ae-id 1;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae2 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn251;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:02;
admin-key 2;
}
mc-ae {
mc-ae-id 2;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae3 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn252;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:03;
admin-key 3;
}
mc-ae {
mc-ae-id 3;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae4 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn253;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:04;
admin-key 4;
}
mc-ae {
mc-ae-id 4;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae5 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn254;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:05;
admin-key 5;
}
mc-ae {
mc-ae-id 5;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae6 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn255;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:06;
admin-key 6;
}
mc-ae {
mc-ae-id 6;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae7 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn256;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:07;
admin-key 7;
}
mc-ae {
mc-ae-id 7;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae8 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn257;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:08;
admin-key 8;
}
mc-ae {
mc-ae-id 8;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae9 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn258;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:09;
admin-key 9;
}
mc-ae {
mc-ae-id 9;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae10 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn259;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:10;
admin-key 10;
}
mc-ae {
mc-ae-id 10;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae11 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn260;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:11;
admin-key 11;
}
mc-ae {
mc-ae-id 11;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae12 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn261;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:12;
admin-key 12;
}
mc-ae {
mc-ae-id 12;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae13 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn262;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:13;
admin-key 13;
}
mc-ae {
mc-ae-id 13;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae14 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn263;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:14;
admin-key 14;
}
mc-ae {
mc-ae-id 14;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae15 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn264;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:15;
admin-key 15;
}
mc-ae {
mc-ae-id 15;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae16 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn265;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:16;
admin-key 16;
}
mc-ae {
mc-ae-id 16;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae17 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn266;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:17;
admin-key 17;
}
mc-ae {
mc-ae-id 17;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae18 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn267;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:18;
admin-key 18;
}
mc-ae {
mc-ae-id 18;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae19 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn268;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:19;
admin-key 19;
}
mc-ae {
mc-ae-id 19;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae20 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn269;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:20;
admin-key 20;
}
mc-ae {
mc-ae-id 20;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae21 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn270;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:21;
admin-key 21;
}
mc-ae {
mc-ae-id 21;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae22 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn271;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:22;
admin-key 22;
}
mc-ae {
mc-ae-id 22;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae23 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn272;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:23;
admin-key 23;
}
mc-ae {
mc-ae-id 23;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae24 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn273;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:24;
admin-key 24;
}
mc-ae {
mc-ae-id 24;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae25 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn274;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:25;
admin-key 25;
}
mc-ae {
mc-ae-id 25;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae26 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn275;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:26;
admin-key 26;
}
mc-ae {
mc-ae-id 26;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae27 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn276;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:27;
admin-key 27;
}
mc-ae {
mc-ae-id 27;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae28 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn277;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:28;
admin-key 28;
}
mc-ae {
mc-ae-id 28;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae29 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn278;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:29;
admin-key 29;
}
mc-ae {
mc-ae-id 29;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae30 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn279;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:30;
admin-key 30;
}
mc-ae {
mc-ae-id 30;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae31 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn280;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:31;
admin-key 31;
}
mc-ae {
mc-ae-id 31;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae32 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn281;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:32;
admin-key 32;
}
mc-ae {
mc-ae-id 32;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae33 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn282;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:33;
admin-key 33;
}
mc-ae {
mc-ae-id 33;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae34 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn283;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:34;
admin-key 34;
}
mc-ae {
mc-ae-id 34;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae35 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn284;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:35;
admin-key 35;
}
mc-ae {
mc-ae-id 35;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae36 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn285;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:36;
admin-key 36;
}
mc-ae {
mc-ae-id 36;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae37 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn286;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:37;
admin-key 37;
}
mc-ae {
mc-ae-id 37;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae38 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn287;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:38;
admin-key 38;
}
mc-ae {
mc-ae-id 38;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae39 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn288;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:39;
admin-key 39;
}
mc-ae {
mc-ae-id 39;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae40 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn289;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:40;
admin-key 40;
}
mc-ae {
mc-ae-id 40;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae41 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn290;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:41;
admin-key 41;
}
mc-ae {
mc-ae-id 41;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae42 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn291;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:42;
admin-key 42;
}
mc-ae {
mc-ae-id 42;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae43 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn292;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:43;
admin-key 43;
}
mc-ae {
mc-ae-id 43;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae44 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn293;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:44;
admin-key 44;
}
mc-ae {
mc-ae-id 44;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae45 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn294;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:45;
admin-key 45;
}
mc-ae {
mc-ae-id 45;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae46 {
apply-groups [ PortAeActiveMCLAG PortAeMCLAG ];
description ns_opdossn295;
aggregated-ether-options {
lacp {
system-id 00:01:02:03:04:46;
admin-key 46;
}
mc-ae {
mc-ae-id 46;
mode active-active;
}
}
unit 0 {
family ethernet-switching {
native-vlan-id 1102;
}
}
}
ae47 {
apply-groups PortNotUsed;
}
ae48 {
apply-groups PortNotUsed;
}
ae49 {
apply-groups PortNotUsed;
}
ae50 {
apply-groups [ PortAeICCP PortAeMCLAGVlansICCP PortAeMCLAGVlans ];
description L3SRND1DOSPRD04_ae50;
aggregated-ether-options {
minimum-links 1;
link-speed 40g;
}
unit 0 {
family ethernet-switching;
}
}
lo0 {
unit 0 {
family inet {
filter {
input protect-re;
}
address 10.109.128.146/32;
}
}
unit 1 {
family inet {
filter {
input protect-re;
}
address 10.109.128.146/32;
}
}
unit 2 {
description Loopback_OSPF_PRD-V-DOS;
family inet {
address 10.77.201.88/32;
}
}
}
me0 {
unit 0 {
family inet {
address 192.168.2.1/30;
}
}
}
vlan {
mtu 9162;
unit 0 {
family inet {
dhcp {
vendor-id Juniper-qfx3500s;
}
}
}
unit 498 {
family inet {
address 10.79.5.237/30;
}
}
unit 1102 {
family inet {
address 10.110.60.124/26 {
vrrp-group 60 {
apply-groups VrrpMaster;
virtual-address 10.110.60.126;
}
}
}
}
}
}
multi-chassis {
multi-chassis-protection 10.79.5.238 {
interface ae50;
}
}
snmp {
name L3SRND1DOSPRD03;
description Switch_QFX;
location ND1;
contact FQCRMH;
client-list Phare {
10.114.0.0/16;
10.96.24.0/26;
}
community NetOrange {
authorization read-only;
client-list-name Phare;
}
trap-options {
source-address 10.109.128.146;
}
trap-group public {
version v2;
categories {
chassis;
link;
routing;
startup;
services;
}
targets {
10.114.138.57;
10.114.130.2;
10.114.138.214;
10.114.134.140;
}
}
}
routing-options {
graceful-restart;
static {
route 10.0.0.0/8 {
next-table ADM-S-DOS-RES.inet.0;
no-readvertise;
}
}
autonomous-system 65062;
forwarding-table {
export load-balance;
}
}
protocols {
iccp {
local-ip-addr 10.79.5.237;
peer 10.79.5.238 {
session-establishment-hold-time 50;
backup-liveness-detection {
backup-peer-ip 192.168.2.2;
}
liveness-detection {
minimum-receive-interval 1000;
transmit-interval {
minimum-interval 900;
}
}
}
inactive: traceoptions {
file iccp-log size 10m;
flag all;
}
}
lacp {
inactive: traceoptions {
file LACP_log size 10m files 5;
flag all;
}
}
igmp-snooping {
vlan all {
interface ae50.0 {
multicast-router-interface;
}
}
}
dcbx {
interface all;
}
rstp {
interface ae50.0 {
disable;
}
interface all {
edge;
}
bpdu-block-on-edge;
}
lldp {
port-id-subtype interface-name;
interface all;
}
lldp-med {
interface all;
}
}
policy-options {
prefix-list LOCALHOST {
127.0.0.1/32;
}
prefix-list NTP-ADDRESSES {
apply-path "system ntp server <*>";
}
prefix-list TACACS-ADDRESSES {
apply-path "system tacplus-server <*>";
}
prefix-list BGP-ADDRESSES-VRF {
apply-path "routing-instances <*> protocols bgp group <*> neighbor <*>";
}
prefix-list LOOPBACK-ADDRESS {
apply-path "interfaces lo0 unit <*> family inet address <*>";
}
prefix-list MGMT-ADDRESSES {
10.114.0.0/16;
}
prefix-list INTERNAL-ADDRESSES {
apply-path "interfaces <*> unit <*> family inet address <*> vrrp-group <*>
virtual-address <*>";
}
prefix-list PRD-V-DOS-MULTI-SITES {
10.110.60.0/22;
}
prefix-list ADM-IPs {
10.102.16.0/24;
10.102.20.0/24;
10.102.225.0/26;
10.102.228.0/23;
10.102.233.0/24;
10.102.236.0/24;
10.103.71.64/26;
10.103.145.0/24;
10.103.160.64/26;
10.103.171.0/24;
10.103.230.192/26;
10.103.231.0/24;
10.105.156.0/23;
10.105.188.0/23;
10.109.128.0/20;
10.114.130.1/32;
10.114.130.2/32;
10.114.130.3/32;
10.114.130.4/32;
10.114.132.0/24;
10.114.134.0/24;
10.114.136.8/29;
10.114.136.40/29;
10.114.136.56/29;
10.114.136.73/32;
10.114.136.88/29;
10.114.137.194/32;
10.114.137.200/32;
10.114.137.201/32;
10.114.137.203/32;
10.114.137.205/32;
10.114.137.210/32;
10.114.138.0/24;
10.114.139.0/24;
10.114.140.0/23;
10.114.143.0/24;
10.114.148.8/29;
10.114.150.2/32;
10.114.150.6/32;
10.114.154.3/32;
10.114.154.4/32;
10.114.154.5/32;
10.114.158.1/32;
10.114.158.2/32;
10.114.168.0/24;
10.114.173.0/24;
10.114.175.194/32;
10.114.175.195/32;
10.114.175.200/32;
10.114.175.201/32;
10.114.175.204/32;
10.114.175.205/32;
10.114.175.207/32;
10.114.176.0/22;
10.114.181.0/26;
}
prefix-list STK-IPs {
10.196.15.0/24;
}
policy-statement PRD-V-DOS_OSPF_export {
then accept;
}
policy-statement PRD-V-DOS_OSPF_import {
then accept;
}
policy-statement PRD-V-DOS_direct_tag {
term direct_MULTI-SITES {
from {
protocol direct;
prefix-list-filter PRD-V-DOS-MULTI-SITES orlonger;
}
then {
tag 1;
next policy;
}
}
}
policy-statement damping_default {
then damping damping_default;
}
policy-statement export-ospf {
term DENY-DEFAULT {
from {
route-filter 0.0.0.0/0 exact;
}
then reject;
}
term export-ospf {
from protocol [ direct static ];
then {
external {
type 1;
}
accept;
}
}
term DEFAULT {
then reject;
}
}
policy-statement export_OBOS {
term All {
from protocol [ static direct ];
then accept;
}
}
policy-statement load-balance {
then {
load-balance per-packet;
}
}
damping damping_default {
half-life 1;
reuse 1000;
suppress 2000;
max-suppress 4;
}
}
firewall {
family inet {
filter protect-re {
term BFD {
from {
protocol udp;
destination-port 3784;
}
then accept;
}
term MH-BFD {
from {
protocol udp;
destination-port 4784;
}
then accept;
}
term BLD {
from {
protocol udp;
destination-port 50015;
}
then accept;
}
term ICCP-src {
from {
protocol tcp;
source-port 33012;
}
then accept;
}
term ICCP-dst {
from {
protocol tcp;
destination-port 33012;
}
then accept;
}
term SSH-dst {
from {
source-prefix-list {
MGMT-ADDRESSES;
}
protocol tcp;
destination-port ssh;
}
then accept;
}
term SSH-src {
from {
source-prefix-list {
MGMT-ADDRESSES;
}
protocol tcp;
source-port ssh;
}
then accept;
}
term OSPF {
from {
protocol ospf;
}
then accept;
}
term BGP-dst {
from {
source-prefix-list {
BGP-ADDRESSES-VRF;
}
protocol tcp;
destination-port bgp;
}
then accept;
}
term BGP-src {
from {
source-prefix-list {
BGP-ADDRESSES-VRF;
}
protocol tcp;
source-port bgp;
}
then accept;
}
term VRRP {
from {
destination-address {
224.0.0.18/32;
}
protocol vrrp;
}
then {
policer VRRP-POLICER;
accept;
}
}
term SNMP {
from {
source-prefix-list {
MGMT-ADDRESSES;
}
protocol udp;
destination-port snmp;
}
then {
policer SNMP-POLICER;
accept;
}
}
term NTP {
from {
source-prefix-list {
NTP-ADDRESSES;
}
protocol udp;
source-port ntp;
}
then {
policer NTP-POLICER;
accept;
}
}
term TACACS-REPLIES {
from {
source-prefix-list {
TACACS-ADDRESSES;
}
protocol tcp;
source-port 49;
tcp-established;
}
then accept;
}
term ICMP {
from {
protocol icmp;
icmp-type [ echo-reply echo-request info-reply info-request
mask-reply mask-request parameter-problem router-solicit source-quench time-
exceeded timestamp timestamp-reply unreachable ];
}
then {
policer ICMP-POLICER;
accept;
}
}
term UDP-SERVICES {
from {
source-prefix-list {
MGMT-ADDRESSES;
}
protocol udp;
source-port 1024-65535;
}
then {
policer SMALL-BW-POLICER;
count UDP-SERVICES-TRAFFIC;
accept;
}
}
term DISCARD {
then {
count DENY-TO-ROUTING-ENGINE;
discard;
}
}
}
}
policer NTP-POLICER {
if-exceeding {
bandwidth-limit 500k;
burst-size-limit 15k;
}
then discard;
}
policer SMALL-BW-POLICER {
if-exceeding {
bandwidth-limit 1m;
burst-size-limit 15k;
}
then discard;
}
policer SNMP-POLICER {
if-exceeding {
bandwidth-limit 2m;
burst-size-limit 15k;
}
then discard;
}
policer VRRP-POLICER {
if-exceeding {
bandwidth-limit 2m;
burst-size-limit 128k;
}
then discard;
}
policer ICMP-POLICER {
if-exceeding {
bandwidth-limit 5m;
burst-size-limit 15k;
}
then discard;
}
}
routing-instances {
ADM-S-DOS-RES {
instance-type virtual-router;
interface xle-0/2/0.1925;
interface xle-0/2/1.1927;
interface lo0.1;
routing-options {
graceful-restart;
router-id 10.109.128.146;
}
protocols {
ospf {
export export-ospf;
reference-bandwidth 40g;
area 0.0.0.0 {
interface xle-0/2/0.1925 {
interface-type p2p;
}
interface xle-0/2/1.1927 {
interface-type p2p;
}
interface lo0.1 {
passive;
}
}
}
}
}
PRD-V-DOS {
instance-type virtual-router;
interface xle-0/2/0.1905;
interface xle-0/2/1.1907;
interface lo0.2;
interface vlan.1102;
routing-options {
graceful-restart;
router-id 10.77.201.88;
}
protocols {
ospf {
export [ PRD-V-DOS_direct_tag PRD-V-DOS_OSPF_export ];
import PRD-V-DOS_OSPF_import;
reference-bandwidth 40g;
area 0.0.0.0 {
interface xle-0/2/0.1905 {
interface-type p2p;
}
interface xle-0/2/1.1907 {
interface-type p2p;
}
interface lo0.2 {
passive;
}
}
}
}
}
}
vlans {
adnd1dosallicp01 {
vlan-id 498;
l3-interface vlan.498;
}
default {
vlan-id 3333;
l3-interface vlan.0;
}
prnd1dosprdstn02 {
vlan-id 1102;
l3-interface vlan.1102;
}
}
ethernet-switching-options {
storm-control {
interface ae50.0 {
bandwidth 4000000;
}
interface all {
bandwidth 1000000;
}
}
}

You might also like