You are on page 1of 79

INPUT INFORMATION

NAME_AGG CP_HUC8116
LOOPBACK 0 10.122.12.212
LOOPBACK 1 10.122.14.212
CA_MASTER CA_SOUTH_SI_01
CA_SLAVE CA_SOUTH_SI_02
MASTER LOOPBACK 0 10.122.12.192
SLAVE LOOPBACK 0 10.122.12.193
CX600-X8A

NAME SYSTEM

LOOPBACK DE
SERVICIO Y OAM
HABILITACION MPLS
QOS (CLASSFIER,
BEHAVIOR, TRAFFIC
to POLICY)
BGP, MBGP

OSPF
OSPF

CLOCK TIMER
ACL
STELNET /
SNETCONFIG / SFTP

SNMP
SNMP

ACCESO A SERVIDOR
DE AUTENTICACION
TACACS
CX600-X8A

#
sysname CP_HUC8116
undo dcn
y
commit
#
efm enable
#
#
ip vpn-instance NMS_ATN910B
description NMS_ATN910B_ME
ipv4-family
route-distinguisher 262.210:31
apply-label per-instance
vpn-target 262.210:31 export-extcommunity
vpn-target 262.210:32 import-extcommunity
commit
#
#
interface LoopBack0
description LOOPBACK_SERVICE
ip address 10.122.12.212 255.255.255.255
q
interface LoopBack1
description LOOOPBACK_OAM
ip binding vpn-instance NMS_ATN910B
ip address 10.122.14.212 255.255.255.255
commit
#
mpls lsr-id 10.122.12.212
mpls
label advertise explicit-null
mpls te
mpls rsvp-te
mpls rsvp-te hello
mpls rsvp-te hello support-peer-gr
mpls te cspf
#
mpls ldp
graceful-restart
y
graceful-restart timer reconnect 180
y
graceful-restart timer recovery 200
y
commit
#
mpls ldp remote-peer ca_south_si_01
remote-ip 10.122.12.192
commit
q
mpls ldp remote-peer ca_south_si_02
remote-ip 10.122.12.193
commit
q
#
#
port-wred WRED_BE
color green low-limit 60 high-limit 100 discard-percentage 100
color yellow low-limit 60 high-limit 100 discard-percentage 100
color red low-limit 60 high-limit 100 discard-percentage 100
#
acl number 3100
rule 10 permit ip dscp 46
rule 20 permit ip dscp 48
#
traffic classifier 3G_VOICE operator or
if-match acl 3100
#
traffic classifier 3G_DATA operator or
if-match any
#
traffic classifier ANY operator or
if-match any
#
traffic behavior BE
service-class be color green
#
traffic behavior AF1
service-class af1 color green
#
traffic behavior AF2
service-class af2 color green
#
traffic behavior AF3
service-class af3 color green
#
traffic behavior AF4
service-class af4 color green
#
traffic behavior EF
service-class ef color green
#
traffic behavior CS6
service-class cs6 color green
#
traffic behavior CS7
service-class cs7 color green
#
traffic policy 3G_Ingress
statistics enable
classifier 3G_VOICE behavior CS6
classifier 3G_DATA behavior EF
#
traffic policy EF_Ingress
statistics enable
classifier ANY behavior EF
#
traffic policy VOD_Ingress
statistics enable
classifier ANY behavior AF3
#
traffic policy VPN_Ingress
statistics enable
classifier ANY behavior AF3
#
traffic policy HSI_Ingress
statistics enable
classifier ANY behavior BE
#
traffic policy OAM_Ingress
statistics enable
classifier ANY behavior AF3
commit
#
bgp 4.66
router-id 10.122.12.212
graceful-restart
graceful-restart timer restart 180
peer 10.122.12.192 as-number 4.66
peer 10.122.12.192 description CA_SOUTH_SI_01
peer 10.122.12.192 connect-interface LoopBack0
peer 10.122.12.192 password cipher Viettel@123
peer 10.122.12.193 as-number 4.66
peer 10.122.12.193 description CA_SOUTH_SI_02
peer 10.122.12.193 connect-interface LoopBack0
peer 10.122.12.193 password cipher Viettel@123
#
ipv4-family unicast
undo synchronization
reflect change-path-attribute
import-route direct
import-route static
auto-frr
supernet unicast advertise enable
peer 10.122.12.192 enable
peer 10.122.12.193 enable
commit
#
ipv4-family vpnv4
reflect change-path-attribute
policy vpn-target
auto-frr
peer 10.122.12.192 enable
y
peer 10.122.12.193 enable
y
commit
#
ipv4-family vpn-instance NMS_ATN910B
import-route direct
import-route static
commit
#
ipv4-family mdt
reflect change-path-attribute
undo policy vpn-target
commit
#
ospf 1 router-id 10.122.12.212
silent-interface LoopBack1
silent-interface LoopBack0
spf-schedule-interval intelligent-timer 200 50 50
lsa-originate-interval intelligent-timer 100 50 50
lsa-arrival-interval intelligent-timer 100 50 50
opaque-capability enable
bandwidth-reference 100000
stub-router on-startup 100
area 0.0.0.0
network 10.122.12.212 0.0.0.0
mpls-te enable
commit
#
#
ntp-service server disable
y
ntp-service ipv6 server disable
ntp-service refclock-master
ntp-service unicast-server preference
ntp-service unicast-server
clock timezone UTC minus 5
commit
#
ntp-service server disable
ntp-service ipv6 server disable
ntp-service refclock-master
ntp-service source-interface LoopBack1 vpn-instance NMS_ATN910B
ntp-service unicast-server 10.122.14.192 preference
ntp-service unicast-server 10.122.14.192 vpn-instance NMS_ATN910B preference
ntp-service unicast-server 10.122.14.193
ntp-service unicast-server 10.122.14.193 vpn-instance NMS_ATN910B
commit
#
acl number 2000
description SNMP
rule 5 permit source 10.121.3.1 0
rule 10 permit source 10.121.3.32 0.0.0.7
rule 20 permit source 10.121.6.136 0
rule 30 permit source 10.121.62.34 0
rule 50 permit source 10.121.62.0 0.0.0.255
rule 55 permit source 10.121.62.99 0
rule 60 permit source 10.121.3.0 0.0.0.255
rule 70 permit vpn-instance NMS_ATN910B source 10.121.3.1 0
rule 80 permit vpn-instance NMS_ATN910B source 10.121.3.32 0.0.0.7
rule 90 permit vpn-instance NMS_ATN910B source 10.121.6.136 0
rule 100 permit vpn-instance NMS_ATN910B source 10.121.62.34 0
rule 110 permit vpn-instance NMS_ATN910B source 10.121.62.0 0.0.0.255
rule 120 permit vpn-instance NMS_ATN910B source 10.121.62.99 0
rule 130 permit vpn-instance NMS_ATN910B source 10.121.3.0 0.0.0.255
rule 140 permit vpn-instance NMS_ATN910B source 10.121.42.0 0.0.0.255
rule 150 permit source 10.121.42.0 0.0.0.255
commit
#
acl number 2100
rule 10 permit source 236.51.1.10 0
rule 20 permit source 236.50.1.10 0
rule 30 permit source 236.52.1.10 0
rule 40 permit source 236.53.1.10 0
commit
#
acl number 3000
description Telnet
rule 25 permit ip source 10.121.62.6 0
rule 35 permit ip source 10.121.62.33 0
rule 40 permit ip source 10.121.6.135 0
rule 45 permit ip source 10.121.124.11 0
rule 50 permit ip source 10.122.0.0 0.0.15.255
rule 60 permit ip source 10.122.12.0 0.0.0.255
rule 70 permit ip source 10.122.14.0 0.0.0.255
rule 80 permit ip source 10.121.6.155 0
rule 85 permit ip source 10.121.6.156 0
rule 90 permit ip vpn-instance NMS_ATN910B source 10.121.62.6 0
rule 100 permit ip vpn-instance NMS_ATN910B source 10.121.62.33 0
rule 110 permit ip vpn-instance NMS_ATN910B source 10.121.6.135 0
rule 120 permit ip vpn-instance NMS_ATN910B source 10.121.124.11 0
rule 130 permit ip vpn-instance NMS_ATN910B source 10.122.0.0 0.0.15.255
rule 140 permit ip vpn-instance NMS_ATN910B source 10.122.12.0 0.0.0.255
rule 150 permit ip vpn-instance NMS_ATN910B source 10.122.14.0 0.0.0.255
rule 160 permit ip vpn-instance NMS_ATN910B source 10.121.6.155 0
rule 170 permit ip vpn-instance NMS_ATN910B source 10.121.6.156 0
rule 220 permit ip vpn-instance NMS_ATN910B source 10.121.13.139 0
rule 230 permit ip vpn-instance NMS_ATN910B source 10.121.13.140 0
rule 240 permit ip vpn-instance NMS_ATN910B source 10.60.97.100 0
rule 250 permit ip vpn-instance NMS_ATN910B source 10.121.13.0 0.0.0.255
rule 255 permit ip vpn-instance NMS_ATN910B source 10.121.62.102 0
commit
#
#
stelnet server enable
ssh user root
ssh user root authentication-type password
ssh user root service-type stelnet
ssh authorization-type default aaa
#
snetconf server enable
ssh client first-time enable
ssh user u2000@ip
ssh user u2000@ip authentication-type password
ssh user u2000@ip service-type all
#
sftp client-source -i LoopBack1 
commit
#
snmp-agent
y
snmp-agent community complexity-check disable
snmp-agent sys-info contact VIETTEL_PERU
snmp-agent sys-info location VIETTEL_PERU
snmp-agent sys-info version all
snmp-agent target-host trap address udp-domain 10.121.3.1 source LoopBack1 params securityname
snmp-agent target-host trap address udp-domain 10.121.3.10 source LoopBack1 vpn-instance NMS_
snmp-agent target-host trap address udp-domain 10.121.3.10 params securityname cipher CP_HUC8
snmp-agent target-host trap address udp-domain 10.121.3.1 source LoopBack1 vpn-instance NMS_A
snmp-agent target-host trap address udp-domain 10.121.3.10 source LoopBack1 vpn-instance NMS_
snmp-agent mib-view included iso iso
snmp-agent mib-view included iso-new iso
snmp-agent mib-view included iso-view iso
snmp-agent mib-view excluded userinfo snmpUsmMIB
snmp-agent mib-view excluded userinfo snmpVacmMIB
snmp-agent mib-view excluded userinfo hwLocalUserTable
snmp-agent mib-view excluded userinfo hwCollectTable
snmp-agent mib-view excluded userinfo hwCfgOperateTable
snmp-agent trap source LoopBack1
snmp-agent community read cipher CP_HUC8116 mib-view iso-view acl 2000
snmp-agent trap enable
y
commit
#
hwtacacs-server template viettel_peru
hwtacacs-server authentication 10.121.62.34 vpn-instance NMS_ATN910B
hwtacacs-server authorization 10.121.62.34 vpn-instance NMS_ATN910B
hwtacacs-server accounting 10.121.62.34 vpn-instance NMS_ATN910B
hwtacacs-server source-ip 10.122.14.212
hwtacacs-server shared-key acsmetrovtp
commit
#
aaa
authentication-scheme default0
authentication-mode hwtacacs local
#
authorization-scheme default
authorization-mode hwtacacs local
authorization-cmd 15 hwtacacs local
#
accounting-scheme default0
accounting-mode hwtacacs
accounting start-fail online
accounting interim-fail max-times 10 online
#
domain default_admin
authentication-scheme default0
authorization-scheme default
accounting-scheme default0
hwtacacs-server viettel_peru
#
recording-scheme 1
recording-mode hwtacacs viettel_peru
#
system recording-scheme 1
outbound recording-scheme 1
cmd recording-scheme 1
#
commit
#
TEMPLATE BGP AGG

AGG BGP

AGG MPLS
B preference
0.0.0.255

opBack1 params securityname cipher CP_HUC8116 v2c


oopBack1 vpn-instance NMS_ATN910B params securityname cipher CP_HUC8116 v2c
ecurityname cipher CP_HUC8116 v2c
opBack1 vpn-instance NMS_ATN910B params securityname cipher CP_HUC8116 v2c
oopBack1 vpn-instance NMS_ATN910B  params securityname cipher CP_HUC8116 v2c
TEMPLATE BGP AGG
#
bgp 4.66
peer 10.122.12.212 as-number 4.66
peer 10.122.12.212 description CP_HUC8116
peer 10.122.12.212 connect-interface LoopBack0
peer 10.122.12.212 password cipher Viettel@123
#
ipv4-family unicast
peer 10.122.12.212 enable
peer 10.122.12.212 reflect-client
#
ipv4-family vpnv4
peer 10.122.12.212 enable
y
peer 10.122.12.212 reflect-client
y
#
ipv4-family mdt
peer 10.122.12.212 enable
peer 10.122.12.212 reflect-client
peer 10.122.12.212 advertise-community
q
q
#

#
mpls ldp remote-peer cp_huc8116
remote-ip 10.122.12.212
#
securityname cipher CP_HUC8116 v2c
stance NMS_ATN910B params securityname cipher CP_HUC8116 v2c
er CP_HUC8116 v2c
ance NMS_ATN910B params securityname cipher CP_HUC8116 v2c
stance NMS_ATN910B  params securityname cipher CP_HUC8116 v2c
interface Eth-Trunk7
description AG_ARE0106_Eth-Trunk7 - CP_ARE0106_Eth-Trunk7
set flow-stat interval 10
mtu 9000
mode lacp-static
load-balance packet-all
lacp timeout fast
trust upstream default
statistic enable

interface Eth-Trunk7.100
vlan-type dot1q 100
description AG_ARE0106_Eth-Trunk7.100 - CP_ARE0106_Eth-Trunk7.100
mtu 9000

pim sm
ospf cost 100

ospf network-type p2p


ospf ldp-sync
mpls
mpls te
mpls rsvp-te
mpls rsvp-te hello
mpls ldp
mpls ldp timer igp-sync-delay 25
trust upstream default
statistic enable

set transfer-mode wan


description AG_ARE0106 Gi 2/0/1 - CP_ARE0106 Gi 1/0/0
undo shutdown
set flow-stat interval 10
eth-trunk 7
efm enable
efm error-frame period 5
efm error-frame threshold 300
efm error-frame notification enable
port-queue be wfq weight 10 port-wred WRED_BE outbound
port-queue af1 wfq weight 20 outbound
port-queue af2 wfq weight 30 outbound
port-queue af3 wfq weight 40 outbound
port-queue af4 wfq weight 50 outbound
transmission-alarm down lais lof los lrdi pais sdbere
transmission-alarm log lais lof los lrdi pais sdbere
transmission-alarm holdoff-timer 50
transmission-alarm holdup-timer 60000
#
INPUT INFORMATION
NAME AR_LIC0707_NEW
LOOPBACK 0 10.124.128.2
LOOPBACK 1 10.126.128.2
AGG_MASTER AG_LIC671_2
AGG_SLAVE AG_CAL010
MASTER LOOPBACK 0 10.122.12.130
SLAVE LOOPBACK 0 10.122.12.131
NAME NEIGHBOR 1
NAME NEIGHBOR 2
OSPF NEIGHBOR 1
OSPF NEIGHBOR 2
INTERFACE 1
INTERFACE 2
VLAN RING
AREA 0.15.47.1
IP 3G NMS
IP 3G NMS GW
IP 3G SERVICE
IP 3G SERVICE GW
IP 4G SERVICE NMS
IP 4G SERVICE GW

peer 10.122.12.76 as-number 4.66


peer 10.122.12.76 description AG_HUN0004_02
peer 10.122.12.76 connect-interface LoopBack0
peer 10.122.12.147 as-number 4.66
peer 10.122.12.147 description TTLIMA2

peer 10.122.12.147 connect-interface LoopBack0


ip ip-prefix IMPORT_NodeB index 10 permit 10.84.0.0 16 greater-equal 16 less-equal 32
ip ip-prefix IMPORT_NodeB index 20 permit 10.87.0.0 16 greater-equal 16 less-equal 32
ip ip-prefix IMPORT_4G index 10 permit 10.70.0.0 16 greater-equal 16 less-equal 32
ip ip-prefix IMPORT_4G index 15 permit 10.72.0.0 16 greater-equal 16 less-equal 32

mpls ldp remote-peer ag_anc0100


remote-ip 10.122.12.66
mpls ldp remote-peer ag_hun0004_02
remote-ip 10.122.12.76
TEMPLATE ATN910C

NAME SYSTEM

INSTANCIAS VPN
(MPLS ROUTE
DISTINGUISHER,
ROUTE TARGET)
LOOPBACK DE
SERVICIO Y OAM

HABILITACION MPLS
QOS (CLASSFIER,
BEHAVIOR, TRAFFIC
to POLICY)
HABILITACION DE
INTERFACES PARA
HACER PEERING
OSPF,MPLS.
BGP, MBGP
BGP, MBGP

OSPF
OSPF

CLOCK TIMER

ACL
ACL

STELNET /
SNETCONFIG / SFTP

SNMP
SNMP

ACCESO A SERVIDOR
DE AUTENTICACION
TACACS
TEMPLATE ATN910C
#
sysname AR_LIC0707_NEW
undo __LOCAL_OAM_VPN__
undo dcn
commit
#

efm enable
#
ip vpn-instance 3G
description 3G
ipv4-family
route-distinguisher 262.210:11
apply-label per-instance
vpn-target 262.210:11 export-extcommunity
vpn-target 262.210:12 import-extcommunity
commit
#
ip vpn-instance 4G
description 4G
ipv4-family
route-distinguisher 262.210:20
apply-label per-instance
vpn-target 262.210:20 export-extcommunity
vpn-target 262.210:20 import-extcommunity
commit
#
ip vpn-instance NMS_ATN910B
description NMS_ATN910B_ME
ipv4-family
route-distinguisher 262.210:31
apply-label per-instance
vpn-target 262.210:31 export-extcommunity
vpn-target 262.210:32 import-extcommunity
#
#
interface LoopBack0
description LOOPBACK_SERVICE
ip address 10.124.128.2 255.255.255.255
q
interface LoopBack1
description LOOOPBACK_OAM
ip binding vpn-instance NMS_ATN910B
ip address 10.126.128.2 255.255.255.255
commit
#
mpls lsr-id 10.124.128.2
mpls
mpls te
mpls rsvp-te
mpls rsvp-te hello
mpls rsvp-te hello full-gr
mpls rsvp-te hello basic-restart-time 180
mpls te cspf
#
mpls l2vpn
#
mpls ldp
graceful-restart
y
graceful-restart timer reconnect 180
y
graceful-restart timer recovery 200
y
commit
#
mpls ldp remote-peer ag_lic671_2
remote-ip 10.122.12.130
commit
q
mpls ldp remote-peer ag_cal010
remote-ip 10.122.12.131
commit
q
#
#
port-wred WRED_BE
color green low-limit 60 high-limit 100 discard-percentage 100
color yellow low-limit 60 high-limit 100 discard-percentage 100
color red low-limit 60 high-limit 100 discard-percentage 100
#
acl number 3100
rule 10 permit ip dscp 46
rule 20 permit ip dscp 48
#
traffic classifier 3G_VOICE operator or
if-match acl 3100
#
traffic classifier 3G_DATA operator or
if-match any
#
traffic classifier ANY operator or
if-match any
#
traffic behavior BE
service-class be color green
#
traffic behavior AF1
service-class af1 color green
#
traffic behavior AF2
service-class af2 color green
#
traffic behavior AF3
service-class af3 color green
#
traffic behavior AF4
service-class af4 color green
#
traffic behavior EF
service-class ef color green
#
traffic behavior CS6
service-class cs6 color green
#
traffic behavior CS7
service-class cs7 color green
#
traffic policy 3G_Ingress
statistics enable
classifier 3G_VOICE behavior CS6
classifier 3G_DATA behavior EF
#
traffic policy EF_Ingress
statistics enable
classifier ANY behavior EF
#
traffic policy VOD_Ingress
statistics enable
classifier ANY behavior AF3
#
traffic policy VPN_Ingress
statistics enable
classifier ANY behavior AF3
#
traffic policy HSI_Ingress
statistics enable
classifier ANY behavior BE
#
traffic policy OAM_Ingress
statistics enable
classifier ANY behavior AF3
commit
#
#
interface GigabitEthernet .
vlan-type dot1q
description AR_LIC0707_NEW - 10G
undo shutdown
mtu 9000
ip address 255.255.255.252
ospf network-type p2p
ospf ldp-sync
mpls
mpls te
mpls rsvp-te
mpls rsvp-te hello
mpls ldp
mpls ldp timer igp-sync-delay 25
trust upstream default
#
interface GigabitEthernet
description
undo shutdown
efm error-frame period 5
efm error-frame threshold 300
efm error-frame notification enable
undo dcn
carrier down-hold-time 100
carrier up-hold-time 2000
negotiation auto
port-queue be wfq weight 10 port-wred WRED_BE outbound
port-queue af1 wfq weight 20 outbound
port-queue af2 wfq weight 30 outbound
port-queue af3 wfq weight 40 outbound
port-queue af4 wfq weight 50 outbound
#
interface GigabitEthernet .
vlan-type dot1q
description AR_LIC0707_NEW - 10G
undo shutdown
mtu 9000
ip address 255.255.255.252
ospf network-type p2p
ospf ldp-sync
mpls
mpls te
mpls rsvp-te
mpls rsvp-te hello
mpls ldp
mpls ldp timer igp-sync-delay 25
trust upstream default
#
interface GigabitEthernet
description
undo shutdown
efm error-frame period 5
efm error-frame threshold 300
efm error-frame notification enable
undo dcn
carrier down-hold-time 100
carrier up-hold-time 2000
negotiation auto
port-queue be wfq weight 10 port-wred WRED_BE outbound
port-queue af1 wfq weight 20 outbound
port-queue af2 wfq weight 30 outbound
port-queue af3 wfq weight 40 outbound
port-queue af4 wfq weight 50 outbound
#
bgp 4.66
router-id 10.124.128.2
graceful-restart
graceful-restart timer restart 180
peer 10.122.12.130 as-number 4.66
peer 10.122.12.130 description AG_LIC671_2
peer 10.122.12.130 connect-interface LoopBack0
peer 10.122.12.131 as-number 4.66
peer 10.122.12.131 description AG_CAL010
peer 10.122.12.131 connect-interface LoopBack0
#
ipv4-family unicast
undo synchronization
auto-frr
network 10.124.128.2 255.255.255.255
peer 10.122.12.130 enable
peer 10.122.12.130 advertise-community
peer 10.122.12.131 enable
peer 10.122.12.131 advertise-community
commit
#
ipv4-family vpnv4
policy vpn-target
peer 10.122.12.130 enable
y
peer 10.122.12.130 advertise-community
peer 10.122.12.131 enable
y
peer 10.122.12.131 advertise-community
commit
#
ipv4-family vpn-instance 3G
import-route direct
import-route static
auto-frr
commit

ipv4-family vpn-instance 4G
import-route direct
import-route static
auto-frr
commit

ipv4-family vpn-instance NMS_ATN910B


import-route direct
commit
#
ospf 1 router-id 10.124.128.2
silent-interface LoopBack0
spf-schedule-interval intelligent-timer 200 50 50
lsa-originate-interval intelligent-timer 100 50 50
lsa-arrival-interval intelligent-timer 100 50 50
opaque-capability enable
enable traffic-adjustment advertise
enable log config
enable log state
enable log error
enable log snmp-trap
graceful-restart period 180
bandwidth-reference 100000
area 0.15.47.1
network 10.124.128.2 0.0.0.0
network 0.0.0.0
network 0.0.0.0
mpls-te enable
commit
#
ip ip-prefix IMPORT_NodeB index 10 permit 0.0 16 greater-equal 16 less-equal 32
ip ip-prefix IMPORT_NodeB index 20 permit 0.0 16 greater-equal 16 less-equal 32
ip ip-prefix IMPORT_4G index 10 permit 0.0 16 greater-equal 16 less-equal 32
#
route-policy 3G permit node 100
if-match ip-prefix IMPORT_NodeB
#
route-policy 4G permit node 100
if-match ip-prefix IMPORT_4G
commit
#
ntp-service server disable
ntp-service ipv6 server disable
ntp-service refclock-master
ntp-service unicast-server preference
ntp-service unicast-server
clock timezone UTC minus 5
commit
#
acl number 2000
description SNMP
rule 5 permit vpn-instance NMS_ATN910B source 10.121.3.1 0
rule 10 permit vpn-instance NMS_ATN910B source 10.121.3.32 0.0.0.7
rule 20 permit vpn-instance NMS_ATN910B source 10.121.6.136 0
rule 30 permit vpn-instance NMS_ATN910B source 10.121.62.34 0
rule 40 permit vpn-instance NMS_ATN910B source 10.121.62.99 0
rule 45 permit vpn-instance NMS_ATN910B source 10.121.62.42 0
rule 50 permit vpn-instance NMS_ATN910B source 10.121.62.0 0.0.0.255
rule 60 permit vpn-instance NMS_ATN910B source 10.121.3.0 0.0.0.255
#
acl number 3000
description Telnet
rule 25 permit ip vpn-instance NMS_ATN910B source 10.121.62.6 0
rule 35 permit ip vpn-instance NMS_ATN910B source 10.121.62.33 0
rule 40 permit ip vpn-instance NMS_ATN910B source 10.121.6.135 0
rule 45 permit ip vpn-instance NMS_ATN910B source 10.121.124.11 0
rule 50 permit ip vpn-instance NMS_ATN910B source 10.122.4.0 0.0.1.255
rule 60 permit ip vpn-instance NMS_ATN910B source 10.122.12.128 0.0.0.63
rule 70 permit ip vpn-instance NMS_ATN910B source 10.122.14.128 0.0.0.63
rule 80 permit ip vpn-instance NMS_ATN910B source 10.121.6.155 0
rule 85 permit ip vpn-instance NMS_ATN910B source 10.121.6.156 0
commit
#
#
stelnet server enable
ssh user root
ssh user root authentication-type password
ssh user root service-type stelnet
ssh authorization-type default aaa
#
snetconf server enable
ssh client first-time enable
ssh user u2000@ip
ssh user u2000@ip authentication-type password
ssh user u2000@ip service-type all
#
sftp client-source -i LoopBack1 
commit
#
snmp-agent
y
snmp-agent community complexity-check disable
snmp-agent sys-info contact VIETTEL_PERU
snmp-agent sys-info location VIETTEL_PERU
snmp-agent sys-info version all
snmp-agent target-host trap address udp-domain 10.121.3.1 source LoopBack1 params securityna
snmp-agent target-host trap address udp-domain 10.121.3.10 source LoopBack1 vpn-instance NM
snmp-agent target-host trap address udp-domain 10.121.3.10 params securityname cipher AR_LI
snmp-agent target-host trap address udp-domain 10.121.3.1 source LoopBack1 vpn-instance NMS
snmp-agent target-host trap address udp-domain 10.121.3.10 source LoopBack1 vpn-instance NM
snmp-agent mib-view included iso iso
snmp-agent mib-view included iso-new iso
snmp-agent mib-view included iso-view iso
snmp-agent mib-view excluded userinfo snmpUsmMIB
snmp-agent mib-view excluded userinfo snmpVacmMIB
snmp-agent mib-view excluded userinfo hwLocalUserTable
snmp-agent mib-view excluded userinfo hwCollectTable
snmp-agent mib-view excluded userinfo hwCfgOperateTable
snmp-agent trap source LoopBack1
snmp-agent community read cipher AR_LIC mib-view iso-view acl 2000
snmp-agent trap enable
y
commit
#
hwtacacs-server template viettel_peru
hwtacacs-server authentication 10.121.62.34 vpn-instance NMS_ATN910B
hwtacacs-server authorization 10.121.62.34 vpn-instance NMS_ATN910B
hwtacacs-server accounting 10.121.62.34 vpn-instance NMS_ATN910B
hwtacacs-server source-ip 10.126.128.2
hwtacacs-server shared-key acsmetrovtp
commit
#
aaa
authentication-scheme default0
authentication-mode hwtacacs local
#
authorization-scheme default
authorization-mode hwtacacs local
authorization-cmd 15 hwtacacs local
#
accounting-scheme default0
accounting-mode hwtacacs
accounting start-fail online
accounting interim-fail max-times 10 online
#
domain default_admin
authentication-scheme default0
authorization-scheme default
accounting-scheme default0
hwtacacs-server viettel_peru
#
recording-scheme 1
recording-mode hwtacacs viettel_peru
#
system recording-scheme 1
outbound recording-scheme 1
cmd recording-scheme 1
#
commit
#

interface GigabitEthernet0/2/2.1000
vlan-type dot1q 1000
description HUN0088_GI0/2/2
ip address 10.129.36.26 255.255.255.252
pim sm
ospf network-type p2p
ospf ldp-sync
mpls
mpls te
mpls rsvp-te
mpls rsvp-te hello
mpls ldp
mpls ldp timer igp-sync-delay 25
trust upstream default

interface GigabitEthernet0/2/4.1000
vlan-type dot1q 1000
description HUN0088_GI0/2/2
ip address 10.129.36.26 255.255.255.252
pim sm
ospf network-type p2p
ospf ldp-sync
mpls
mpls te
mpls rsvp-te
mpls rsvp-te hello
mpls ldp
mpls ldp timer igp-sync-delay 25
trust upstream default
TEMPLATE BGP AGG

AGG BGP

AGG MPLS
AGG MPLS
ess-equal 32
ess-equal 32
Back1 params securityname cipher AR_LIC v2c
pBack1 vpn-instance NMS_ATN910B params securityname cipher AR_LIC v2c
urityname cipher AR_LIC v2c
Back1 vpn-instance NMS_ATN910B params securityname cipher AR_LIC v2c
pBack1 vpn-instance NMS_ATN910B  params securityname cipher AR_LIC v2c
TEMPLATE BGP AGG
#
bgp 4.66
peer 10.124.128.2 as-number 4.66
peer 10.124.128.2 description AR_LIC0707_NEW
peer 10.124.128.2 connect-interface LoopBack0
#
ipv4-family unicast
peer 10.124.128.2 enable
peer 10.124.128.2 route-policy FILTER_FROM_SRT import
peer 10.124.128.2 route-policy FILTER_TO_SRT export
peer 10.124.128.2 reflect-client
peer 10.124.128.2 advertise-community
peer 10.124.128.2 default-route-advertise
#
ipv4-family vpnv4
peer 10.124.128.2 enable
peer 10.124.128.2 route-policy AGG_FROM_SRT_VPNV4 import
peer 10.124.128.2 route-policy AGG_TO_SRT_VPNV4 export
peer 10.124.128.2 reflect-client
peer 10.124.128.2 next-hop-local
peer 10.124.128.2 advertise-community
#
ipv4-family mdt
peer 10.124.128.2 enable
peer 10.124.128.2 route-policy AGG_TO_SRT_VPN_MDT export
peer 10.124.128.2 reflect-client
peer 10.124.128.2 advertise-community
#
ipv4-family vpn-target
peer 10.124.128.2 enable
peer 10.124.128.2 default-route-advertise

#
#
#
mpls ldp remote-peer ar_lic0707_new
remote-ip 10.124.128.2
commit
q
#
#
ecurityname cipher AR_LIC v2c
tance NMS_ATN910B params securityname cipher AR_LIC v2c
er AR_LIC v2c
ance NMS_ATN910B params securityname cipher AR_LIC v2c
tance NMS_ATN910B  params securityname cipher AR_LIC v2c
undo description
undo eth-trunk
shutdown
undo carrier up-hold-time
undo carrier down-hold-time
undo set flow-stat interval
undo efm enable
undo efm error-frame period
undo efm error-frame threshold
undo efm error-frame notification enable
undo port-queue be wfq outbound
undo port-queue af1 wfq outbound
undo port-queue af2 wfq outbound
undo port-queue af3 wfq outbound
undo port-queue af4 wfq outbound
undo port-queue be outbound
undo transmission-alarm holdoff to timer
undo transmission-alarm holdup to timer
undo transmission-alarm log lais lof los lrdi pais sdbere
undo transmission-alarm down lais lof los lrdi pais sdbere
transmission-alarm holdup-timer
undo transmission-alarm holdoff-timer
transmission-alarm down lais lof los
undo statistic enable
set transfer-mode lan
commit
vlan batch 34 portswitch
vlan batch 72 y
vlan batch 74 commit
vlan batch 76 port link-type trunk
vlan batch 79 to 82 port trunk allow-pass vlan 34
vlan batch 87 to 88 port trunk allow-pass vlan 72
vlan batch 93 port trunk allow-pass vlan 74
vlan batch 173 port trunk allow-pass vlan 76
vlan batch 406 port trunk allow-pass vlan 79 to 82
vlan batch 1951 port trunk allow-pass vlan 87 to 88
vlan batch 1960 port trunk allow-pass vlan 93
vlan batch 2000 port trunk allow-pass vlan 173
vlan batch 2002 port trunk allow-pass vlan 406
vlan batch 2005 to 2071 port trunk allow-pass vlan 1951
vlan batch 2204 port trunk allow-pass vlan 1960
vlan batch 2206 to 2270 port trunk allow-pass vlan 2000
vlan batch 3000 port trunk allow-pass vlan 2002
vlan batch 3494 port trunk allow-pass vlan 2005 to 2071
vlan batch 3600 port trunk allow-pass vlan 2204
vlan batch 3617 to 3618 port trunk allow-pass vlan 2206 to 2270
vlan batch 3718 port trunk allow-pass vlan 3000
vlan batch 3737 port trunk allow-pass vlan 3494
vlan batch 3748 port trunk allow-pass vlan 3600
vlan batch 3781 port trunk allow-pass vlan 3617 to 3618
vlan batch 3790 port trunk allow-pass vlan 3718
vlan batch 3984 port trunk allow-pass vlan 3737
vlan batch 3986 to 3987 port trunk allow-pass vlan 3748
vlan batch 3989 to 3995 port trunk allow-pass vlan 3781
vlan batch 3998 port trunk allow-pass vlan 3790
vlan batch 4000 to 4004 port trunk allow-pass vlan 3984
vlan batch 4011 port trunk allow-pass vlan 3986 to 3987

commit port trunk allow-pass vlan 4031


port trunk allow-pass vlan 4042
port trunk allow-pass vlan 4055
port trunk allow-pass vlan 4063
commit
INPUT INFORMATION
NAME AR_PIU0164_LAP_NEW
NMS VLAN 3906
IP NMS 10.122.188.10
GW 10.122.160.126
TEMPLATE ATN910C

NAME SYSTEM

NMS

CLOCK TIMER
ACL

STELNET / SNETCONFIG /
SFTP
SNMP

NMS

NMS
NMS

ACCESO A SERVIDOR DE
AUTENTICACION
TACACS
TEMPLATE ATN910C
#
sysname AR_PIU0164_LAP_NEW
undo __LOCAL_OAM_VPN__
undo dcn
commit
#

efm enable
#
#
vlan batch 3906
commit
#
interface Vlanif3906
ip address 10.122.188.10 255.255.255.224
ip route-static 0.0.0.0 0.0.0.0 10.122.160.126
commit
#
ntp-service server disable
ntp-service ipv6 server disable
ntp-service refclock-master
ntp-service unicast-server preference
ntp-service unicast-server
clock timezone UTC minus 5
commit
#
acl number 2000
description SNMP
rule 5 permit source 10.121.3.1 0
rule 10 permit source 10.121.3.32 0.0.0.7
rule 20 permit source 10.121.6.136 0
rule 30 permit source 10.121.62.34 0
rule 40 permit source 10.121.62.99 0
rule 45 permit source 10.121.62.42 0
rule 50 permit source 10.121.62.0 0.0.0.255
rule 60 permit source 10.121.3.0 0.0.0.255
rule 70 permit source 10.121.42.0 0.0.0.255
commit
#
acl number 3000
description Telnet
rule 25 permit ip source 10.121.62.6 0
rule 35 permit ip source 10.121.62.33 0
rule 40 permit ip source 10.121.6.135 0
rule 45 permit ip source 10.121.124.11 0
rule 50 permit ip source 10.122.4.0 0.0.1.255
rule 60 permit ip source 10.122.12.128 0.0.0.63
rule 70 permit ip source 10.122.14.128 0.0.0.63
rule 80 permit ip source 10.121.6.155 0
rule 85 permit ip source 10.121.6.156 0
commit
#
#
stelnet server enable
ssh user root
ssh user root authentication-type password
ssh user root service-type stelnet
ssh authorization-type default aaa
#
snetconf server enable
ssh client first-time enable
ssh user u2000@ip
ssh user u2000@ip authentication-type password
ssh user u2000@ip service-type all
#
sftp client-source -i Vlanif 3906
commit
#
snmp-agent
y
snmp-agent community complexity-check disable
snmp-agent sys-info contact VIETTEL_PERU
snmp-agent sys-info location VIETTEL_PERU
snmp-agent sys-info version all
snmp-agent target-host trap address udp-domain 10.121.3.1 source Vlanif 3906 params securityname
snmp-agent target-host trap address udp-domain 10.121.3.10 source Vlanif 3906 params securitynam
snmp-agent target-host trap address udp-domain 10.121.3.10 params securityname cipher AR_PIU v
snmp-agent target-host trap address udp-domain 10.121.3.1 source Vlanif 3906 params securitynam
snmp-agent target-host trap address udp-domain 10.121.3.10 source Vlanif 3906  params securityn
snmp-agent mib-view included iso iso
snmp-agent mib-view included iso-new iso
snmp-agent mib-view included iso-view iso
snmp-agent mib-view excluded userinfo snmpUsmMIB
snmp-agent mib-view excluded userinfo snmpVacmMIB
snmp-agent mib-view excluded userinfo hwLocalUserTable
snmp-agent mib-view excluded userinfo hwCollectTable
snmp-agent mib-view excluded userinfo hwCfgOperateTable
snmp-agent trap source Vlanif 3906
snmp-agent community read cipher AR_PIU mib-view iso-view acl 2000
snmp-agent trap enable
y
commit
#
#
interface GigabitEthernet0/2/27
portswitch
y
description NMS_AR_PIU0164_LAP_NEW
port link-type access
port default vlan 3906
undo dcn
commit
#
#
interface GigabitEthernet0/2/27
portswitch
y
description NMS_AR_PIU0164_LAP_NEW
port link-type trunk
port trunk allow-pass vlan 3906
undo dcn
commit
#
hwtacacs-server template viettel_peru
hwtacacs-server authentication 10.121.62.34
hwtacacs-server authorization 10.121.62.34
hwtacacs-server accounting 10.121.62.34
hwtacacs-server source-ip 10.122.188.10
hwtacacs-server shared-key acsmetrovtp
commit
#
aaa
authentication-scheme default0
authentication-mode hwtacacs local
#
authorization-scheme default
authorization-mode hwtacacs local
authorization-cmd 15 hwtacacs local
#
accounting-scheme default0
accounting-mode hwtacacs
accounting start-fail online
accounting interim-fail max-times 10 online
#
domain default_admin
authentication-scheme default0
authorization-scheme default
accounting-scheme default0
hwtacacs-server viettel_peru
#
recording-scheme 1
recording-mode hwtacacs viettel_peru
#
system recording-scheme 1
outbound recording-scheme 1
cmd recording-scheme 1
#
commit
#
interface Eth-Trunk11
portswitch
port link-type trunk
port trunk allow-pass vlan 100
description AG_LAM0011
trust upstream default
set flow-stat interval 10
trust upstream default
mode lacp-static
load-balance packet-all
lacp timeout fast
commit

interface Eth-Trunk12
portswitch
port link-type trunk
port trunk allow-pass vlan 100
description AG_PIU0088
set flow-stat interval 10
trust upstream default
mode lacp-static
load-balance packet-all
lacp timeout fast
commit
arams securityname cipher AR_PIU v2c
params securityname cipher AR_PIU v2c
e cipher AR_PIU v2c
params securityname cipher AR_PIU v2c
 params securityname cipher AR_PIU v2c
interface GigabitEthernet0/2/0
undo shutdown
eth-trunk 11
undo dcn
commit
q

interface GigabitEthernet0/2/1
undo shutdown
eth-trunk 11
undo dcn
commit
q

interface GigabitEthernet0/2/2
undo shutdown
eth-trunk 12
undo dcn
commit
q

interface GigabitEthernet0/2/3
undo shutdown
eth-trunk 12
undo dcn
commit
q

You might also like