Table Of Contents
Services Layer Switch—Catalyst 6500
Services Block Switch - Catalyst 6500
Access Layer Switch—Catalyst 4500
Remote-Access Termination ASA 5520
SAFE 1.0 Release Notes
Created: August 20, 2009, OLThis Release Notes provides a list of all platforms and software releases that were validated for the SAFE reference architecture. There are also network diagrams for each module and complete configuration for each platform.
This Release Notes document is associated with the Cisco SAFE Reference Guide available at the following URL:
http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/SAFE_RG/SAFE_rg.htm
The Cisco SAFE consists of design blueprints based on the Cisco Validated Designs (CVDs) and proven security best practices that provide the design guidelines for building secure and reliable network infrastructures. The design blueprint follows a modular design where the overall network infrastructure is divided into functional modules, each one representing a place-in-the network (PIN). Functional modules are then subdivided into more manageable and granular functional blocks, each serving a specific role in the network.
Contents
Cisco Platforms and Versions
This section lists the Cisco platforms and releases used for SAFE 1.0 reference architecture.
Enterprise Core
Role Platforms Version Core SwitchCatalyst 6500 Series
VS-S720-10G
WS-X6716-10GE
WS-X6148A-GE-TX
12.2(33)SXH4
Intranet Data Center
Enterprise Campus
Enterprise Internet Edge
Enterprise WAN Edge
Role Platforms Version Unified WAN PlatformASR1004
2.3.0 12.2(33)XNC
Intrusion Prevention SystemIPS 4270
6.1(2)E3
SwitchCatalyst 3750
12.2(35)SE5
Enterprise Branch
Management
Role Platforms Version AAA ServerCS-ACS
4.1.4
Security ManagerCSM
3.2.2 SP1
Monitoring, Analysis, and CorrelationCS-MARS
6.0.2
FirewallASA 5540
8.0(3)
SAFE Configurations
This section contains a network diagram for each module that was tested in the lab and a copy of the complete configuration for each platform validated in the SAFE system testing (only for platforms with command-line (CLI) configurations; does not include GUI configurations). Note that externally accessible IP addresses and passwords have been replaced with descriptive text.
Enterprise Core
Figure 1 Enterprise Core Network Diagram
Core Switch—Catalyst 6500
sfx14-6504e-1!! Last configuration change at 16:05:10 GMT Mon Apr 13 2009 by mapuebla-ops! NVRAM config last updated at <tacacs+ server>16:08:04 GMT Mon Apr 13 2009 by mapuebla-ops!upgrade fpd auto<CS-MARS>version 12.2no service padservice tcp-keepalives-inservice timestamps debug datetime msec localtime show-timezoneservice timestamps log datetime msec localtime show-timezoneservice password-encryptionservice counters max age 5!hostname SFX14-6504E-1!boot-start-markerboot system flash sup-bootdisk:/s72033-advipservicesk9_wan-mz.122-33.SXH4.binboot-end-marker!logging rate-limit 10no logging consoleenable secret 5 <encrypted password>!username admin privilege 15 secret 5 <encrypted password>username csmars privilege 15 secret 5 <encrypted password>aaa new-modelaaa group server tacacs+ tacacs-groupserver <tacacs+ server>!aaa authentication login authen-exec-list group tacacs-group local-caseaaa authentication enable default group tacacs-group enableaaa authorization exec author-exec-list group tacacs-group if-authenticatedaaa authorization commands 15 author-15-list group tacacs-group noneaaa accounting send stop-record authentication failureaaa accounting exec default start-stop group tacacs-groupaaa accounting commands 15 default start-stop group tacacs-groupaaa accounting system default start-stop group tacacs-group!aaa session-id commonclock timezone GMT 0call-homealert-group configurationalert-group diagnosticalert-group environmentalert-group inventoryalert-group syslogprofile "CiscoTAC-1"no activeno destination transport-method httpdestination transport-method emaildestination address email callhome@cisco.comdestination address http https://tools.cisco.com/its/service/oddce/services/DDCEServicesubscribe-to-alert-group diagnostic severity minorsubscribe-to-alert-group environment severity minorsubscribe-to-alert-group syslog severity major pattern ".*"subscribe-to-alert-group configuration periodic monthly 3 11:25subscribe-to-alert-group inventory periodic monthly 3 11:10ip subnet-zerono ip source-route!!!ip ftp source-interface GigabitEthernet1/3ip ftp username adminip ftp password 7 <encrypted password>no ip bootp serverip ssh time-out 60ip ssh authentication-retries 2ip scp server enableno ip domain-lookupip domain-name cisco.comlogin block-for 100 attempts 5 within 50login quiet-mode access-class 10login on-failure logmls ip slb purge globalmls netflow interfaceno mls flow ipno mls flow ipv6mls qosmls cef error action reset!key chain eigrp-chainkey 10key-string 7 <key>!!!!!!!!!memory reserve critical 1000memory free low-watermark processor 91490memory free low-watermark IO 6710no hw-module slot 3 oversubscription port-group 1!redundancykeepalive-enablemode ssomain-cpuauto-sync running-configspanning-tree mode pvstspanning-tree extend system-iddiagnostic cns publish cisco.cns.device.diag_resultsdiagnostic cns subscribe cisco.cns.device.diag_commands!power redundancy-mode combinedfabric timer 15!vlan internal allocation policy ascendingvlan access-log ratelimit 2000!class-map match-all coppclass-igpmatch access-group name coppacl-igpclass-map match-all coppclass-monitoringmatch access-group name coppacl-monitoringclass-map match-all coppclass-filemanagementmatch access-group name coppacl-filemanagementclass-map match-all coppclass-managementmatch access-group name coppacl-management!!policy-map copp-policyclass coppclass-igppolice cir 300000 bc 3000 be 3000 conform-action transmit exceed-action drop violate-action dropclass coppclass-filemanagementpolice cir 6000000 bc 60000 be 60000 conform-action transmit exceed-action drop violate-action dropclass coppclass-managementpolice cir 500000 bc 5000 be 5000 conform-action transmit exceed-action drop violate-action dropclass coppclass-monitoringpolice cir 900000 bc 9000 be 9000 conform-action transmit exceed-action drop violate-action dropclass class-defaultpolice cir 500000 bc 5000 be 5000 conform-action transmit exceed-action drop violate-action drop!!!!!!interface Loopback0ip address 10.242.10.36 255.255.255.254!interface GigabitEthernet1/1description WAN Edge he4-3750-1 Gig 1/0/50ip address 10.242.10.2 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet1/2description WAN Edge he4-3750-2 Gig 1/0/50ip address 10.242.10.4 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet1/3description FLASH NETip address <management IP add> 255.255.254.0ip access-group 133 inip access-group 134 outload-interval 60!interface TenGigabitEthernet1/4description DATA CENTERip address 10.242.10.24 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface TenGigabitEthernet1/5no ip addressshutdown!interface TenGigabitEthernet3/1no ip addressshutdownno rcv-queue random-detect 1!interface TenGigabitEthernet3/2no ip addressshutdown!interface TenGigabitEthernet3/3no ip addressshutdown!interface TenGigabitEthernet3/4no ip addressshutdown!interface TenGigabitEthernet3/5no ip addressshutdown!interface TenGigabitEthernet3/6no ip addressshutdown!interface TenGigabitEthernet3/7no ip addressshutdown!interface TenGigabitEthernet3/8no ip addressshutdown!interface TenGigabitEthernet3/9no ip addressshutdown!interface TenGigabitEthernet3/10no ip addressshutdown!interface TenGigabitEthernet3/11no ip addressshutdown!interface TenGigabitEthernet3/12no ip addressshutdown!interface TenGigabitEthernet3/13no ip addressshutdown!interface TenGigabitEthernet3/14no ip addressshutdown!interface TenGigabitEthernet3/15no ip addressshutdown!interface TenGigabitEthernet3/16no ip addressshutdown!interface GigabitEthernet4/1description Internet Edge IE-6500-3 g2/26ip address 10.242.10.10 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet4/2ip address 10.242.10.12 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet4/3description OOB Switch Fe0/23ip address 10.242.10.18 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet4/4no ip addressshutdown!interface GigabitEthernet4/5no ip addressshutdown!interface GigabitEthernet4/6no ip addressshutdown!interface GigabitEthernet4/7no ip addressshutdown!interface GigabitEthernet4/8no ip addressshutdown!interface GigabitEthernet4/9no ip addressshutdown!interface GigabitEthernet4/10no ip addressshutdown!interface GigabitEthernet4/11no ip addressshutdown!interface GigabitEthernet4/12no ip addressshutdown!interface GigabitEthernet4/13no ip addressshutdown!interface GigabitEthernet4/14no ip addressshutdown!interface GigabitEthernet4/15no ip addressshutdown!interface GigabitEthernet4/16no ip addressshutdown!interface GigabitEthernet4/17no ip addressshutdown!interface GigabitEthernet4/18no ip addressshutdown!interface GigabitEthernet4/19no ip addressshutdown!interface GigabitEthernet4/20no ip addressshutdown!interface GigabitEthernet4/21no ip addressshutdown!interface GigabitEthernet4/22no ip addressshutdown!interface GigabitEthernet4/23no ip addressshutdown!interface GigabitEthernet4/24no ip addressshutdown!interface GigabitEthernet4/25no ip addressshutdown!interface GigabitEthernet4/26no ip addressshutdown!interface GigabitEthernet4/27no ip addressshutdown!interface GigabitEthernet4/28no ip addressshutdown!interface GigabitEthernet4/29no ip addressshutdown!interface GigabitEthernet4/30no ip addressshutdown!interface GigabitEthernet4/31no ip addressshutdown!interface GigabitEthernet4/32no ip addressshutdown!interface GigabitEthernet4/33no ip addressshutdown!interface GigabitEthernet4/34no ip addressshutdown!interface GigabitEthernet4/35ip address 10.242.150.1 255.255.255.0!interface GigabitEthernet4/36no ip addressshutdown!interface GigabitEthernet4/37no ip addressshutdown!interface GigabitEthernet4/38no ip addressshutdown!interface GigabitEthernet4/39no ip addressshutdown!interface GigabitEthernet4/40no ip addressshutdown!interface GigabitEthernet4/41no ip addressshutdown!interface GigabitEthernet4/42no ip addressshutdown!interface GigabitEthernet4/43no ip addressshutdown!interface GigabitEthernet4/44no ip addressshutdown!interface GigabitEthernet4/45no ip addressshutdown!interface GigabitEthernet4/46description CAMPUS SFX13-6504E-2 Gig 4/46ip address 10.242.10.32 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet4/47description CAMPUS SFX13-6504E-1 Gig 4/47ip address 10.242.10.28 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet4/48description SFX14-6504E-2 Gig 4/48ip address 10.242.10.22 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface Vlan1no ip addressshutdown!router eigrp 1network 10.0.0.0auto-summary!ip classlessip route 172.26.0.0 255.255.0.0 172.26.170.1!!no ip http serverno ip http secure-serverip tacacs source-interface GigabitEthernet1/3!ip access-list extended coppacl-filemanagementremark CoPP File transfer traffic classpermit tcp 172.26.0.0 0.0.255.255 eq ftp host <management IP add> gt 1023 establishedpermit tcp 172.26.0.0 0.0.255.255 eq ftp-data host <management IP add> gt 1023permit tcp 172.26.0.0 0.0.255.255 gt 1023 host <management IP add> gt 1023 establishedpermit udp 172.26.0.0 0.0.255.255 gt 1023 host <management IP add> gt 1023ip access-list extended coppacl-igpremark IGP traffic classpermit eigrp any host 224.0.0.10permit eigrp 10.0.0.0 0.255.255.255 host <management IP add>ip access-list extended coppacl-managementremark CoPP management traffic classpermit tcp 172.26.0.0 0.0.255.255 eq tacacs host <management IP add> establishedpermit tcp 172.26.0.0 0.0.255.255 host <management IP add> eq 22permit tcp 172.26.0.0 0.0.255.255 host <management IP add> eq telnetpermit udp 172.26.0.0 0.0.255.255 host <management IP add> eq snmppermit udp 172.26.0.0 0.0.255.255 host <management IP add> eq ntppermit udp 10.0.0.0 0.255.255.255 host 10.242.10.36 eq ntpip access-list extended coppacl-monitoringremark C<tacacs+ server>oPP monitoring traffic classpermit icmp any any ttl-exceededpermit icmp any any port-unreachablepermit icmp any any echo-replypermit icmp any any echo!logging trap criticallogging source-interface GigabitEthernet1/3logging <CS-MARS>access-list 10 permit 172.26.191.92access-list 20 permit <ntp peer>access-list 20 remark ACL for NTP Servers and Peersaccess-list 20 permit <ntp server>access-list 21 remark ACL for NTP Clientaccess-list 21 permit 10.0.0.0 0.255.255.255access-list 21 permit 172.0.0.0 0.255.255.255access-list 21 deny any logaccess-list 111 remark ACL for SSHaccess-list 111 permit tcp 172.26.0.0 0.0.255.255 any eq 22access-list 111 deny ip any any log-inputaccess-list 112 remark ACL for last resort accessaccess-list 112 permit tcp host 172.26.191.92 any eq 22access-list 112 deny ip any any log-inputaccess-list 133 permit icmp 172.26.0.0 0.0.255.255 host <management IP add> ttl-exceededaccess-list 133 permit icmp 172.26.0.0 0.0.255.255 host <management IP add> port-unreachableaccess-list 133 permit icmp 172.26.0.0 0.0.255.255 host <management IP add> echo-replyaccess-list 133 permit icmp 172.26.0.0 0.0.255.255 host <management IP add> echoaccess-list 133 permit tcp 172.26.0.0 0.0.255.255 eq tacacs host <management IP add> establishedaccess-list 133 permit tcp 172.26.0.0 0.0.255.255 host <management IP add> eq tacacsaccess-list 133 permit udp 172.26.0.0 0.0.255.255 host <management IP add> eq ntpaccess-list 133 permit tcp 172.26.0.0 0.0.255.255 host <management IP add> eq 22access-list 133 permit tcp 172.26.0.0 0.0.255.255 eq ftp host <management IP add> gt 1023 establishedaccess-list 133 permit tcp 172.26.0.0 0.0.255.255 eq ftp-data host <management IP add> gt 1023access-list 133 permit tcp 172.26.0.0 0.0.255.255 gt 1023 host <management IP add> gt 1023 establishedaccess-list 133 permit udp 172.26.0.0 0.0.255.255 gt 1023 host <management IP add> gt 1023access-list 133 permit ip any any logaccess-list 134 permit ip host <management IP add> 172.26.0.0 0.0.255.255access-list 134 deny ip any <tacacs+ server>any logaccess-list 155 permit ip any any log!snmp-server enable traps cpu thresholdsnmp-server host <CS-MARS> csmars cputacacs-server host <tacacs+ server> single-connection key 7 <key>no tacacs-server directed-request!radius-server source-ports 1645-1646!control-planeservice-policy input copp-policy!!dial-peer cor custom!!!banner loginUNAUTHORIZED ACCESS TO THIS DEVICE IS PROHIBITEDYou must have explicit, authorized permission to access or configure this device.Unauthorized attempts and actions to access or use this system may result in civil and/or criminal penalties.All activities performed on this device are logged and monitored.!line con 0session-timeout 3exec-timeout 3 0login authentication authen-exec-listline vty 0 3session-timeout 3access-class 111 inexec-timeout 3 0password 7 <encrypted password>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listtransport preferred nonetransport input telnet sshtransport output noneline vty 4session-timeout 3access-class 112 inexec-timeout 3 0password 7 <encrypted password>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listtransport preferred nonetransport input sshtransport output noneline vty 5 15no exec!exception protocol ftpexception dump <ftp-server>process cpu threshold type total rising 80 interval 5 falling 20 interval 5process cpu statistics limit entry-percentage 40 size 300ntp authentication-key 10 md5 <encrypted password> 7ntp authenticatentp trusted-key 10ntp clock-period 17180041ntp access-group peer 20ntp access-group serve-only 21ntp update-calendarntp peer <ntp peer>ntp server <ntp server>no event manager policy Mandatory.go_switchbus.tcl type system!endsfx14-6504e-2!! Last configuration change at 16:05:13 GMT Mon Apr 13 2009 by mapuebla-ops! NVRAM config last updated at 16:08:03 GMT Mon Apr 13 2009 by mapuebla-ops!upgrade fpd auto<management IP add>version 12.2no service padservice tcp-keepalives-inservice timestamps debug datetime msec localtime show-timezoneservice timestamps log datetime msec localtime show-timezoneservice password-encryptionservice counters max age 5!hostname SFX14-6504E-2!boot-start-markerboot system flash bootflash:s72033-advipservicesk9_wan-mz.122-33.SXH4.binboot-end-marker!no logging consoleenable secret 5 <encrypted password>!username admin privilege 15 secret 5 <encrypted password>username csmars privilege 15 secret 5 <encrypted password>aaa new-modelaaa group server tacacs+ tacacs-groupserver <tacacs+ server>!aaa authentication login authen-exec-list group tacacs-group local-caseaaa authentication enable default group tacacs-group enableaaa authorization exec author-exec-list group tacacs-group if-authenticatedaaa authorization commands 15 author-15-list group tacacs-group noneaaa accounting send stop-record authentication failureaaa accounting exec default start-stop group tacacs-groupaaa accounting commands 15 default start-stop group tacacs-groupaaa accounting system default start-stop group tacacs-group!aaa session-id commonclock timezone GMT 0call-homealert-group configurationalert-group diagnosticalert-group environmentalert-group inventoryalert-group syslogprofile "CiscoTAC-1"no activeno destination transport-method httpdestination transport-method emaildestination address email callhome@cisco.comdestination address http https://tools.cisco.com/its/service/oddce/services/DDCEServicesubscribe-to-alert-group diagnostic severity minorsubscribe-to-alert-group environment severity minorsubscribe-to-alert-group syslog severity major pattern ".*"subscribe-to-alert-group configuration periodic monthly 3 15:57subscribe-to-alert-group inventory periodic monthly 3 15:42ip subnet-zerono ip source-route!!!ip ftp source-interface GigabitEthernet4/4ip ftp username adminip ftp password 7 <encrypted password>no ip bootp serverip ssh time-out 60ip ssh authentication-retries 2ip scp server enableip domain-name cisco.comlogin block-for 100 attempts 5 within 50login quiet-mode access-class 10login on-failure logmls ip slb purge globalmls netflow interfaceno mls flow ipno mls flow ipv6mls qosmls cef error action reset!key chain eigrp-chainkey 10key-string 7 <key>!!!!!!!!!memory reserve critical 1000memory free low-watermark processor 91490memory free low-watermark IO 6710!redundancykeepalive-enablemode ssomain-cpuauto-sync running-configspanning-tree mode pvstspanning-tree extend system-iddiagnostic cns publish cisco.cns.device.diag_resultsdiagnostic cns subscribe cisco.cns.device.diag_commandsfabric timer 15!vlan internal allocation policy ascendingvlan access-log ratelimit 2000!class-map match-all coppclass-igpmatch access-group name coppacl-igpclass-map match-all coppclass-monitoringmatch access-group name coppacl-monitoringclass-map match-all coppclass-filemanagementmatch access-group name coppacl-filemanagementclass-map match-all coppclass-managementmatch access-group name coppacl-management!!policy-map copp-policyclass coppclass-igppolice cir 300000 bc 3000 be 3000 conform-action transmit exceed-action drop violate-action dropclass coppclass-filemanagementpolice cir 6000000 bc 60000 be 60000 conform-action transmit exceed-action drop violate-action dropclass coppclass-managementpolice cir 500000 bc 5000 be 5000 conform-action transmit exceed-action drop violate-action dropclass coppclass-monitoringpolice cir 900000 bc 9000 be 9000 conform-action transmit exceed-action drop violate-action dropclass class-defaultpolice cir 500000 bc 5000 be 5000 conform-action transmit exceed-action drop violate-action drop!!!!!!interface Loopback0ip address 10.242.10.38 255.255.255.254!interface GigabitEthernet1/1description Wan Edge he4-3750-1 Gig1/0/52ip address 10.242.10.6 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet1/2description Wan Edge he4-3750-2 Gig1/0/52ip address 10.242.10.8 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet1/3no ip addressshutdown!interface TenGigabitEthernet1/4ip address 10.242.10.26 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface TenGigabitEthernet1/5no ip addressshutdown!interface TenGigabitEthernet3/1no ip addressshutdown!interface TenGigabitEthernet3/2no ip addressshutdown!interface TenGigabitEthernet3/3no ip addressshutdown!interface TenGigabitEthernet3/4no ip addressshutdown!interface TenGigabitEthernet3/5no ip addressshutdown!interface TenGigabitEthernet3/6no ip addressshutdown!interface TenGigabitEthernet3/7no ip addressshutdown!interface TenGigabitEthernet3/8no ip addressshutdown!interface TenGigabitEthernet3/9no ip addressshutdown!interface TenGigabitEthernet3/10no ip addressshutdown!interface TenGigabitEthernet3/11no ip addressshutdown!interface TenGigabitEthernet3/12no ip addressshutdown!interface TenGigabitEthernet3/13no ip addressshutdown!interface TenGigabitEthernet3/14no ip addressshutdown!interface TenGigabitEthernet3/15no ip addressshutdown!interface TenGigabitEthernet3/16no ip addressshutdown!interface GigabitEthernet4/1description Internet Edge IE-6500-4ip address 10.242.10.14 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet4/2ip address 10.242.10.16 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet4/3description OOB Switch Fe0/24ip address 10.242.10.20 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet4/4description FLASH NETip address <management IP add> 255.255.254.0ip access-group 133 inip access-group 134 outload-interval 60!interface GigabitEthernet4/5no ip addressshutdown!interface GigabitEthernet4/6no ip addressshutdown!interface GigabitEthernet4/7no ip addressshutdown!interface GigabitEthernet4/8no ip addressshutdown!interface GigabitEthernet4/9no ip addressshutdown!interface GigabitEthernet4/10no ip addressshutdown!interface GigabitEthernet4/11no ip addressshutdown!interface GigabitEthernet4/12no ip addressshutdown!interface GigabitEthernet4/13no ip addressshutdown!interface GigabitEthernet4/14no ip addressshutdown!interface GigabitEthernet4/15no ip addressshutdown!interface GigabitEthernet4/16no ip addressshutdown!interface GigabitEthernet4/17no ip addressshutdown!interface GigabitEthernet4/18no ip addressshutdown!interface GigabitEthernet4/19no ip addressshutdown!interface GigabitEthernet4/20no ip addressshutdown!interface GigabitEthernet4/21no ip addressshutdown!interface GigabitEthernet4/22no ip addressshutdown!interface GigabitEthernet4/23no ip addressshutdown!interface GigabitEthernet4/24no ip addressshutdown!interface GigabitEthernet4/25no ip addressshutdown!interface GigabitEthernet4/26no ip addressshutdown!interface GigabitEthernet4/27no ip addressshutdown!interface GigabitEthernet4/28no ip addressshutdown!interface GigabitEthernet4/29no ip addressshutdown!interface GigabitEthernet4/30no ip addressshutdown!interface GigabitEthernet4/31no ip addressshutdown!interface GigabitEthernet4/32no ip addressshutdown!interface GigabitEthernet4/33no ip addressshutdown!interface GigabitEthernet4/34no ip addressshutdown!interface GigabitEthernet4/35no ip addressshutdown!interface GigabitEthernet4/36no ip addressshutdown!interface GigabitEthernet4/37no ip addressshutdown!interface GigabitEthernet4/38no ip addressshutdown!interface GigabitEthernet4/39no ip addressshutdown!interface GigabitEthernet4/40no ip addressshutdown!interface GigabitEthernet4/41no ip addressshutdown!interface GigabitEthernet4/42no ip addressshutdown!interface GigabitEthernet4/43no ip addressshutdown!interface GigabitEthernet4/44no ip addressshutdown!interface GigabitEthernet4/45no ip addressshutdown!interface GigabitEthernet4/46description CAMPUS SFX13-6504E-1 Gig 4/46ip address 10.242.10.30 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet4/47description CAMPUS SFX13-6504E-2 Gig 4/47ip address 10.242.10.34 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface GigabitEthernet4/48description SFX14-6504E-1 Gig 4/48ip address 10.242.10.23 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface Vlan1no ip addressshutdown!router eigrp 1network 10.0.0.0auto-summary!ip classlessip route 172.26.0.0 255.255.0.0 172.26.170.1!!no ip http serverno ip http secure-serverip tacacs source-interface GigabitEthernet4/4!ip access-list extended coppacl-filemanagementremark CoPP File transfer traffic classpermit tcp 172.26.0.0 0.0.255.255 eq ftp host <management IP add> gt 1023 establishedpermit tcp 172.26.0.0 0.0.255.255 eq ftp-data host <management IP add> gt 1023permit tcp 172.26.0.0 0.0.255.255 gt 1023 host <management IP add> gt 1023 establishedpermit udp 172.26.0.0 0.0.255.255 gt 1023 host <management IP add> gt 1023ip access-list extended coppacl-igpremark IGP traffic classpermit eigrp any host 224.0.0.10permit eigrp 10.0.0.0 0.255.255.255 host <management IP add>ip access-list extended coppacl-managementremark CoPP management traffic classpermit tcp 172.26.0.0 0.0.255.255 eq tacacs host <management IP add> establishedpermit tcp 172.26.0.0 0.0.255.255 host <management IP add> eq 22permit tcp 172.26.0.0 0.0.255.255 host <management IP add> eq telnetpermit udp 172.26.0.0 0.0.255.255 host <management IP add> eq snmppermit udp 172.26.0.0 0.0.255.255 host <management IP add> eq ntppermit udp 10.0.0.0 0.255.255.255 host 10.242.10.38 eq ntpip access-list extended coppacl-monitoringremark CoPP monitoring traffic classpermit icmp any any ttl-exceededpermit icmp any any port-unreachablepermit icmp any any echo-replypermit icmp any any echo!logging trap criticallogging source-interface GigabitEthernet4/4<tacacs+ server>logging <CS-MARS>access-list 10 permit 172.26.191.92access-list 20 permit <ntp peer>access-list 20 remark ACL for NTP Servers and Peersaccess-list 20 permit <ntp server>access-list 21 remark ACL for NTP Clientaccess-list 21 permit 10.0.0.0 0.255.255.255access-list 21 permit 172.0.0.0 0.255.255.255access-list 21 deny any logaccess-list 111 remark ACL for SSHaccess-list 111 permit tcp 172.26.0.0 0.0.255.255 any eq 22access-list 111 deny ip any any log-inputaccess-list 112 remark ACL for last resort accessaccess-list 112 permit tcp host 172.26.191.92 any eq 22access-list 112 deny ip any any log-inputaccess-list 133 permit icmp 172.26.0.0 0.0.255.255 host <management IP add> ttl-exceededaccess-list 133 permit icmp 172.26.0.0 0.0.255.255 host <management IP add> port-unreachableaccess-list 133 permit icmp 172.26.0.0 0.0.255.255 host <management IP add> echo-replyaccess-list 133 permit icmp 172.26.0.0 0.0.255.255 host <management IP add> echoaccess-list 133 permit tcp 172.26.0.0 0.0.255.255 eq tacacs host <management IP add> establishedaccess-list 133 permit tcp 172.26.0.0 0.0.255.255 host <management IP add> eq tacacsaccess-list 133 permit udp 172.26.0.0 0.0.255.255 host <management IP add> eq ntpaccess-list 133 permit tcp 172.26.0.0 0.0.255.255 host <management IP add> eq 22access-list 133 permit tcp 172.26.0.0 0.0.255.255 eq ftp host <management IP add> gt 1023 establishedaccess-list 133 permit tcp 172.26.0.0 0.0.255.255 eq ftp-data host <management IP add> gt 1023access-list 133 permit tcp 172.26.0.0 0.0.255.255 gt 1023 host <management IP add> gt 1023 establishedaccess-list 133 permit udp 172.26.0.0 0.0.255.255 gt 1023 host <management IP add> gt 1023access-list 133 permit ip any any logaccess-list 134 permit ip host <management IP add><CS-MARS> 172.26.0.0 0.0.255.255access-list 134 deny ip any any log!snmp-server enable traps cpu threshold<tacacs+ server>snmp-server host <CS-MARS> csmars cputacacs-server host <tacacs+ server> single-connection key 7 <key>tacacs-server directed-request!radius-server source-ports 1645-1646!control-planeservice-policy input copp-policy!!dial-peer cor custom!!!banner loginUNAUTHORIZED ACCESS TO THIS DEVICE IS PROHIBITEDYou must have explicit, authorized permission to access or configure this device.Unauthorized attempts and actions to access or use this system may result in civil and/or criminal penalties.All activities performed on this device are logged and monitored.!line con 0session-timeout 3exec-timeout 3 0login authentication authen-exec-listline vty 0 3session-timeout 3access-class 111 inexec-timeout 3 0password 7 <encrypted password><tacacs+ server>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listtransport preferred nonetransport input sshtransport output noneline vty 4session-timeout 3access-class 112 inexec-timeout 3 0password 7 <encrypted password>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listtransport preferred nonetransport input sshtransport output noneline vty 5 15no exectransport input lat pad udptn telnet rlogin!exception protocol ftpexception dump <ftp-server>process cpu threshold type total rising 80 interval 5 falling 20 interval 5process cpu statistics limit entry-percentage 40 size 300ntp authentication-key 10 md5 <encrypted password> 7ntp authenticatentp trusted-key 10ntp clock-period 17179940ntp access-group peer 20ntp access-group serve-only 21ntp update-calendarntp peer <ntp peer>ntp server <ntp server>!endIntranet Data Center
Figure 2 Intranet Data Center Network Diagram
Figure 3 Intranet Data Center Security Service Traffic Flow Diagram
Core Switch—Catalyst 6500
DCA-core1dca-core1#sh runBuilding configuration....May 14 21:15:44.150 EST: %SEC-6-IPACCESSLOGP: list 133 denied udp x.26.146.86(138) -> x.26.147.255(138), 1 packetCurrent configuration : 16685 bytes!! Last configuration change at 19:50:45 EST Mon Mar 23 2009 by chris! NVRAM config last updated at 00:05:54 EST Thu May 14 2009!upgrade fpd autoversion 12.2no service padservice tcp-keepalives-inservice timestamps debug datetime msec localtime show-timezoneservice timestamps log datetime msec localtime show-timezoneservice password-encryptionservice counters max age 5!hostname dca-core1!boot-start-markerboot system disk0:s72033-ipservicesk9-mz.122-33.SXH2a.binboot-end-marker!enable secret 5 <encrypted password>.!username admin privilege 15 password <encrypted password>username dma password <encrypted password>username chris password <encrypted password>username csmars privilege 15 secret 5 <encrypted password>aaa new-modelaaa group server tacacs+ tacacs-groupserver x.26.191.94!aaa authentication login authen-exec-list group tacacs-group local-caseaaa authentication enable default group tacacs-group enableaaa authorization exec author-exec-list group tacacs-group if-authenticatedaaa authorization commands 15 author-15-list group tacacs-group noneaaa accounting send stop-record authentication failureaaa accounting exec default start-stop group tacacs-groupaaa accounting commands 15 default start-stop group tacacs-groupaaa accounting system default start-stop group tacacs-group!aaa session-id commonclock timezone GMT 0clock summer-time EST recurringcall-homealert-group configurationalert-group diagnosticalert-group environmentalert-group inventoryalert-group syslogprofile "CiscoTAC-1"no activeno destination transport-method httpdestination transport-method emaildestination address email callhome@cisco.comdestination address http https://tools.cisco.com/its/service/oddce/services/DDCEServicesubscribe-to-alert-group diagnostic severity minorsubscribe-to-alert-group environment severity minorsubscribe-to-alert-group syslog severity major pattern ".*"subscribe-to-alert-group configuration periodic monthly 9 9:39subscribe-to-alert-group inventory periodic monthly 9 9:24ip subnet-zerono ip source-route!!!ip ftp source-interface GigabitEthernet6/3ip ftp username dma1ip ftp password <encrypted password>no ip bootp serverip multicast-routingip ssh authentication-retries 2ip ssh version 2ip scp server enableip domain-name cisco.comlogin block-for 100 attempts 5 within 50login quiet-mode access-class 10login on-failure logudld enablevtp domain datacentervtp mode transparent!switch virtual domain 100!mls ip cef load-sharing full simplemls netflow interfacemls flow ip interface-fullmls nde sender version 5mls sampling packet-based 128 16000mls qosmls cef error action reset!flow-sampler-map csmars-samplemode random one-out-of 100!key chain eigrpkey 7key-string 7 05080F1C2243key chain eigrp-chainkey 10key-string 7 121A0C0411045D5679!!!!!!!!!archivepath ftp://chrobrie:J0eyD0gg2@x.26.129.252/VSSarchives/$h-$twrite-memorymemory reserve critical 1000memory free low-watermark processor 91492memory free low-watermark IO 6710!redundancykeepalive-enablemode ssomain-cpuauto-sync running-config!spanning-tree mode rapid-pvstspanning-tree extend system-iddiagnostic cns publish cisco.cns.device.diag_resultsdiagnostic cns subscribe cisco.cns.device.diag_commandsfabric switching-mode allow truncated threshold 1fabric switching-mode allow truncatedport-channel hash-distribution adaptiveport-channel load-balance src-dst-mixed-ip-port!vlan internal allocation policy ascendingvlan access-log ratelimit 2000!class-map match-all coppclass-igpmatch access-group name coppacl-igpclass-map match-all coppclass-monitoringmatch access-group name coppacl-monitoringclass-map match-all coppclass-filemanagementmatch access-group name coppacl-filemanagementclass-map match-all coppclass-managementmatch access-group name coppacl-management!!policy-map copp-policyclass coppclass-igppolice cir 300000 bc 3000 be 3000 conform-action transmit exceed-action drop violate-action dropclass coppclass-filemanagementpolice cir 6000000 bc 60000 be 60000 conform-action transmit exceed-action drop violate-action dropclass coppclass-managementpolice cir 500000 bc 5000 be 5000 conform-action transmit exceed-action drop violate-action dropclass coppclass-monitoringpolice cir 900000 bc 9000 be 9000 conform-action transmit exceed-action drop violate-action dropclass class-defaultpolice cir 500000 bc 5000 be 5000 conform-action transmit exceed-action drop violate-action drop!!!!interface Loopback0ip address 10.7.20.1 255.255.255.0ip pim sparse-modeip igmp version 3!interface Port-channel11description <<** to VSS **>>ip address 10.7.1.1 255.255.255.0ip pim sparse-modeip authentication mode eigrp 7 md5ip authentication key-chain eigrp 7 eigrpip igmp version 3logging event link-statuslogging event trunk-statuslogging event bundle-statusload-interval 30!interface GigabitEthernet1/1no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/2no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/3no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/4no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/5no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/6no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/7no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/8no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/9no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/10no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/11no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/12no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/13no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/14no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/15no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/16no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/17no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/18no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/19no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/20no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/21no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/22no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/23no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/24description G1/24 -- to NETEM -- ToAbstr1ip address 10.7.15.1 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-modeip igmp version 3load-interval 30!interface TenGigabitEthernet4/1description <to dc03-agg>no ip addressno ip redirectsno ip proxy-arpip pim sparse-modeip igmp version 3load-interval 30channel-protocol pagpchannel-group 11 mode desirable!interface TenGigabitEthernet4/2description <to dc01-agg>no ip addressno ip redirectsno ip proxy-arpip pim sparse-modeip igmp version 3load-interval 30channel-protocol pagpchannel-group 11 mode desirable!interface TenGigabitEthernet4/3description <to core-2>ip address 10.8.0.1 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-modeip igmp version 3ip ospf authentication message-digestip ospf message-digest-key 1 md5 7 00071A150754ip ospf hello-interval 1ip ospf dead-interval 3logging event link-statusload-interval 30!interface TenGigabitEthernet4/4ip address 10.8.1.1 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-modeip igmp version 3ip ospf authentication message-digestip ospf message-digest-key 1 md5 7 094F471A1A0Aip ospf hello-interval 1ip ospf dead-interval 3logging event link-statusload-interval 30!interface TenGigabitEthernet5/1description <to abs1>ip address 10.7.11.1 255.255.255.0ip pim sparse-modeip igmp version 3load-interval 30!interface TenGigabitEthernet5/2description <to abs2>ip address 10.7.12.1 255.255.255.0ip flow ingressip pim sparse-modeip igmp version 3load-interval 30mls netflow samplingflow-sampler csmars-sample!interface TenGigabitEthernet5/3no ip addressip pim sparse-modeip igmp version 3load-interval 30!interface TenGigabitEthernet5/4ip address 10.242.10.25 255.255.255.254ip flow ingressip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainlogging event link-statusload-interval 30mls netflow samplingflow-sampler csmars-sample!interface GigabitEthernet6/1no ip addressshutdown!interface GigabitEthernet6/2no ip addressshutdown!interface GigabitEthernet6/3ip address x.26.146.14 255.255.254.0ip access-group 133 inip access-group 134 outno ip redirectsno ip proxy-arp!interface TenGigabitEthernet6/4no ip addressshutdown!interface TenGigabitEthernet6/5no ip addressshutdown!interface Vlan1no ip addressshutdown!router eigrp 7redistribute ospf 8network 10.7.0.0 0.0.255.255default-metric 1000000 100 255 1 1500no auto-summaryeigrp router-id 1.1.1.1!router eigrp 1redistribute ospf 8network 10.242.0.0 0.0.255.255default-metric 1000000 100 255 1 1500no auto-summary!router ospf 8router-id 8.8.8.1log-adjacency-changesauto-cost reference-bandwidth 10000area 0 authentication message-digesttimers throttle spf 10 100 5000timers throttle lsa all 10 100 5000redistribute connectedredistribute static subnetsredistribute eigrp 7 subnetspassive-interface defaultno passive-interface TenGigabitEthernet4/3no passive-interface TenGigabitEthernet4/4network 10.8.0.0 0.0.0.255 area 0network 10.8.1.0 0.0.0.255 area 0network 10.8.2.0 0.0.0.255 area 0default-information originate!ip classlessip route 0.0.0.0 0.0.0.0 10.242.10.24ip route 10.116.132.0 255.255.255.240 x.26.146.1ip route 64.102.208.0 255.255.254.0 x.26.146.1ip route x.26.0.0 255.255.0.0 x.26.146.1ip route x.26.0.0 255.255.0.0 x.26.170.1ip route x.26.129.252 255.255.255.255 x.26.146.1!ip flow-export source GigabitEthernet6/3ip flow-export version 5ip flow-export destination x.26.191.99 2055!no ip http serverno ip http secure-serverip pim bsr-candidate Loopback0 0ip pim rp-candidate Loopback0 priority 100ip tacacs source-interface GigabitEthernet6/3!ip access-list extended coppacl-filemanagementremark CoPP File transfer traffic classpermit tcp x.26.0.0 0.0.255.255 eq ftp host x.26.146.14 gt 1023 establishedpermit tcp x.26.0.0 0.0.255.255 eq ftp-data host x.26.146.14 gt 1023permit tcp x.26.0.0 0.0.255.255 gt 1023 host x.26.146.14 gt 1023 establishedpermit udp x.26.0.0 0.0.255.255 gt 1023 host x.26.146.14 gt 1023ip access-list extended coppacl-igpremark IGP traffic classpermit eigrp any host 224.0.0.10permit eigrp x.26.0.0 0.0.255.255 host x.26.146.14ip access-list extended coppacl-managementremark CoPP management traffic classpermit tcp x.26.0.0 0.0.255.255 eq tacacs host x.26.146.14 establishedpermit tcp x.26.0.0 0.0.255.255 host x.26.146.14 eq 22permit tcp x.26.0.0 0.0.255.255 host x.26.146.14 eq telnetpermit udp x.26.0.0 0.0.255.255 host x.26.146.14 eq snmppermit udp x.26.0.0 0.0.255.255 host x.26.146.14 eq ntpip access-list extended coppacl-monitoringremark CoPP monitoring traffic classpermit icmp any any ttl-exceededpermit icmp any any port-unreachablepermit icmp any any echo-replypermit icmp any any echo!kron occurrence daily-config-backup at 0:05 recurringpolicy-list backup-config!kron policy-list backup-configcli write memory!logging trap criticallogging source-interface GigabitEthernet6/3logging x.26.191.94access-list 7 permit 10.7.0.0 0.0.255.255access-list 8 permit 10.8.0.0 0.0.255.255access-list 10 permit x.26.191.92access-list 55 remark ACL for SNMP access to deviceaccess-list 55 permit x.26.191.99access-list 55 deny any logaccess-list 111 remark ACL for SSHaccess-list 111 permit tcp x.26.0.0 0.0.255.255 any eq 22access-list 111 deny ip any any log-inputaccess-list 111 permit tcp x.26.0.0 0.0.255.255 eq telnet anyaccess-list 111 permit tcp 10.0.0.0 0.255.255.255 eq telnet anyaccess-list 112 remark ACL for last resort accessaccess-list 112 permit tcp host x.26.191.92 any eq 22access-list 112 deny ip any any log-inputaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.146.14 ttl-exceededaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.146.14 port-unreachableaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.146.14 echo-replyaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.146.14 echoaccess-list 133 permit tcp x.26.0.0 0.0.255.255 eq tacacs host x.26.146.14 establishedaccess-list 133 permit tcp x.26.0.0 0.0.255.255 host x.26.146.14 eq tacacsaccess-list 133 permit udp x.26.0.0 0.0.255.255 host x.26.146.14 eq ntpaccess-list 133 permit tcp x.26.0.0 0.0.255.255 host x.26.146.14 eq 22access-list 133 permit tcp x.26.0.0 0.0.255.255 eq ftp host x.26.146.14 gt 1023 establishedaccess-list 133 permit tcp x.26.0.0 0.0.255.255 eq ftp-data host x.26.146.14 gt 1023access-list 133 permit tcp x.26.0.0 0.0.255.255 gt 1023 host x.26.146.14 gt 1023 establishedaccess-list 133 permit udp x.26.0.0 0.0.255.255 gt 1023 host x.26.146.14 gt 1023access-list 133 permit udp host x.26.191.99 host x.26.146.14 eq snmpaccess-list 133 deny ip any any logaccess-list 134 permit ip host x.26.146.14 x.26.0.0 0.0.255.255access-list 134 deny ip any any logsnmp-server community public ROsnmp-server community csmars RO 55snmp-server chassis-id DCA-agg2snmp-server enable traps cpu thresholdsnmp-server host x.26.191.99 csmars cpusnmp ifmib ifindex persisttacacs-server host x.26.191.94 single-connection key 7 02050D4808095E731Ftacacs-server directed-request!radius-server source-ports 1645-1646!control-planeservice-policy input copp-policy!!dial-peer cor custom!!!banner login ^CUNAUTHORIZED ACCESS TO THIS DEVICE IS PROHIBITED You must have explicit, authorized permission to access or configure this device.Unauthorized attempts and actions to access or use this system may result in civil and/or criminal penalties.All activities performed on this device are logged and monitored.^C!line con 0session-timeout 3login authentication authen-exec-listline vty 0 3session-timeout 480access-class 111 inexec-timeout 480 0password <encrypted password>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listlength 0transport preferred nonetransport input sshtransport output noneline vty 4session-timeout 480access-class 112 inexec-timeout 480 0password <encrypted password>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listlength 0transport preferred nonetransport input sshtransport output noneline vty 5 15no exectransport input none!exception protocol ftpexception dump x.26.129.252process cpu threshold type total rising 80 interval 5 falling 20 interval 5process cpu statistics limit entry-percentage 40 size 300ntp authentication-key 10 md5 110A1016141D5A5E57 7ntp authenticatentp trusted-key 10ntp clock-period 17238214ntp source GigabitEthernet6/3ntp update-calendarntp server x.26.170.14ntp server x.26.170.13!endDCA-core2dca-core2#sh runBuilding configuration...Current configuration : 16721 bytes!! Last configuration change at 23:27:03 EST Tue May 12 2009 by chris! NVRAM config last updated at 00:05:37 EST Thu May 14 2009!upgrade fpd autoversion 12.2no service padservice tcp-keepalives-inservice timestamps debug datetime msec localtime show-timezoneservice timestamps log datetime msec localtime show-timezoneservice password-encryptionservice counters max age 5!hostname dca-core2!boot-start-markerboot system disk0:s72033-ipservi.May 14 21:17:19.448 EST: %SEC-6-IPACCESSLOGP: list 133 denied udp x.26.146.21(137) -> x.26.147.255(137), 1 packetcesk9-mz.122-33.SXH2a.binboot-end-marker!enable secret 5 $<encrypted password>/enable password <encrypted password>!username admin privilege 15 password <encrypted password>username dmusername dma password 7 <encrypted password>username chris password 7 <encrypted password>username csmars privilege 15 secret 5 <encrypted password>/aaa new-modelaaa group server tacacs+ tacacs-groupserver x.26.191.94!aaa authentication login authen-exec-list group tacacs-group local-caseaaa authentication enable default group tacacs-group enableaaa authorization exec author-exec-list group tacacs-group if-authenticatedaaa authorization commands 15 author-15-list group tacacs-group noneaaa accounting send stop-record authentication failureaaa accounting exec default start-stop group tacacs-groupaaa accounting commands 15 default start-stop group tacacs-groupaaa accounting system default start-stop group tacacs-group!aaa session-id commonclock timezone GMT 0clock summer-time EST recurringcall-homealert-group configurationalert-group diagnosticalert-group environmentalert-group inventoryalert-group syslogprofile "CiscoTAC-1"no activeno destination transport-method httpdestination transport-method emaildestination address email callhome@cisco.comdestination address http https://tools.cisco.com/its/service/oddce/services/DDCEServicesubscribe-to-alert-group diagnostic severity minorsubscribe-to-alert-group environment severity minorsubscribe-to-alert-group syslog severity major pattern ".*"subscribe-to-alert-group configuration periodic monthly 16 16:46subscribe-to-alert-group inventory periodic monthly 16 16:31ip subnet-zerono ip source-route!!!ip ftp source-interface GigabitEthernet6/3ip ftp username adminip ftp password 7 <encrypted password>no ip bootp serverip multicast-routingip ssh authentication-retries 2ip ssh version 2ip scp server enableno ip domain-lookupip domain-name cisco.comlogin block-for 100 attempts 5 within 50login quiet-mode access-class 10login on-failure logudld enablevtp domain datacentervtp mode transparent!switch virtual domain 100!mls ip cef load-sharing full simplemls netflow interfacemls flow ip interface-fullmls nde sender version 5mls sampling packet-based 128 16000mls qosmls cef error action reset!flow-sampler-map csmars-samplemode random one-out-of 100!key chain eigrpkey 7key-string 7 13061E010803key chain eigrp-chainkey 10key-string 7 05080F1C22431F5B4A!!!!!!!!!archivepath ftp://chrobrie:J0eyD0gg2@x.26.129.252/VSSarchives/$h-$twrite-memorymemory reserve critical 1000memory free low-watermark processor 91492memory free low-watermark IO 6710!redundancykeepalive-enablemode ssomain-cpuauto-sync running-config!spanning-tree mode rapid-pvstspanning-tree extend system-iddiagnostic cns publish cisco.cns.device.diag_resultsdiagnostic cns subscribe cisco.cns.device.diag_commandsfabric switching-mode allow truncated threshold 1fabric switching-mode allow truncatedport-channel hash-distribution adaptiveport-channel load-balance src-dst-mixed-ip-port!vlan internal allocation policy ascendingvlan access-log ratelimit 2000!class-map match-all coppclass-igpmatch access-group name coppacl-igpclass-map match-all coppclass-monitoringmatch access-group name coppacl-monitoringclass-map match-all coppclass-filemanagementmatch access-group name coppacl-filemanagementclass-map match-all coppclass-managementmatch access-group name coppacl-management!!policy-map copp-policyclass coppclass-igppolice cir 300000 bc 3000 be 3000 conform-action transmit exceed-action drop violate-action dropclass coppclass-filemanagementpolice cir 6000000 bc 60000 be 60000 conform-action transmit exceed-action drop violate-action dropclass coppclass-managementpolice cir 500000 bc 5000 be 5000 conform-action transmit exceed-action drop violate-action dropclass coppclass-monitoringpolice cir 900000 bc 9000 be 9000 conform-action transmit exceed-action drop violate-action dropclass class-defaultpolice cir 500000 bc 5000 be 5000 conform-action transmit exceed-action drop violate-action drop!!!!interface Loopback0ip address 10.7.21.1 255.255.255.0ip pim sparse-modeip igmp version 3!interface Port-channel12ip address 10.7.2.1 255.255.255.0ip pim sparse-modeip authentication mode eigrp 7 md5ip authentication key-chain eigrp 7 eigrpip igmp version 3logging event link-statuslogging event trunk-statuslogging event bundle-status!interface GigabitEthernet1/1no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/2no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/3no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/4no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/5no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/6no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/7no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/8no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/9no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/10no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!-More--.May 14 21:17:26.937 EST: %SEC-6-IPACCESSLOGP: list 133 denied udp x.26.146.34(137) -> x.26.147.255(137), 3 packets.May 14 21:17:26.937 EST: %SEC-6-IPACCESSLOGRP: list 133 denied igmp x.26.146.75 -> 224.0.0.2, 5 packeinterface GigabitEthernet1/11no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/12no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/13no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/14no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/15no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/16no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/17no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/18no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/19no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/20no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/21no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/22no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/23no ip addressno ip redirectsno ip proxy-arpload-interval 30shutdown!interface GigabitEthernet1/24description G1/24 -- NETEM -- Abstr2ip address 10.7.16.1 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-modeip igmp version 3load-interval 30!interface TenGigabitEthernet4/1description <** to Agg2 **>no ip addressno ip redirectsno ip proxy-arpip pim sparse-modeip igmp version 3load-interval 30channel-protocol pagpchannel-group 12 mode desirable!interface TenGigabitEthernet4/2description <** to Agg1 **>>no ip addressno ip redirectsno ip proxy-arpip pim sparse-modeip igmp version 3load-interval 30channel-protocol pagpchannel-group 12 mode desirable!interface TenGigabitEthernet4/3description <<** to Core1 **>>ip address 10.8.0.2 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-modeip igmp version 3ip ospf authentication message-digestip ospf message-digest-key 1 md5 7 0822455D0A16ip ospf hello-interval 1ip ospf dead-interval 3logging event link-statusload-interval 30!interface TenGigabitEthernet4/4ip address 10.8.2.1 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-modeip igmp query-interval 125ip ospf authentication message-digestip ospf message-digest-key 1 md5 7 05080F1C2243ip ospf hello-interval 1ip ospf dead-interval 3logging event link-statusload-interval 30!interface TenGigabitEthernet5/1description <<** to Abstr1 **>>ip address 10.7.13.1 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-modeip igmp version 3load-interval 30!interface TenGigabitEthernet5/2description <<** to Abstr2 **>>ip address 10.7.14.1 255.255.255.0no ip redirectsno ip proxy-arpip flow ingressip pim sparse-modeip igmp version 3load-interval 30mls netflow samplingflow-sampler csmars-sample!interface TenGigabitEthernet5/3no ip addressno ip redirectsno ip proxy-arpip pim sparse-modeip igmp version 3load-interval 30!interface TenGigabitEthernet5/4ip address 10.242.10.27 255.255.255.254no ip redirectsno ip proxy-arpip flow ingressip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainlogging event link-statusload-interval 30mls netflow samplingflow-sampler csmars-sample!interface GigabitEthernet6/1no ip addressshutdown!interface GigabitEthernet6/2no ip addressshutdown!interface GigabitEthernet6/3ip address x.26.146.15 255.255.254.0ip access-group 133 inip access-group 134 outno ip redirectsno ip proxy-arp!interface TenGigabitEthernet6/4no ip address--.May 14 21:17:31.964 EST: %SEC-6-IPACCESSLOGP: list 133 denied udp x.26.146.133(137) -> x.26.147.255(137), 1 pac shutdown!interface TenGigabitEthernet6/5no ip address!interface Vlan1no ip addressshutdown!router eigrp 7redistribute ospf 8network 10.7.0.0 0.0.255.255default-metric 1000000 100 255 1 1500no auto-summaryeigrp router-id 1.1.1.2!router eigrp 1redistribute ospf 8network 10.242.0.0 0.0.255.255default-metric 1000000 100 255 1 1500no auto-summary!router ospf 8router-id 8.8.8.2log-adjacency-changesauto-cost reference-bandwidth 10000area 0 authentication message-digesttimers throttle spf 10 100 5000timers throttle lsa all 10 100 5000redistribute connectedredistribute static subnetsredistribute eigrp 7 subnetspassive-interface defaultno passive-interface TenGigabitEthernet4/3no passive-interface TenGigabitEthernet4/4network 10.8.0.0 0.0.0.255 area 0network 10.8.1.0 0.0.0.255 area 0network 10.8.2.0 0.0.0.255 area 0default-information originate!ip classlessip route 0.0.0.0 0.0.0.0 10.242.10.26ip route 10.116.132.0 255.255.255.240 x.26.146.1ip route 64.102.208.0 255.255.254.0 x.26.146.1ip route x.26.0.0 255.255.0.0 x.26.146.1ip route x.26.129.252 255.255.255.255 x.26.146.1!ip flow-export source GigabitEthernet6/3ip flow-export destination x.26.191.99 2055!no ip http serverno ip http secure-serverip pim bsr-candidate Loopback0 0ip pim rp-candidate Loopback0 priority 90ip tacacs source-interface GigabitEthernet6/3!ip access-list extended coppacl-filemanagementremark CoPP File transfer traffic classpermit tcp x.26.0.0 0.0.255.255 eq ftp host x.26.146.15 gt 1023 establishedpermit tcp x.26.0.0 0.0.255.255 eq ftp-data host x.26.146.15 gt 1023permit tcp x.26.0.0 0.0.255.255 gt 1023 host x.26.146.15 gt 1023 establishedpermit udp x.26.0.0 0.0.255.255 gt 1023 host x.26.146.15 gt 1023ip access-list extended coppacl-igpremark IGP traffic classpermit eigrp any host 224.0.0.10permit eigrp x.26.0.0 0.0.255.255 host x.26.146.15ip access-list extended coppacl-managementremark CoPP management traffic classpermit tcp x.26.0.0 0.0.255.255 eq tacacs host x.26.146.15 establishedpermit tcp x.26.0.0 0.0.255.255 host x.26.146.15 eq 22permit tcp x.26.0.0 0.0.255.255 host x.26.146.15 eq telnetpermit udp x.26.0.0 0.0.255.255 host x.26.146.15 eq snmppermit udp x.26.0.0 0.0.255.255 host x.26.146.15 eq ntpip access-list extended coppacl-monitoringremark CoPP monitoring traffic classpermit icmp any any ttl-exceededpermit icmp any any port-unreachablepermit icmp any any echo-replypermit icmp any any echo!kron occurrence daily-config-backup at 0:05 recurringpolicy-list backup-config!kron policy-list backup-configcli write memory!logging trap criticallogging x.26.191.99access-list 7 permit 10.7.0.0 0.0.255.255access-list 8 permit 10.8.0.0 0.0.255.255access-list 10 permit x.26.191.92access-list 10 remarkaccess-list 10 remark Login Delay a 100-second quiet period if 5 failed login attempts is exceededaccess-list 55 remark ACL for SNMP access to deviceaccess-list 55 permit x.26.191.99access-list 55 deny any logaccess-list 111 remark ACL for SSHaccess-list 111 permit tcp x.26.0.0 0.0.255.255 any eq 22access-list 111 deny ip any any log-inputaccess-list 112 remark ACL for last resort accessaccess-list 112 permit tcp host x.26.191.92 any eq 22access-list 112 deny ip any any log-inputaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.146.15 ttl-exceededaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.146.15 port-unreachableaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.146.15 echo-replyaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.146.15 echoaccess-list 133 permit tcp x.26.0.0 0.0.255.255 eq tacacs host x.26.146.15 establishedaccess-list 133 permit tcp x.26.0.0 0.0.255.255 host x.26.146.15 eq tacacsaccess-list 133 permit udp x.26.0.0 0.0.255.255 host x.26.146.15 eq ntpaccess-list 133 permit tcp x.26.0.0 0.0.255.255 host x.26.146.15 eq 22access-list 133 permit tcp x.26.0.0 0.0.255.255 eq ftp host x.26.146.15 gt 1023 establishedaccess-list 133 permit tcp x.26.0.0 0.0.255.255 eq ftp-data host x.26.146.15 gt 1023access-list 133 permit tcp x.26.0.0 0.0.255.255 gt 1023 host x.26.146.15 gt 1023 establishedaccess-list 133 permit udp x.26.0.0 0.0.255.255 gt 1023 host x.26.146.15 gt 1023access-list 133 permit udp host x.26.191.99 host x.26.146.15 eq snmpaccess-list 133 deny ip any any logaccess-list 134 permit ip host x.26.146.15 x.26.0.0 0.0.255.255access-list 134 deny ip any any logsnmp-server community public ROsnmp-server community csmars RO 55snmp-server chassis-id DCA-agg2snmp-server enable traps cpu thresholdsnmp-server host x.26.191.99 public cpusnmp ifmib ifindex persisttacacs-server host x.26.191.94 single-connection key 7 01100F175804575D72tacacs-server directed-request!radius-server source-ports 1645-1646!control-planeservice-policy input copp-policy!!dial-peer cor custom!!!banner login ^CUNAUTHORIZED ACCESS TO THIS DEVICE IS PROHIBITEDYou must have explicit, authorized permission to access or configure this device.Unauthorized attempts and actions to access or use this system may result in civil and/or criminal penalties.All activities performed on this device are logged and monitored.^C!line con 0session-timeout 3login authentication authen-exec-listline vty 0 3session-timeout 480access-class 111 inexec-timeout 480 0password 7 <encrypted password>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listlength 0transport preferred nonetransport input sshtransport output noneline vty 4session-timeout 480access-class 112 inexec-timeout 480 0password 7 <encrypted password>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listlength 0transport preferred nonetransport input sshtransport output noneline vty 5 15no exectransport input none!exception protocol ftpexception dump x.26.129.252process cpu threshold type total rising 80 interval 5 falling 20 interval 5process cpu statistics limit entry-percentage 40 size 300ntp authentication-key 10 md5 13061E010803557878 7ntp authenticatentp trusted-key 10ntp clock-period 17093461ntp source GigabitEthernet6/3ntp server x.26.170.14ntp server x.26.170.13!endAggregation Switch - Nexus 7000Nexus 7000 1dca-n7k1# sh run vdc-all!Running config for default vdc: dca-n7k1version 4.1(2)power redundancy-mode combined forcefeature telnetfeature tacacs+feature ospffeature pimfeature private-vlanfeature udldfeature interface-vlanfeature netflowfeature hsrpfeature lacprole feature-group name network-adminusername admin password 5 <encrypted password>role network-adminusername dma password 5 <encrypted password>role network-adminusername chris password 5 <encrypted password>. role network-adminusername me password 5 <encrypted password>role network-operatorntp server x.26.146.1 use-vrf managementntp source x.26.146.136ip domain-lookupip host dca-n7k1 x.26.146.136tacacs-server key 7 "<key>"tacacs-server host x.26.191.94 key 7 "<key>"aaa group server tacacs+ tacacs-groupserver x.26.191.94use-vrf managementswitchname dca-n7k1ip access-list copp-system-acl-ftp10 permit tcp any any eq ftp-data20 permit tcp any any eq ftp30 permit tcp any eq ftp-data any40 permit tcp any eq ftp anyip access-list copp-system-acl-bgp10 permit tcp any gt 1024 any eq bgp20 permit tcp any eq bgp any gt 1024ip access-list copp-system-acl-rip10 permit udp any 224.0.0.0/24 eq ripip access-list copp-system-acl-vrrp10 permit 112 any 224.0.0.0/24ip access-list 13410 permit ip x.26.146.136/32 x.26.0.0/1620 deny ip any any logip access-list copp-system-acl-igmp10 permit igmp any 224.0.0.0/24ip access-list copp-system-acl-pim10 permit pim any 224.0.0.0/2420 permit udp any any eq pim-auto-rpip access-list copp-system-acl-msdp10 permit tcp any gt 1024 any eq 63920 permit tcp any eq 639 any gt 1024ip access-list copp-system-acl-telnet10 permit tcp any any eq telnet20 permit tcp any any eq 10730 permit tcp any eq telnet any40 permit tcp any eq 107 anyip access-list copp-system-acl-tftp10 permit udp any any eq tftp20 permit udp any any eq 175830 permit udp any eq tftp any40 permit udp any eq 1758 anyip access-list copp-system-acl-eigrp10 permit eigrp any anyip access-list copp-system-acl-ssh10 permit tcp any any eq 2220 permit tcp any eq 22 anyip access-list copp-system-acl-glbp10 permit udp any eq 3222 224.0.0.0/24 eq 3222ip access-list copp-system-acl-snmp10 permit udp any any eq snmp20 permit udp any any eq snmptrapip access-list copp-system-acl-hsrp10 permit udp any 224.0.0.0/24 eq 1985ip access-list copp-system-acl-ospf10 permit ospf any anyip access-list copp-system-acl-sftp10 permit tcp any any eq 11520 permit tcp any eq 115 anyip access-list copp-system-acl-tacacs10 permit tcp any any eq tacacs20 permit tcp any eq tacacs anyip access-list 13310 permit icmp x.26.0.0/16 x.26.146.136/32 ttl-exceeded20 permit icmp x.26.0.0/16 x.26.146.136/32 port-unreachable30 permit icmp x.26.0.0/16 x.26.146.136/32 echo-reply40 permit icmp x.26.0.0/16 x.26.146.136/32 echo50 permit tcp x.26.0.0/16 eq tacacs x.26.146.136/32 established60 permit tcp x.26.0.0/16 x.26.146.136/32 eq tacacs70 permit udp x.26.0.0/16 x.26.146.136/32 eq ntp80 permit tcp x.26.0.0/16 x.26.146.136/32 eq 2290 permit tcp x.26.0.0/16 eq ftp x.26.146.136/32 gt 1023 established100 permit tcp x.26.0.0/16 eq ftp-data x.26.146.136/32 gt 1023110 permit tcp x.26.0.0/16 gt 1023 x.26.146.136/32 gt 1023 established120 permit udp x.26.0.0/16 gt 1023 x.26.146.136/32 gt 1023130 permit udp x.26.191.99/32 x.26.146.136/32 eq snmp140 deny ip any any logip access-list copp-system-acl-traceroute10 permit icmp any any ttl-exceeded20 permit icmp any any port-unreachableip access-list copp-system-acl-undesirable10 permit udp any any eq 1434ip access-list copp-system-acl-icmp10 permit icmp any any echo20 permit icmp any any echo-replyip access-list copp-system-acl-radius10 permit udp any any eq 181220 permit udp any any eq 181330 permit udp any any eq 164540 permit udp any any eq 164650 permit udp any eq 1812 any60 permit udp any eq 1813 any70 permit udp any eq 1645 any80 permit udp any eq 1646 anyip access-list copp-system-acl-ntp10 permit udp any any eq ntp20 permit udp any eq ntp anyclass-map type control-plane match-any copp-system-class-criticalmatch access-group name copp-system-acl-bgpmatch access-group name copp-system-acl-eigrpmatch access-group name copp-system-acl-igmpmatch access-group name copp-system-acl-msdpmatch access-group name copp-system-acl-ospfmatch access-group name copp-system-acl-pimmatch access-group name copp-system-acl-ripclass-map type control-plane match-any copp-system-class-exceptionmatch exception ip optionmatch exception ip icmp unreachableclass-map type control-plane match-any copp-system-class-importantmatch access-group name copp-system-acl-glbpmatch access-group name copp-system-acl-hsrpmatch access-group name copp-system-acl-vrrpclass-map type control-plane match-any copp-system-class-managementmatch access-group name copp-system-acl-ftpmatch access-group name copp-system-acl-ntpmatch access-group name copp-system-acl-radiusmatch access-group name copp-system-acl-sftpmatch access-group name copp-system-acl-snmpmatch access-group name copp-system-acl-sshmatch access-group name copp-system-acl-tacacsmatch access-group name copp-system-acl-telnetmatch access-group name copp-system-acl-tftpclass-map type control-plane match-any copp-system-class-monitoringmatch access-group name copp-system-acl-icmpmatch access-group name copp-system-acl-tracerouteclass-map type control-plane match-any copp-system-class-normalmatch protocol arpclass-map type control-plane match-any copp-system-class-redirectmatch redirect dhcp-snoopmatch redirect arp-inspectclass-map type control-plane match-any copp-system-class-undesirablematch access-group name copp-system-acl-undesirablepolicy-map type control-plane copp-system-policyclass copp-system-class-criticalpolice cir 40900 kbps bc 250 ms conform transmit violate dropclass copp-system-class-importantpolice cir 1060 kbps bc 250 ms conform transmit violate dropclass copp-system-class-managementpolice cir 10000 kbps bc 250 ms conform transmit violate dropclass copp-system-class-normalpolice cir 680 kbps bc 250 ms conform transmit violate dropclass copp-system-class-redirectpolice cir 280 kbps bc 250 ms conform transmit violate dropclass copp-system-class-monitoringpolice cir 100 kbps bc 250 ms conform transmit violate dropclass copp-system-class-exceptionpolice cir 360 kbps bc 250 ms conform transmit violate dropclass copp-system-class-undesirablepolice cir 32 kbps bc 250 ms conform drop violate dropclass class-defaultpolice cir 100 kbps bc 250 ms conform transmit violate dropcontrol-planeservice-policy input copp-system-policysnmp-server user me network-operator auth md5 0xdd0bd06e76f692a1bbaebceac6f6ee1apriv 0xdd0bd06e76f692a1bbaebceac6f6ee1a localizedkeysnmp-server user dma network-admin auth md5 0xdd0bd06e76f692a1bbaebceac6f6ee1a priv 0xdd0bd06e76f692a1bbaebceac6f6ee1a localizedkeysnmp-server user admin network-admin auth md5 0xdd0bd06e76f692a1bbaebceac6f6ee1apriv 0xdd0bd06e76f692a1bbaebceac6f6ee1a localizedkeysnmp-server user chris network-admin auth md5 0xdd0bd06e76f692a1bbaebceac6f6ee1apriv 0xdd0bd06e76f692a1bbaebceac6f6ee1a localizedkeysnmp-server enable traps entity fruaaa authentication login console group tacacs-groupaaa accounting default group tacacs-groupaaa authentication login error-enableaaa authentication login ascii-authenticationvrf context managementip route 0.0.0.0/0 10.1.1.1ip route 0.0.0.0/0 x.26.146.1vlan 1route-map clients permit 1vdc dca-n7k1 id 1limit-resource vlan minimum 16 maximum 4094limit-resource monitor-session minimum 0 maximum 2limit-resource vrf minimum 16 maximum 8192limit-resource port-channel minimum 0 maximum 192limit-resource u4route-mem minimum 32 maximum 32limit-resource u6route-mem minimum 16 maximum 16limit-resource m4route-mem minimum 48 maximum 48limit-resource m6route-mem minimum 8 maximum 8vdc vdc1 id 2allocate interface Ethernet1/1,Ethernet1/3,Ethernet1/5,Ethernet1/7,Ethernet1/9,Ethernet1/11,Ethernet1/13,Ethernet1/15allocate interface Ethernet2/2,Ethernet2/4,Ethernet2/6,Ethernet2/8limit-resource vlan minimum 16 maximum 4094limit-resource monitor-session minimum 0 maximum 2limit-resource vrf minimum 16 maximum 8192limit-resource port-channel minimum 0 maximum 192limit-resource u4route-mem minimum 8 maximum 8limit-resource u6route-mem minimum 4 maximum 4limit-resource m4route-mem minimum 8 maximum 8limit-resource m6route-mem minimum 2 maximum 2vdc vdc2 id 3allocate interface Ethernet1/2,Ethernet1/4,Ethernet1/6,Ethernet1/8,Ethernet1/10,Ethernet1/12,Ethernet1/14,Ethernet1/16-32allocate interface Ethernet2/1,Ethernet2/3,Ethernet2/5,Ethernet2/7,Ethernet2/9-48limit-resource vlan minimum 16 maximum 4094limit-resource monitor-session minimum 0 maximum 2limit-resource vrf minimum 16 maximum 8192limit-resource port-channel minimum 0 maximum 192limit-resource u4route-mem minimum 8 maximum 8limit-resource u6route-mem minimum 4 maximum 4limit-resource m4route-mem minimum 8 maximum 8limit-resource m6route-mem minimum 2 maximum 2interface Vlan1interface cmp-mgmt module 5ip address x.26.146.175 255.255.254.0ip default-gateway x.26.146.1interface cmp-mgmt module 6ip address x.26.146.176 255.255.254.0ip default-gateway x.26.146.1interface Ethernet10/1interface Ethernet10/2interface Ethernet10/3interface Ethernet10/4interface Ethernet10/5interface Ethernet10/6interface Ethernet10/7interface Ethernet10/8interface Ethernet10/9interface Ethernet10/10interface Ethernet10/11interface Ethernet10/12interface Ethernet10/13interface Ethernet10/14interface Ethernet10/15interface Ethernet10/16interface Ethernet10/17interface Ethernet10/18interface Ethernet10/19interface Ethernet10/20interface Ethernet10/21interface Ethernet10/22interface Ethernet10/23interface Ethernet10/24interface Ethernet10/25interface Ethernet10/26interface Ethernet10/27interface Ethernet10/28interface Ethernet10/29interface Ethernet10/30interface Ethernet10/31interface Ethernet10/32interface Ethernet10/33interface Ethernet10/34interface Ethernet10/35interface Ethernet10/36interface Ethernet10/37interface Ethernet10/38interface Ethernet10/39interface Ethernet10/40interface Ethernet10/41interface Ethernet10/42interface Ethernet10/43interface Ethernet10/44interface Ethernet10/45interface Ethernet10/46interface Ethernet10/47interface Ethernet10/48interface mgmt0ip access-group 133 inip access-group 134 outvrf member managementip address x.26.146.136/23no ip redirectsclock timezone EDT -5 0clock summer-time EDT 3 Sun Mar 00:00 3 Sunday Oct 00:00 60cli alias name save copy runn start vdcline consoleterminal length 30boot kickstart bootflash:/n7000-s1-kickstart.4.1.2.bin sup-1boot system bootflash:/n7000-s1-dk9.4.1.2.bin sup-1boot kickstart bootflash:/n7000-s1-kickstart.4.1.2.bin sup-2boot system bootflash:/n7000-s1-dk9.4.1.2.bin sup-2ip route x.26.0.0/16 x.26.146.1monitor session 1!Running config for vdc: vdc1switchto vdc vdc1version 4.1(2)feature tacacs+feature ospffeature ospfv3feature pimfeature udldfeature interface-vlanfeature hsrpfeature lacplogging level monitor 7username admin password 5 <encrypted password>role vdc-adminip domain-lookupip domain-name cisco.comtacacs-server key 7 "fewhg123"tacacs-server host x.26.191.94 key 7 "fewhg123"aaa group server tacacs+ tacacs-groupserver x.26.191.94service unsupported-transceiverip access-list 11210 remark ACL for last resort access20 permit tcp x.26.191.92/32 any eq 2230 deny ip any any logip access-list 11110 remark ACL for SSH20 permit tcp x.26.0.0/16 any eq 2230 deny ip any any logsnmp-server user admin vdc-admin auth md5 0xdd0bd06e76f692a1bbaebceac6f6ee1a priv 0xdd0bd06e76f692a1bbaebceac6f6ee1a localizedkeyaaa accounting default group tacacs-groupvrf context managementip route 0.0.0.0/0 x.26.146.1vlan 1,3vlan 99name vmconsolevlan 128-133vlan 151name asa-vdc2-Outsidevlan 161name asa-vdc1-Outsidevlan 770-771spanning-tree pathcost method longspanning-tree port type network defaultspanning-tree vlan 99,128,130,132,166,770-771 priority 24576spanning-tree vlan 129,131,133 priority 28672route-map static permit 10interface Vlan1interface Vlan3no shutdownip address 10.8.3.1/24ip ospf authentication message-digestip ospf authentication-key 3 9125d59c18a9b015ip ospf dead-interval 3ip ospf hello-interval 1ip router ospf 8 area 0.0.0.0ip pim sparse-modeip igmp version 3interface Vlan99no shutdownip address 10.8.99.3/24ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20timers 1 3ip 10.8.99.1interface Vlan128no shutdownip address 10.8.128.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.128.1interface Vlan129no shutdownip address 10.8.129.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.129.1interface Vlan130no shutdownip address 10.8.130.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.130.1interface Vlan131no shutdownip address 10.8.131.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.131.1interface Vlan132no shutdownip address 10.8.132.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.132.1interface Vlan133no shutdownip address 10.8.133.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.133.1interface Vlan151no shutdownip address 10.8.152.3/24ip ospf authentication message-digestip ospf message-digest-key 1 md5 3 b2255cb5a7107f1bip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.152.1interface Vlan161no shutdownip address 10.8.162.3/24ip ospf authentication message-digestip ospf message-digest-key 1 md5 3 b2255cb5a7107f1bip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.162.1interface port-channel99description to dca-n7k2-vdc1switchportswitchport mode trunkswitchport trunk allowed vlan 3,50-51,99,128-133,151,161,770-771spanning-tree port type networklogging event port link-statusinterface Ethernet1/1description to dca-core2 Ten4/4ip address 10.8.1.2/24ip ospf authentication message-digestip ospf message-digest-key 1 md5 3 9125d59c18a9b015ip ospf dead-interval 3ip ospf hello-interval 1ip router ospf 8 area 0.0.0.0ip pim sparse-modeip igmp version 3no shutdowninterface Ethernet1/3description to dca-asa2 Ten5/0switchportswitchport mode trunkswitchport trunk allowed vlan 161spanning-tree port type normalno shutdowninterface Ethernet1/5description to dca-asa2 Ten7/0switchportswitchport mode trunkswitchport trunk allowed vlan 151spanning-tree port type normalno shutdowninterface Ethernet1/7no shutdowninterface Ethernet1/9interface Ethernet1/11interface Ethernet1/13description ISLswitchportswitchport mode trunkswitchport trunk allowed vlan 3,50-51,99,128-133,151,161,770-771channel-group 99 mode activeno shutdowninterface Ethernet1/15description ISLswitchportswitchport mode trunkswitchport trunk allowed vlan 3,50-51,99,128-133,151,161,770-771channel-group 99 mode activeno shutdowninterface Ethernet2/2description IXIA port 4/1switchportswitchport access vlan 128spanning-tree port type edgeno shutdowninterface Ethernet2/4description IXIA port 4/2switchportswitchport access vlan 130spanning-tree port type edgeno shutdowninterface Ethernet2/6description IXIA port 4/3switchportswitchport access vlan 132spanning-tree port type edgeno shutdowninterface Ethernet2/8description IXIA port 4/4interface mgmt0description <<mgmt interface>>ip address x.26.146.137/23clock timezone EDT -5 0clock summer-time EDT 3 Sun Mar 00:00 3 Sunday Oct 00:00 60no logging consolecli alias name save copy runn startline consoleterminal length 30router ospf 8router-id 3.3.3.1area 81 nssadefault-information originatearea 0.0.0.0 range 10.8.0.0/24area 0.0.0.0 range 10.8.1.0/24area 0.0.0.0 range 10.8.2.0/24area 0.0.0.0 range 10.8.3.0/24area 0.0.0.81 range 10.8.128.0/18area 0.0.0.0 authentication message-digestarea 0.0.0.81 authentication message-digesttimers throttle spf 10 100 5000timers throttle lsa router 1000timers throttle lsa network 1000auto-cost reference-bandwidth 10000no ip source-routeip pim ssm range 232.0.0.0/8switchback!Running config for vdc: vdc2switchto vdc vdc2version 4.1(2)feature ospffeature ospfv3feature pimfeature udldfeature interface-vlanfeature hsrpfeature lacpusername admin password 5 <encrypted password>/ role vdc-adminip domain-lookupsystem default switchportlogging event link-status defaultlogging event trunk-status defaultservice unsupported-transceiversnmp-server user admin vdc-admin auth md5 0xdd0bd06e76f692a1bbaebceac6f6ee1a priv 0xdd0bd06e76f692a1bbaebceac6f6ee1a localizedkeyvrf context erspanvrf context servers1ip route 0.0.0.0/0 10.8.162.1vrf context servers2ip route 0.0.0.0/0 10.8.152.1vrf context managementip route 0.0.0.0/0 x.26.146.1vlan 1vlan 15name vmkernelvlan 50-51vlan 98name serviceconsolevlan 141-142,152-153,162-164,166-169vlan 171name failovervlan 172name statevlan 180-183vlan 191name waasvlan 200name Mike-Server-1vlan 201name Mike-Server-2vlan 202name Mike-Server-3vlan 300-399vlan 999name ACEqueryvlan 3000name erspanvlan 3001name erspan-ss1vlan 3002name vemcontrolvlan 3003name vempacketspanning-tree pathcost method longspanning-tree port type network defaultspanning-tree vlan 1,15,98,142,166,168,180,182,200-202,300-399,3000,3002-3003 priority 24576spanning-tree vlan 50-51,167,169,181,183 priority 28672interface Vlan1interface Vlan15no shutdownvrf member servers1ip address 10.8.15.3/24ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20timers 1 3ip 10.8.15.1interface Vlan50no shutdownvrf member servers2ip address 10.8.50.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.50.1interface Vlan51no shutdownvrf member servers2ip address 10.8.51.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.51.1interface Vlan98no shutdownvrf member servers1ip address 10.8.98.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20timers 1 3ip 10.8.98.1interface Vlan141vrf member servers1ip address 10.8.141.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.141.1interface Vlan142no shutdownvrf member servers1ip address 10.8.141.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.141.1interface Vlan152no shutdownvrf member servers2ip address 10.8.152.5/24ip ospf authentication message-digestip ospf message-digest-key 1 md5 3 b2255cb5a7107f1bip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 2authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.152.7interface Vlan153vrf member servers2ip address 10.8.152.5/24ip ospf authentication message-digestip ospf message-digest-key 1 md5 3 b2255cb5a7107f1bip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 2authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.152.7interface Vlan164no shutdownvrf member servers1ip address 10.8.162.5/24ip ospf authentication message-digestip ospf message-digest-key 1 md5 3 b2255cb5a7107f1bip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 2authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.162.7interface Vlan166no shutdownvrf member servers1ip address 10.8.166.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.166.1interface Vlan167no shutdownvrf member servers2ip address 10.8.167.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.167.1interface Vlan168no shutdownvrf member servers1ip address 10.8.168.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.168.1interface Vlan169no shutdownvrf member servers2ip address 10.8.169.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.169.1interface Vlan180no shutdownvrf member servers1ip address 10.8.180.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.180.1interface Vlan181no shutdownvrf member servers2ip address 10.8.181.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.181.1interface Vlan182no shutdownvrf member servers1ip address 10.8.182.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.182.1interface Vlan183no shutdownvrf member servers2ip address 10.8.183.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.183.1interface Vlan200no shutdownvrf member servers2ip address 10.8.200.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 600 reload 300timers 1 3ip 10.8.200.1interface Vlan201no shutdownvrf member servers2ip address 10.8.201.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 600 reload 300timers 1 3ip 10.8.201.1interface Vlan202no shutdownvrf member servers2ip address 10.8.202.3/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 600 reload 300timers 1 3ip 10.8.202.1interface Vlan3000no shutdownip address 10.8.3.3/24hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.3.1interface Vlan3001no shutdownip address 10.8.33.3/24interface port-channel7description to vbsswitchport mode trunkswitchport trunk allowed vlan 180-183spanning-tree port type normalspanning-tree guard rootlogging event port link-statuslogging event port trunk-statusinterface port-channel71switchport mode trunkswitchport trunk allowed vlan 15,142,180-183,300-399,3002-3003spanning-tree port type networkspanning-tree guard rootlogging event port link-statuslogging event port trunk-statusinterface port-channel72interface port-channel99description ISL to dca-n7k2-vdc1switchport mode trunkswitchport trunk allowed vlan 15,50-51,98,141-142,152-153,162-164switchport trunk allowed vlan add 166-169,171-172,180-183,191,200-202switchport trunk allowed vlan add 300-399,999,3000-3003spanning-tree cost 500spanning-tree port type networklogging event port link-statusinterface port-channel200description to dc10-5020-5switchport mode trunkswitchport trunk allowed vlan 200-202spanning-tree port type networkspanning-tree guard looplogging event port link-statuslogging event port trunk-statusinterface Ethernet1/2description E1/2 to dca-newSS2 Ten1/2switchport mode trunkswitchport trunk allowed vlan 152-153,162-164,191,999,3001spanning-tree port type networkspanning-tree guard loopmtu 9216logging event port link-statuslogging event port trunk-statusinterface Ethernet1/4description E1/4 to dca-newSS1 Ten1/1switchport mode trunkswitchport trunk allowed vlan 152-153,162-164,191,999,3001spanning-tree port type networkspanning-tree guard loopmtu 9216logging event port link-statuslogging event port trunk-statusinterface Ethernet1/6description to dc10-5020-5switchport mode trunkswitchport trunk allowed vlan 200-202logging event port link-statuslogging event port trunk-statusudld enablechannel-group 200 mode activeinterface Ethernet1/8description to dc10-5020-6switchport mode trunkswitchport trunk allowed vlan 200-202spanning-tree port type networkspanning-tree guard looplogging event port link-statuslogging event port trunk-statusudld enableinterface Ethernet1/10description to dca-asa2 Ten5/1switchport mode trunkswitchport trunk allowed vlan 162spanning-tree port type normalinterface Ethernet1/12description to dca-asa2 Ten7/1switchport mode trunkswitchport trunk allowed vlan 152spanning-tree port type normalinterface Ethernet1/14description ISLswitchport mode trunkswitchport trunk allowed vlan 15,50-51,98,141-142,152-153,162-164switchport trunk allowed vlan add 166-169,171-172,180-183,191,200-202switchport trunk allowed vlan add 300-399,999,3000-3003channel-group 99 mode activeinterface Ethernet1/16description ISLswitchport mode trunkswitchport trunk allowed vlan 15,50-51,98,141-142,152-153,162-164switchport trunk allowed vlan add 166-169,171-172,180-183,191,200-202switchport trunk allowed vlan add 300-399,999,3000-3003channel-group 99 mode activeinterface Ethernet1/17description dc20-4948-1switchport mode trunkswitchport trunk allowed vlan 50-51,142spanning-tree port type normalspanning-tree guard rootinterface Ethernet1/18description dc07-3120-vbs Ten4/0/2switchport mode trunkswitchport trunk allowed vlan 180-183spanning-tree port type normalspanning-tree guard rootchannel-group 7 mode activeinterface Ethernet1/19description dc20-4948-2switchport mode trunkswitchport trunk allowed vlan 50-51,142spanning-tree port type normalspanning-tree guard rootinterface Ethernet1/20description dc07-3120-vbs Ten2/0/1switchport mode trunkswitchport trunk allowed vlan 180-183spanning-tree port type normalspanning-tree guard rootchannel-group 7 mode activeinterface Ethernet1/21interface Ethernet1/22description to dc10-5020-5switchport mode trunkswitchport trunk allowed vlan 200-202logging event port link-statuslogging event port trunk-statusudld enablechannel-group 200 mode activeinterface Ethernet1/23interface Ethernet1/24interface Ethernet1/25description dca-vss-accswitchport mode trunkswitchport trunk allowed vlan 15,142,180-183,300-399,3002-3003spanning-tree port type networkspanning-tree guard rootlogging event port link-statuslogging event port trunk-statuschannel-group 71 mode activeinterface Ethernet1/26description dc10-5020-1switchport mode trunkswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type networkspanning-tree guard rootmtu 9216logging event port link-statuslogging event port trunk-statusinterface Ethernet1/27description dca-vss-accswitchport mode trunkswitchport trunk allowed vlan 15,142,180-183,300-399,3002-3003spanning-tree port type networkspanning-tree guard rootlogging event port link-statuslogging event port trunk-statuschannel-group 71 mode activeinterface Ethernet1/28description dc10.5020-2switchport mode trunkswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type networkspanning-tree guard rootmtu 9216logging event port link-statuslogging event port trunk-statusinterface Ethernet1/29description to 6k accessswitchport mode trunkswitchport trunk allowed vlan 128-133,164-169,180-183,300-399spanning-tree port type normalspanning-tree guard rootinterface Ethernet1/30description dc10-5020-1switchport mode trunkswitchport trunk allowed vlan 15,98,180-183spanning-tree port type networkinterface Ethernet1/31description to 6k accessswitchport mode trunkswitchport trunk allowed vlan 128-133,164-169,180-183,300-399spanning-tree port type normalspanning-tree guard rootinterface Ethernet1/32description dc10-5020-1switchport mode trunkswitchport trunk allowed vlan 15,98,180-183spanning-tree port type networkinterface Ethernet2/1switchport access vlan 172spanning-tree port type normalinterface Ethernet2/3switchport access vlan 171spanning-tree port type normalinterface Ethernet2/5interface Ethernet2/7interface Ethernet2/9interface Ethernet2/10interface Ethernet2/11interface Ethernet2/12interface Ethernet2/13interface Ethernet2/14interface Ethernet2/15interface Ethernet2/16interface Ethernet2/17interface Ethernet2/18interface Ethernet2/19interface Ethernet2/20interface Ethernet2/21interface Ethernet2/22interface Ethernet2/23interface Ethernet2/24interface Ethernet2/25interface Ethernet2/26interface Ethernet2/27interface Ethernet2/28interface Ethernet2/29interface Ethernet2/30interface Ethernet2/31interface Ethernet2/32interface Ethernet2/33interface Ethernet2/34interface Ethernet2/35interface Ethernet2/36interface Ethernet2/37description ASA1 int g3/3switchport mode trunkswitchport trunk allowed vlan 142spanning-tree port type normallogging event port link-statuslogging event port trunk-statusinterface Ethernet2/38description ASA int g3/2switchport mode trunkswitchport trunk allowed vlan 141spanning-tree port type normallogging event port link-statuslogging event port trunk-statusinterface Ethernet2/39interface Ethernet2/40interface Ethernet2/41interface Ethernet2/42interface Ethernet2/43interface Ethernet2/44interface Ethernet2/45interface Ethernet2/46interface Ethernet2/47interface Ethernet2/48interface mgmt0ip address x.26.146.138/23clock timezone EDT -5 0clock summer-time EDT 3 Sun Mar 00:00 3 Sunday Oct 00:00 60cli alias name save copy runn startline consoleterminal length 30router ospf 8vrf servers1router-id 4.4.4.1area 81 nssaarea 0.0.0.81 authentication message-digesttimers throttle spf 10 100 5000timers throttle lsa router 1000timers throttle lsa network 1000vrf servers2router-id 5.5.5.1area 81 nssaarea 0.0.0.81 authentication message-digesttimers throttle spf 10 100 5000timers throttle lsa router 1000timers throttle lsa network 1000ip pim rp-address 10.8.20.1 group-list 224.0.0.0/4ip pim ssm range 232.0.0.0/8no system default switchport shutdownswitchbackdca-n7k1#Nexus 7000 2dca-n7k2# sh run vdc-all!Running config for default vdc: dca-n7k2version 4.1(2)power redundancy-mode combined forcefeature telnetfeature tacacs+feature ospffeature pimfeature private-vlanfeature udldfeature interface-vlanfeature netflowfeature hsrpfeature lacpusername admin password 5 <encrypted password>role network-adminusername dma password 5 <encrypted password>. role network-adminusername chris password 5 <encrypted password>. role network-adminusername dma1-ops password 5 <encrypted password>role network-operatorntp server x.26.146.1 use-vrf managementip domain-lookupip host dca-n7k2 x.26.146.204ip host dca-n7k2 x.26.146.204tacacs-server key 7 "<key>"tacacs-server host x.26.191.94 key 7 "<key>"aaa group server tacacs+ tacacs-groupserver x.26.191.94use-vrf managementhostname dca-n7k2service unsupported-transceiverip access-list copp-system-acl-ftp10 permit tcp any any eq ftp-data20 permit tcp any any eq ftp30 permit tcp any eq ftp-data any40 permit tcp any eq ftp anyip access-list copp-system-acl-bgp10 permit tcp any gt 1024 any eq bgp20 permit tcp any eq bgp any gt 1024ip access-list copp-system-acl-rip10 permit udp any 224.0.0.0/24 eq ripip access-list copp-system-acl-vrrp10 permit 112 any 224.0.0.0/24ip access-list 13410 permit ip x.26.146.204/32 x.26.0.0/1620 deny ip any any logip access-list copp-system-acl-igmp10 permit igmp any 224.0.0.0/24ip access-list copp-system-acl-pim10 permit pim any 224.0.0.0/2420 permit udp any any eq pim-auto-rpip access-list copp-system-acl-msdp10 permit tcp any gt 1024 any eq 63920 permit tcp any eq 639 any gt 1024ip access-list copp-system-acl-telnet10 permit tcp any any eq telnet20 permit tcp any any eq 10730 permit tcp any eq telnet any40 permit tcp any eq 107 anyip access-list copp-system-acl-tftp10 permit udp any any eq tftp20 permit udp any any eq 175830 permit udp any eq tftp any40 permit udp any eq 1758 anyip access-list copp-system-acl-eigrp10 permit eigrp any anyip access-list copp-system-acl-ssh10 permit tcp any any eq 2220 permit tcp any eq 22 anyip access-list copp-system-acl-glbp10 permit udp any eq 3222 224.0.0.0/24 eq 3222ip access-list copp-system-acl-snmp10 permit udp any any eq snmp20 permit udp any any eq snmptrapip access-list copp-system-acl-hsrp10 permit udp any 224.0.0.0/24 eq 1985ip access-list copp-system-acl-ospf10 permit ospf any anyip access-list copp-system-acl-sftp10 permit tcp any any eq 11520 permit tcp any eq 115 anyip access-list copp-system-acl-tacacs10 permit tcp any any eq tacacs20 permit tcp any eq tacacs anyip access-list 13310 permit icmp x.26.0.0/16 x.26.146.204/32 ttl-exceeded20 permit icmp x.26.0.0/16 x.26.146.204/32 port-unreachable30 permit icmp x.26.0.0/16 x.26.146.204/32 echo-reply40 permit icmp x.26.0.0/16 x.26.146.204/32 echo50 permit tcp x.26.0.0/16 eq tacacs x.26.146.204/32 established60 permit tcp x.26.0.0/16 x.26.146.204/32 eq tacacs70 permit udp x.26.0.0/16 x.26.146.204/32 eq ntp80 permit tcp x.26.0.0/16 x.26.146.204/32 eq 2290 permit tcp x.26.0.0/16 eq ftp x.26.146.204/32 gt 1023 established100 permit tcp x.26.0.0/16 eq ftp-data x.26.146.204/32 gt 1023110 permit tcp x.26.0.0/16 gt 1023 x.26.146.204/32 gt 1023 established120 permit udp x.26.0.0/16 gt 1023 x.26.146.204/32 gt 1023130 permit udp x.26.191.99/32 x.26.146.204/32 eq snmp140 deny ip any any logip access-list copp-system-acl-traceroute10 permit icmp any any ttl-exceeded20 permit icmp any any port-unreachableip access-list copp-system-acl-undesirable10 permit udp any any eq 1434ip access-list copp-system-acl-icmp10 permit icmp any any echo20 permit icmp any any echo-replyip access-list copp-system-acl-radius10 permit udp any any eq 181220 permit udp any any eq 181330 permit udp any any eq 164540 permit udp any any eq 164650 permit udp any eq 1812 any60 permit udp any eq 1813 any70 permit udp any eq 1645 any80 permit udp any eq 1646 anyip access-list copp-system-acl-ntp10 permit udp any any eq ntp20 permit udp any eq ntp anyclass-map type control-plane match-any copp-system-class-criticalmatch access-group name copp-system-acl-bgpmatch access-group name copp-system-acl-eigrpmatch access-group name copp-system-acl-igmpmatch access-group name copp-system-acl-msdpmatch access-group name copp-system-acl-ospfmatch access-group name copp-system-acl-pimmatch access-group name copp-system-acl-ripclass-map type control-plane match-any copp-system-class-exceptionmatch exception ip optionmatch exception ip icmp unreachableclass-map type control-plane match-any copp-system-class-importantmatch access-group name copp-system-acl-glbpmatch access-group name copp-system-acl-hsrpmatch access-group name copp-system-acl-vrrpclass-map type control-plane match-any copp-system-class-managementmatch access-group name copp-system-acl-ftpmatch access-group name copp-system-acl-ntpmatch access-group name copp-system-acl-radiusmatch access-group name copp-system-acl-sftpmatch access-group name copp-system-acl-snmpmatch access-group name copp-system-acl-sshmatch access-group name copp-system-acl-tacacsmatch access-group name copp-system-acl-telnetmatch access-group name copp-system-acl-tftpclass-map type control-plane match-any copp-system-class-monitoringmatch access-group name copp-system-acl-icmpmatch access-group name copp-system-acl-tracerouteclass-map type control-plane match-any copp-system-class-normalmatch protocol arpclass-map type control-plane match-any copp-system-class-redirectmatch redirect dhcp-snoopmatch redirect arp-inspectclass-map type control-plane match-any copp-system-class-undesirablematch access-group name copp-system-acl-undesirablepolicy-map type control-plane copp-system-policyclass copp-system-class-criticalpolice cir 40900 kbps bc 250 ms conform transmit violate dropclass copp-system-class-importantpolice cir 1060 kbps bc 250 ms conform transmit violate dropclass copp-system-class-managementpolice cir 10000 kbps bc 250 ms conform transmit violate dropclass copp-system-class-normalpolice cir 680 kbps bc 250 ms conform transmit violate dropclass copp-system-class-redirectpolice cir 280 kbps bc 250 ms conform transmit violate dropclass copp-system-class-monitoringpolice cir 100 kbps bc 250 ms conform transmit violate dropclass copp-system-class-exceptionpolice cir 360 kbps bc 250 ms conform transmit violate dropclass copp-system-class-undesirablepolice cir 32 kbps bc 250 ms conform drop violate dropclass class-defaultpolice cir 100 kbps bc 250 ms conform transmit violate dropcontrol-planeservice-policy input copp-system-policysnmp-server user dma network-admin auth md5 0xb1f79b0d0c98a2387bb30043f9c8e5ce priv 0xb1f79b0d0c98a2387bb30043f9c8e5ce localizedkeysnmp-server user admin network-admin auth md5 0xb1f79b0d0c98a2387bb30043f9c8e5ce priv 0xb1f79b0d0c98a2387bb30043f9c8e5ce localizedkeysnmp-server user chris network-admin auth md5 0xb1f79b0d0c98a2387bb30043f9c8e5ce priv 0xb1f79b0d0c98a2387bb30043f9c8e5ce localizedkeysnmp-server user dma1-ops network-operator auth md5 0xb1f79b0d0c98a2387bb30043f9c8e5ce priv 0xb1f79b0d0c98a2387bb30043f9c8e5ce localizedkeysnmp-server enable traps entity fruaaa authentication login console group tacacs-groupaaa accounting default group tacacs-groupaaa authentication login error-enablevrf context managementip route 0.0.0.0/0 x.26.146.1vlan 1vdc dca-n7k2 id 1limit-resource vlan minimum 16 maximum 4094limit-resource monitor-session minimum 0 maximum 2limit-resource vrf minimum 16 maximum 8192limit-resource port-channel minimum 0 maximum 192limit-resource u4route-mem minimum 32 maximum 32limit-resource u6route-mem minimum 16 maximum 16limit-resource m4route-mem minimum 48 maximum 48limit-resource m6route-mem minimum 8 maximum 8vdc vdc1 id 2allocate interface Ethernet1/1,Ethernet1/3,Ethernet1/5,Ethernet1/7,Ethernet1/9,Ethernet1/11,Ethernet1/13,Ethe rnet1/15allocate interface Ethernet2/2,Ethernet2/4,Ethernet2/6,Ethernet2/8limit-resource vlan minimum 16 maximum 4094limit-resource monitor-session minimum 0 maximum 2limit-resource vrf minimum 16 maximum 8192limit-resource port-channel minimum 0 maximum 192limit-resource u4route-mem minimum 8 maximum 8limit-resource u6route-mem minimum 4 maximum 4limit-resource m4route-mem minimum 8 maximum 8limit-resource m6route-mem minimum 2 maximum 2vdc vdc2 id 3allocate interface Ethernet1/2,Ethernet1/4,Ethernet1/6,Ethernet1/8,Ethernet1/10,Ethernet1/12,Ethernet1/14,Eth ernet1/16-32allocate interface Ethernet2/1,Ethernet2/3,Ethernet2/5,Ethernet2/7,Ethernet2/9-48limit-resource vlan minimum 16 maximum 4094limit-resource monitor-session minimum 0 maximum 2limit-resource vrf minimum 16 maximum 8192limit-resource port-channel minimum 0 maximum 192limit-resource u4route-mem minimum 8 maximum 8limit-resource u6route-mem minimum 4 maximum 4limit-resource m4route-mem minimum 8 maximum 8limit-resource m6route-mem minimum 2 maximum 2interface Vlan1interface cmp-mgmt module 5ip address x.26.146.85 255.255.254.0ip default-gateway x.26.146.1interface cmp-mgmt module 6ip address x.26.146.86 255.255.254.0ip default-gateway x.26.146.1interface mgmt0description <<** Flash address **>>ip access-group 133 inip access-group 134 outvrf member managementip address x.26.146.204/23no ip redirectsclock timezone EDT -5 0clock summer-time EDT 3 Sun Mar 00:00 3 Sunday Oct 00:00 60cli alias name save copy runn start vdcline consoleterminal length 30boot kickstart bootflash:/n7000-s1-kickstart.4.1.2.bin sup-1boot system bootflash:/n7000-s1-dk9.4.1.2.bin sup-1boot kickstart bootflash:/n7000-s1-kickstart.4.1.2.bin sup-2boot system bootflash:/n7000-s1-dk9.4.1.2.bin sup-2interface Ethernet10/1interface Ethernet10/2interface Ethernet10/3interface Ethernet10/4interface Ethernet10/5interface Ethernet10/6interface Ethernet10/7interface Ethernet10/8interface Ethernet10/9interface Ethernet10/10interface Ethernet10/11interface Ethernet10/12interface Ethernet10/13interface Ethernet10/14interface Ethernet10/15interface Ethernet10/16interface Ethernet10/17interface Ethernet10/18interface Ethernet10/19interface Ethernet10/20interface Ethernet10/21interface Ethernet10/22interface Ethernet10/23interface Ethernet10/24interface Ethernet10/25interface Ethernet10/26interface Ethernet10/27interface Ethernet10/28interface Ethernet10/29interface Ethernet10/30interface Ethernet10/31interface Ethernet10/32interface Ethernet10/33interface Ethernet10/34interface Ethernet10/35interface Ethernet10/36interface Ethernet10/37interface Ethernet10/38interface Ethernet10/39interface Ethernet10/40interface Ethernet10/41interface Ethernet10/42interface Ethernet10/43interface Ethernet10/44interface Ethernet10/45interface Ethernet10/46interface Ethernet10/47interface Ethernet10/48ip route x.26.0.0/16 x.26.146.1no ip source-routelogging timestamp milliseconds!Running config for vdc: vdc1switchto vdc vdc1version 4.1(2)feature telnetfeature ospffeature pimfeature private-vlanfeature udldfeature interface-vlanfeature hsrpfeature lacpusername admin password 5 <encrypted password>. role vdc-adminip domain-lookupservice unsupported-transceiversnmp-server user admin vdc-admin auth md5 <encrypted password> priv<encrypted password> localizedkeyvrf context managementip route 0.0.0.0/0 x.26.146.1vlan 1,3vlan 99name vmconsolevlan 128-133vlan 151name asa-vdc2-Outsidevlan 161name asa-vdc1-Outsidevlan 770-771spanning-tree pathcost method longspanning-tree port type network defaultspanning-tree vlan 99,128,130,132,166,770-771 priority 28672spanning-tree vlan 129,131,133 priority 24576interface Vlan1interface Vlan3no shutdownip address 10.8.3.2/24ip ospf authentication message-digestip ospf authentication-key 3 9125d59c18a9b015ip ospf dead-interval 3ip ospf hello-interval 1ip router ospf 8 area 0.0.0.0ip pim sparse-modeip igmp version 3interface Vlan99no shutdownip address 10.8.99.2/24ip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10timers 1 3ip 10.8.99.1interface Vlan128no shutdownip address 10.8.128.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.128.1interface Vlan129no shutdownip address 10.8.129.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.129.1interface Vlan130no shutdownip address 10.8.130.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.130.1interface Vlan131no shutdownip address 10.8.131.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.131.1interface Vlan132no shutdownip address 10.8.132.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.132.1interface Vlan133no shutdownip address 10.8.133.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.133.1interface Vlan151no shutdownip address 10.8.152.2/24ip ospf authentication message-digestip ospf message-digest-key 1 md5 3 b2255cb5a7107f1bip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.152.1interface Vlan161no shutdownip address 10.8.162.2/24ip ospf authentication message-digestip ospf message-digest-key 1 md5 3 b2255cb5a7107f1bip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.162.1interface port-channel99description to dca-n7k1-vdc1switchportswitchport mode trunkswitchport trunk allowed vlan 3,50-51,99,128-133,151,161,770-771spanning-tree port type networklogging event port link-statusinterface Ethernet1/1description to dca-core2 Ten4/4ip address 10.8.2.2/24ip ospf authentication message-digestip ospf message-digest-key 1 md5 3 9125d59c18a9b015ip ospf dead-interval 3ip ospf hello-interval 1ip router ospf 8 area 0.0.0.0ip pim sparse-modeip igmp version 3no shutdowninterface Ethernet1/3description to dca-asa2 Ten5/0switchportswitchport mode trunkswitchport trunk allowed vlan 161spanning-tree port type normalno shutdowninterface Ethernet1/5description to dca-asa2 Ten7/0switchportswitchport mode trunkswitchport trunk allowed vlan 151spanning-tree port type normalno shutdowninterface Ethernet1/7no shutdowninterface Ethernet1/9interface Ethernet1/11interface Ethernet1/13description ISLswitchportswitchport mode trunkswitchport trunk allowed vlan 3,50-51,99,128-133,151,161,770-771channel-group 99 mode activeno shutdowninterface Ethernet1/15description ISLswitchportswitchport mode trunkswitchport trunk allowed vlan 3,50-51,99,128-133,151,161,770-771channel-group 99 mode activeno shutdowninterface Ethernet2/2description IXIA port 4/5switchportswitchport access vlan 129spanning-tree port type edgeno shutdowninterface Ethernet2/4description IXIA port 4/6switchportswitchport access vlan 131spanning-tree port type edgeno shutdowninterface Ethernet2/6description IXIA port 4/7switchportswitchport access vlan 133spanning-tree port type edgeno shutdowninterface Ethernet2/8description IXIA port 4/8interface mgmt0ip address x.26.146.202/23clock timezone EDT -5 0clock summer-time EDT 3 Sun Mar 00:00 3 Sunday Oct 00:00 60cli alias name save copy runn startline consoleterminal length 0router ospf 8router-id 3.3.3.2area 81 nssadefault-information originatearea 0.0.0.0 range 10.8.0.0/24area 0.0.0.0 range 10.8.1.0/24area 0.0.0.0 range 10.8.2.0/24area 0.0.0.0 range 10.8.3.0/24area 0.0.0.81 range 10.8.128.0/18area 0.0.0.0 authentication message-digestarea 0.0.0.81 authentication message-digesttimers throttle spf 10 100 5000timers throttle lsa router 1000timers throttle lsa network 1000auto-cost reference-bandwidth 10000no ip source-routeip pim ssm range 232.0.0.0/8switchback!Running config for vdc: vdc2switchto vdc vdc2version 4.1(2)feature ospffeature pimfeature udldfeature interface-vlanfeature hsrpfeature lacplogging level monitor 7username admin password 5 <encrypted password> role vdc-adminssh key rsa 768ip domain-lookupswitchname vdc2system default switchportlogging event link-status defaultlogging event trunk-status defaultservice unsupported-transceiversnmp-server user admin vdc-admin auth md5 <encrypted password> priv<encrypted password> localizedkeyvrf context erspanvrf context servers1ip route 0.0.0.0/0 10.8.162.1vrf context servers2ip route 0.0.0.0/0 10.8.152.1vrf context managementip route 0.0.0.0/0 x.26.146.1vlan 1vlan 15name vmkernelvlan 50-51vlan 98name serviceconsolevlan 141-142,152-153,162-164,166-169vlan 171name failovervlan 172name statevlan 180-183vlan 191name waasvlan 200name Mike-Server-1vlan 201name Mike-Server-2vlan 202name Mike-Server-3vlan 300-399,999vlan 3000name erspanvlan 3001name erspan-ss1vlan 3002name vemcontrolvlan 3003name vempacketspanning-tree pathcost method longspanning-tree port type network defaultspanning-tree vlan 1,15,98,142,166,168,180,182,200-202,300-399,3000,3002-3003 priority 28672spanning-tree vlan 50-51,167,169,181,183 priority 24576interface Vlan1interface Vlan15no shutdownvrf member servers1ip address 10.8.15.2/24ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10timers 1 3ip 10.8.15.1interface Vlan50no shutdownvrf member servers2ip address 10.8.50.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.50.1interface Vlan51no shutdownvrf member servers2ip address 10.8.51.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.51.1interface Vlan98no shutdownvrf member servers1ip address 10.8.98.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20timers 1 3ip 10.8.98.1interface Vlan141vrf member servers1ip address 10.8.141.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.141.1interface Vlan152no shutdownvrf member servers2ip address 10.8.152.6/24ip ospf authentication message-digestip ospf message-digest-key 1 md5 3 b2255cb5a7107f1bip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 2authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.152.7interface Vlan153vrf member servers2ip address 10.8.152.6/24ip ospf authentication message-digestip ospf message-digest-key 1 md5 3 b2255cb5a7107f1bip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 2authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.152.7interface Vlan164no shutdownvrf member servers1ip address 10.8.162.6/24ip ospf authentication message-digestip ospf message-digest-key 1 md5 3 b2255cb5a7107f1bip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 2authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.162.7interface Vlan166no shutdownvrf member servers1ip address 10.8.166.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.166.1interface Vlan167no shutdownvrf member servers2ip address 10.8.167.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.167.1interface Vlan168no shutdownvrf member servers1ip address 10.8.168.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.168.1interface Vlan169no shutdownvrf member servers2ip address 10.8.169.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.169.1interface Vlan180no shutdownvrf member servers1ip address 10.8.180.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.180.1interface Vlan181no shutdownvrf member servers2ip address 10.8.181.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.181.1interface Vlan182no shutdownvrf member servers1ip address 10.8.182.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.182.1interface Vlan183no shutdownvrf member servers2ip address 10.8.183.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 180priority 20 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.183.1interface Vlan200no shutdownvrf member servers2ip address 10.8.200.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 600 reload 300priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.200.1interface Vlan201no shutdownvrf member servers2ip address 10.8.201.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 600 reload 300priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.201.1interface Vlan202no shutdownvrf member servers2ip address 10.8.202.2/24ip ospf passive-interfaceip router ospf 8 area 0.0.0.81ip pim sparse-modeip igmp version 3hsrp 1authentication text c1sc0preempt delay minimum 600 reload 300priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.202.1interface Vlan3000no shutdownip address 10.8.3.2/24hsrp 1authentication text c1sc0preempt delay minimum 180priority 10 forwarding-threshold lower 0 upper 0timers 1 3ip 10.8.3.1interface Vlan3001no shutdownip address 10.8.33.2/24interface port-channel8description to vbsswitchport mode trunkswitchport trunk allowed vlan 180-183spanning-tree port type normalspanning-tree guard rootlogging event port link-statuslogging event port trunk-statusinterface port-channel72switchport mode trunkswitchport trunk allowed vlan 15,142,180-183,300-399,3002-3003spanning-tree port type networkspanning-tree guard rootlogging event port link-statuslogging event port trunk-statusinterface port-channel99description ISL to dca-n7k1-vdc1switchport mode trunkswitchport trunk allowed vlan 15,50-51,98,141-142,152-153,162-164switchport trunk allowed vlan add 166-169,171-172,180-183,191,200-202switchport trunk allowed vlan add 300-399,999,3000-3003spanning-tree cost 500spanning-tree port type networklogging event port link-statusinterface port-channel201switchport mode trunkswitchport trunk allowed vlan 200-202spanning-tree port type networklogging event port link-statuslogging event port trunk-statusinterface Ethernet1/2description E1/2 to dca-newSS1 T1/1switchport mode trunkswitchport trunk allowed vlan 152-153,162-164,191,999,3001spanning-tree port type networkspanning-tree guard loopmtu 9216logging event port link-statuslogging event port trunk-statusinterface Ethernet1/4description E1/4 to dca-newSS2 T1/2switchport mode trunkswitchport trunk allowed vlan 152-153,162-164,191,999,3001spanning-tree port type networkspanning-tree guard loopmtu 9216logging event port link-statuslogging event port trunk-statusinterface Ethernet1/6description to dc10-5020-5switchport mode trunkswitchport trunk allowed vlan 200-202logging event port link-statuslogging event port trunk-statusudld enablechannel-group 201 mode activeinterface Ethernet1/8description to dc10-5020-6switchport mode trunkswitchport trunk allowed vlan 200-202spanning-tree port type networkspanning-tree guard looplogging event port link-statuslogging event port trunk-statusudld enableinterface Ethernet1/10description to dca-asa2 Ten5/1switchport mode trunkswitchport trunk allowed vlan 162spanning-tree port type normalinterface Ethernet1/12description to dca-asa2 Ten7/1switchport mode trunkswitchport trunk allowed vlan 152spanning-tree port type normalinterface Ethernet1/14description ISLswitchport mode trunkswitchport trunk allowed vlan 15,50-51,98,141-142,152-153,162-164switchport trunk allowed vlan add 166-169,171-172,180-183,191,200-202switchport trunk allowed vlan add 300-399,999,3000-3003channel-group 99 mode activeinterface Ethernet1/16description ISLswitchport mode trunkswitchport trunk allowed vlan 15,50-51,98,141-142,152-153,162-164switchport trunk allowed vlan add 166-169,171-172,180-183,191,200-202switchport trunk allowed vlan add 300-399,999,3000-3003channel-group 99 mode activeinterface Ethernet1/17description dc20-4948-1switchport mode trunkswitchport trunk allowed vlan 50-51,142spanning-tree port type normalspanning-tree guard rootinterface Ethernet1/18description dc07-3120-vbs Ten4/0/2switchport mode trunkswitchport trunk allowed vlan 180-183spanning-tree port type normalspanning-tree guard rootchannel-group 8 mode activeinterface Ethernet1/19description dc20-4948-2switchport mode trunkswitchport trunk allowed vlan 50-51,142spanning-tree port type normalspanning-tree guard rootinterface Ethernet1/20description dc07-3120-vbs Ten2/0/2switchport mode trunkswitchport trunk allowed vlan 180-183spanning-tree port type normalspanning-tree guard rootchannel-group 8 mode activeinterface Ethernet1/21interface Ethernet1/22switchport mode trunkswitchport trunk allowed vlan 200-202logging event port link-statuslogging event port trunk-statusudld enablechannel-group 201 mode activeinterface Ethernet1/23interface Ethernet1/24interface Ethernet1/25description dca-vss-accswitchport mode trunkswitchport trunk allowed vlan 15,142,180-183,300-399,3002-3003spanning-tree port type networkspanning-tree guard rootchannel-group 72 mode activeinterface Ethernet1/26description dc10-5020-1switchport mode trunkswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type networkspanning-tree guard rootmtu 9216logging event port link-statuslogging event port trunk-statusinterface Ethernet1/27description dca-vss-accswitchport mode trunkswitchport trunk allowed vlan 15,142,180-183,300-399,3002-3003spanning-tree port type networkspanning-tree guard rootchannel-group 72 mode activeinterface Ethernet1/28description dc10-5020-2switchport mode trunkswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type networkspanning-tree guard rootmtu 9216logging event port link-statuslogging event port trunk-statusinterface Ethernet1/29description to 6k accessswitchport mode trunkswitchport trunk allowed vlan 128-133,164-169,180-183,300-399spanning-tree port type normalspanning-tree guard rootinterface Ethernet1/30description dc10-5020-3switchport mode trunkswitchport trunk allowed vlan 15,98,180-183spanning-tree port type networkinterface Ethernet1/31description to 6k accessswitchport mode trunkswitchport trunk allowed vlan 128-133,164-169,180-183,300-399spanning-tree port type normalspanning-tree guard rootinterface Ethernet1/32description dc10-5020-4switchport mode trunkswitchport trunk allowed vlan 15,98,180-183spanning-tree port type networkinterface Ethernet2/1switchport access vlan 172spanning-tree port type normalinterface Ethernet2/3switchport access vlan 171spanning-tree port type normalinterface Ethernet2/5spanning-tree port type normalinterface Ethernet2/7interface Ethernet2/9interface Ethernet2/10interface Ethernet2/11interface Ethernet2/12interface Ethernet2/13interface Ethernet2/14interface Ethernet2/15interface Ethernet2/16interface Ethernet2/17interface Ethernet2/18interface Ethernet2/19interface Ethernet2/20interface Ethernet2/21interface Ethernet2/22interface Ethernet2/23interface Ethernet2/24interface Ethernet2/25interface Ethernet2/26interface Ethernet2/27interface Ethernet2/28interface Ethernet2/29interface Ethernet2/30interface Ethernet2/31interface Ethernet2/32interface Ethernet2/33interface Ethernet2/34interface Ethernet2/35interface Ethernet2/36interface Ethernet2/37description ASA1 int g3/3switchport mode trunkswitchport trunk allowed vlan 142spanning-tree port type normallogging event port link-statuslogging event port trunk-statusinterface Ethernet2/38description ASA int g3/2switchport mode trunkswitchport trunk allowed vlan 141spanning-tree port type normallogging event port link-statuslogging event port trunk-statusinterface Ethernet2/39interface Ethernet2/40interface Ethernet2/41interface Ethernet2/42interface Ethernet2/43interface Ethernet2/44interface Ethernet2/45interface Ethernet2/46interface Ethernet2/47interface Ethernet2/48interface mgmt0ip address x.26.146.203/23interface loopback88vrf member testclock timezone EDT -5 0clock summer-time EDT 3 Sun Mar 00:00 3 Sunday Oct 00:00 60cli alias name save copy runn startline consoleterminal length 0router ospf 8vrf servers1router-id 4.4.4.2area 81 nssaarea 0.0.0.81 authentication message-digesttimers throttle spf 10 100 5000timers throttle lsa router 1000timers throttle lsa network 1000vrf servers2router-id 5.5.5.2area 81 nssaarea 0.0.0.81 authentication message-digesttimers throttle spf 10 100 5000timers throttle lsa router 1000timers throttle lsa network 1000ip pim rp-address 10.8.20.1 group-list 224.0.0.0/4ip pim ssm range 232.0.0.0/8no system default switchport shutdownswitchbackdca-n7k2#Services Layer Switch—Catalyst 6500
Service Switch 1
dca-newSS1#sh runBuilding configuration...Current configuration : 20243 bytes!! Last configuration change at 03:21:52 EST Fri May 1 2009 by chris! NVRAM config last updated at 00:05:07 EST Thu May 14 2009!upgrade fpd autoversion 12.2no service padservice tcp-keepalives-inservice timestamps debug datetime msec localtime show-timezoneservice timestamps log datetime msec localtime show-timezoneservice password-encryptionservice counters max age 5!hostname dca-newSS1!boot-start-markerboot system flash bootflash:s72033-adventerprisek9_wan-mz.122-33.SXI.binboot-end-marker!enable secret 5 <encrypted password>!username admin privilege 15 secret 5 <encrypted password>username dma-ops password 7 <encrypted password>username chris-ops password 7 <encrypted password>username martin password 7 <encrypted password>aaa new-model!!aaa group server tacacs+ tacacs-groupserver x.26.191.94!aaa authentication login authen-exec-list group tacacs-group local-caseaaa authentication enable default group tacacs-group enableaaa authorization exec author-exec-list group tacacs-group if-authenticatedaaa authorization commands 15 author-15-list group tacacs-group noneaaa accounting send stop-record authentication failureaaa accounting exec default start-stop group tacacs-groupaaa accounting commands 15 default start-stop group tacacs-groupaaa accounting system default start-stop group tacacs-group!!!aaa session-id commonclock timezone EST -5clock summer-time EST recurringsvclc autostatesvclc multiple-vlan-interfacessvclc module 7 vlan-group 1svclc module 8 vlan-group 1,2,150,160,190,999svclc vlan-group 1 146svclc vlan-group 2 170svclc vlan-group 150 152,153svclc vlan-group 160 162,163svclc vlan-group 190 190,191svclc vlan-group 999 999firewall autostatefirewall multiple-vlan-interfacesfirewall module 7 vlan-group 1analysis module 9 management-port access-vlan 146ip subnet-zerono ip source-route!!!ip ftp source-interface Vlan146ip ftp username chrobrieip ftp password 7 <encrypted password>no ip bootp serverip ssh authentication-retries 2ip ssh logging eventsip ssh version 2ip scp server enableip domain-name cisco.comip name-server x.26.129.252login block-for 100 attempts 5 within 50login quiet-mode access-class 10login on-failure logvtp mode transparentmls ip slb purge globalmls netflow interfacemls flow ip interface-fullno mls flow ipv6mls nde sender version 5mls qosmls cef error action reset!!!!!!!!!archivepath ftp://test:test@x.26.129.252/NexusDCPhase1/$h-$twrite-memorymemory reserve critical 1000memory free low-watermark processor 91492memory free low-watermark IO 6710!spanning-tree mode rapid-pvstspanning-tree portfast network defaultspanning-tree extend system-idspanning-tree pathcost method longspanning-tree vlan 163,170-172,191,999,3001 priority 24576diagnostic bootup level minimaldiagnostic cns publish cisco.cns.device.diag_resultsdiagnostic cns subscribe cisco.cns.device.diag_commandsfabric timer 15fabric switching-mode allow truncated threshold 1fabric switching-mode allow truncatedport-channel hash-distribution adaptive!redundancymain-cpuauto-sync running-configmode sso!vlan internal allocation policy ascendingvlan access-log ratelimit 2000!vlan 146name flash!vlan 152-153,162-164,170-172!vlan 190name waflan!vlan 191name waas!vlan 999!vlan 3001name erspan!class-map match-all coppclass-igpmatch access-group name coppacl-igpclass-map match-all coppclass-monitoringmatch access-group name coppacl-monitoringclass-map match-all coppclass-filemanagementmatch access-group name coppacl-filemanagementclass-map match-all coppclass-managementmatch access-group name coppacl-management!!policy-map copp-policyclass coppclass-igppolice cir 300000 bc 3000 be 3000 conform-action transmit exceed-action drop violate-action dropclass coppclass-filemanagementpolice cir 6000000 bc 60000 be 60000 conform-action transmit exceed-action drop violate-action dropclass coppclass-managementpolice cir 500000 bc 5000 be 5000 conform-action transmit exceed-action drop violate-action dropclass coppclass-monitoringpolice cir 900000 bc 9000 be 9000 conform-action transmit exceed-action drop violate-action dropclass class-defaultpolice cir 500000 bc 5000 be 5000 conform-action transmit exceed-action drop violate-action drop!!!!!!interface Port-channel31switchportswitchport access vlan 191switchport mode accesslogging event link-statusspanning-tree portfast edge!interface Port-channel2switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 163,164switchport mode trunkswitchport nonegotiatemtu 9216!interface Port-channel99switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 170-172switchport mode trunklogging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusspanning-tree portfast network!interface GigabitEthernet3/21description <<** G3/25 to dc-waecm G2/0 **>>switchportswitchport access vlan 191switchport trunk encapsulation dot1qswitchport trunk allowed vlan 163,164switchport mode accesslogging event link-statusspanning-tree portfast edge!interface GigabitEthernet3/23description <<** G3/23 to dc-wae2 G2/0 **>>switchportswitchport access vlan 191switchport mode accesslogging event link-statusspanning-tree portfast edgechannel-group 31 mode on!interface GigabitEthernet3/24description <<** G3/23 to dc-wae1 G1/0 **>>switchportswitchport access vlan 191switchport mode accesslogging event link-statusspanning-tree portfast edgechannel-group 31 mode on!interface GigabitEthernet3/25switchportswitchport access vlan 191switchport trunk encapsulation dot1qswitchport trunk allowed vlan 163,164switchport mode trunklogging event link-statusshutdownrmon collection stats 6028 owner monitorrmon collection stats 6032 owner monitorspanning-tree portfast edge!interface TenGigabitEthernet1/1description <<** T1/1 to dca-n7k2-vdc2 **>>switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 152,153,162-164,191,999,3001switchport mode trunkmtu 9216logging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusrmon collection stats 6000 owner monitorspanning-tree portfast network!interface TenGigabitEthernet1/2description <<** T1/2 to dca-n7k1-vdc2 **>>switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 152,153,162-164,191,999,3001switchport mode trunkmtu 9216logging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusrmon collection stats 6001 owner monitorspanning-tree portfast network!interface TenGigabitEthernet1/3description to ips2switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 163,164switchport mode trunkswitchport nonegotiatemtu 9216logging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusshutdownrmon collection stats 6002 owner monitorchannel-group 2 mode on!interface TenGigabitEthernet1/4description to ips1 7/1switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 163,164switchport mode trunkswitchport nonegotiatemtu 9216logging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusrmon collection stats 6003 owner monitorchannel-group 2 mode on!interface TenGigabitEthernet1/5no ip addressrmon collection stats 6004 owner monitor!interface TenGigabitEthernet1/6no ip addressrmon collection stats 6005 owner monitor!interface TenGigabitEthernet1/7switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 170-172switchport mode trunklogging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusrmon collection stats 6006 owner monitorchannel-protocol lacpchannel-group 99 mode active!interface TenGigabitEthernet1/8switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 170-172switchport mode trunklogging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusrmon collection stats 6007 owner monitorchannel-protocol lacpchannel-group 99 mode active!interface GigabitEthernet3/1no ip addressno ip redirectsno ip proxy-arprmon collection stats 6008 owner monitor!interface GigabitEthernet3/2no ip addressno ip redirectsno ip proxy-arprmon collection stats 6009 owner monitor!interface GigabitEthernet3/3no ip addressno ip redirectsno ip proxy-arprmon collection stats 6010 owner monitor!interface GigabitEthernet3/4no ip addressno ip redirectsno ip proxy-arprmon collection stats 6011 owner monitor!interface GigabitEthernet3/5no ip addressno ip redirectsno ip proxy-arprmon collection stats 6012 owner monitor!interface GigabitEthernet3/6no ip addressno ip redirectsno ip proxy-arprmon collection stats 6013 owner monitor!interface GigabitEthernet3/7no ip addressno ip redirectsno ip proxy-arprmon collection stats 6014 owner monitor!interface GigabitEthernet3/8no ip addressno ip redirectsno ip proxy-arprmon collection stats 6015 owner monitor!interface GigabitEthernet3/9no ip addressno ip redirectsno ip proxy-arprmon collection stats 6016 owner monitor!interface GigabitEthernet3/10no ip addressno ip redirectsno ip proxy-arprmon collection stats 6017 owner monitor!interface GigabitEthernet3/11no ip addressno ip redirectsno ip proxy-arprmon collection stats 6018 owner monitor!interface GigabitEthernet3/12description to waf2 eth3switchportswitchport access vlan 190switchport mode accessrmon collection stats 6019 owner monitorspanning-tree portfast edge!interface GigabitEthernet3/13no ip addressno ip redirectsno ip proxy-arprmon collection stats 6020 owner monitor!interface GigabitEthernet3/14description to waf1 eth3switchportswitchport access vlan 190switchport mode accessrmon collection stats 6021 owner monitorspanning-tree portfast edge!interface GigabitEthernet3/15no ip addressno ip redirectsno ip proxy-arprmon collection stats 6022 owner monitor!interface GigabitEthernet3/16no ip addressno ip redirectsno ip proxy-arprmon collection stats 6023 owner monitor!interface GigabitEthernet3/17no ip addressno ip redirectsno ip proxy-arprmon collection stats 6024 owner monitor!interface GigabitEthernet3/18no ip addressno ip redirectsno ip proxy-arprmon collection stats 6025 owner monitor!interface GigabitEthernet3/19no ip addressno ip redirectsno ip proxy-arprmon collection stats 6026 owner monitor!interface GigabitEthernet3/20no ip addressno ip redirectsno ip proxy-arprmon collection stats 6027 owner monitor!interface GigabitEthernet3/22no ip addressno ip redirectsno ip proxy-arprmon collection stats 6029 owner monitor!interface GigabitEthernet3/26description to IPS1 gig 3/3switchportswitchport trunk encapsulation dot1qswitchport mode trunklogging event link-statuslogging event trunk-statusload-interval 30rmon collection stats 6033 owner monitorspanning-tree portfast edge trunk!interface GigabitEthernet3/27no ip addressno ip redirectsno ip proxy-arprmon collection stats 6034 owner monitor!interface GigabitEthernet3/28no ip addressno ip redirectsno ip proxy-arprmon collection stats 6035 owner monitor!interface GigabitEthernet3/29no ip addressno ip redirectsno ip proxy-arprmon collection stats 6036 owner monitor!interface GigabitEthernet3/30no ip addressno ip redirectsno ip proxy-arprmon collection stats 6037 owner monitor!interface GigabitEthernet3/31no ip addressno ip redirectsno ip proxy-arprmon collection stats 6038 owner monitor!interface GigabitEthernet3/32no ip addressno ip redirectsno ip proxy-arprmon collection stats 6039 owner monitor!interface GigabitEthernet3/33no ip addressno ip redirectsno ip proxy-arprmon collection stats 6040 owner monitor!interface GigabitEthernet3/34no ip addressno ip redirectsno ip proxy-arprmon collection stats 6041 owner monitor!interface GigabitEthernet3/35no ip addressno ip redirectsno ip proxy-arprmon collection stats 6042 owner monitor!interface GigabitEthernet3/36no ip addressno ip redirectsno ip proxy-arprmon collection stats 6043 owner monitor!interface GigabitEthernet3/37switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 163,164switchport mode trunkshutdownrmon collection stats 6044 owner monitor!interface GigabitEthernet3/38no ip addressno ip redirectsno ip proxy-arprmon collection stats 6045 owner monitor!interface GigabitEthernet3/39no ip addressno ip redirectsno ip proxy-arprmon collection stats 6046 owner monitor!interface GigabitEthernet3/40no ip addressno ip redirectsno ip proxy-arprmon collection stats 6047 owner monitor!interface GigabitEthernet3/41no ip addressno ip redirectsno ip proxy-arprmon collection stats 6048 owner monitor!interface GigabitEthernet3/42no ip addressno ip redirectsno ip proxy-arprmon collection stats 6049 owner monitor!interface GigabitEthernet3/43no ip addressno ip redirectsno ip proxy-arprmon collection stats 6050 owner monitor!interface GigabitEthernet3/44no ip addressno ip redirectsno ip proxy-arprmon collection stats 6051 owner monitor!interface GigabitEthernet3/45no ip addressno ip redirectsno ip proxy-arprmon collection stats 6052 owner monitor!interface GigabitEthernet3/46no ip addressno ip redirectsno ip proxy-arprmon collection stats 6053 owner monitor!interface GigabitEthernet3/47no ip addressno ip redirectsno ip proxy-arprmon collection stats 6054 owner monitor!interface GigabitEthernet3/48switchportswitchport access vlan 4000switchport mode accesslogging event link-statuslogging event spanning-tree statusshutdownrmon collection stats 6055 owner monitorspanning-tree portfast edge trunk!interface GigabitEthernet5/1description <<** to mgmt net **>>switchportswitchport access vlan 146switchport mode accesslogging event link-statuslogging event spanning-tree statusudld portrmon collection stats 6056 owner monitor!interface GigabitEthernet5/2no ip addressrmon collection stats 6057 owner monitor!interface GigabitEthernet5/3description To Mgmt Netno ip addressspeed 1000duplex fullrmon collection stats 6058 owner monitor!interface TenGigabitEthernet5/4no ip addressrmon collection stats 6059 owner monitor!interface TenGigabitEthernet5/5no ip addressrmon collection stats 6060 owner monitor!interface Vlan191ip address 10.8.191.191 255.255.255.0ntp broadcast!interface Vlan1no ip addressshutdown!interface Vlan146ip address x.26.147.209 255.255.254.0ip access-group 133 inip access-group 134 outip flow ingress!interface Vlan3001mtu 9216ip address 10.8.33.4 255.255.255.0load-interval 30!ip classlessip route 0.0.0.0 0.0.0.0 x.26.146.1ip route 10.8.0.0 255.255.0.0 10.8.33.2ip route 10.8.0.0 255.255.0.0 10.8.33.3!ip flow-export destination x.26.147.230 3000!ip http serverip http authentication localno ip http secure-serverip http path disk0:ip tacacs source-interface Vlan146!ip access-list extended coppacl-monitoringremark CoPP monitoring traffic classpermit icmp any any ttl-exceededpermit icmp any any port-unreachablepermit icmp any any echo-replypermit icmp any any echoip access-list extended dmapermit ip any host 10.8.180.153!kron occurrence daily-config-backup at 0:05 recurringpolicy-list backup-config!kron policy-list backup-configcli write memory!logging trap criticallogging source-interface GigabitEthernet5/3logging x.26.191.94access-list 10 permit x.26.191.92access-list 10 remark a 100-second quiet period if 5 failed login attempts is exceededaccess-list 111 remark ACL for SSHaccess-list 111 permit tcp x.26.0.0 0.0.255.255 any eq 22access-list 111 deny ip any any log-inputaccess-list 112 remark ACL for last resort accessaccess-list 112 permit tcp host x.26.191.92 any eq 22access-list 112 deny ip any any log-inputaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.147.209 ttl-exceededaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.147.209 port-unreachableaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.147.209 echo-replyaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.147.209 echoaccess-list 133 permit tcp x.26.0.0 0.0.255.255 eq tacacs host x.26.147.209 establishedaccess-list 133 permit tcp x.26.0.0 0.0.255.255 host x.26.147.209 eq tacacsaccess-list 133 permit udp x.26.0.0 0.0.255.255 host x.26.147.209 eq ntpaccess-list 133 permit tcp x.26.0.0 0.0.255.255 host x.26.147.209 eq 22access-list 133 permit tcp x.26.0.0 0.0.255.255 eq ftp host x.26.147.209 gt 1023 establishedaccess-list 133 permit tcp x.26.0.0 0.0.255.255 eq ftp-data host x.26.147.209 gt 1023access-list 133 permit tcp x.26.0.0 0.0.255.255 gt 1023 host x.26.147.209 gt 1023 establishedaccess-list 133 permit udp x.26.0.0 0.0.255.255 gt 1023 host x.26.147.209 gt 1023access-list 134 permit ip host x.26.147.209 x.26.0.0 0.0.255.255access-list 134 deny ip any any log!!!!snmp-server engineID local 8000000903000021D72AC000snmp-server enable traps cpu thresholdsnmp-server host x.26.191.94 public cputacacs-server host x.26.191.94 single-connection key 7 01100F175804575D72tacacs-server directed-request!!control-planeservice-policy input copp-policy!!dial-peer cor custom!!!banner login ^CUNAUTHORIZED ACCESS TO THIS DEVICE IS PROHIBITEDYou must have explicit, authorized permission to access or configure this device.Unauthorized attempts and actions to access or use this system may result in civil and/or criminal penalties.All activities performed on this device are logged and monitored.^C!line con 0login authentication authen-exec-listline vty 0 3exec-timeout 180 0password 7 <encrypted password>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listtransport preferred nonetransport input alltransport output noneline vty 4exec-timeout 180 0password 7 <encrypted password>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listtransport preferred nonetransport input alltransport output noneline vty 5 15login authentication authen-exec-listno exectransport input all!exception protocol ftpexception dump x.26.129.252!monitor session 1 type erspan-sourcedescription <** N1k ERSPAN - originating from dcesx4n1 monitor session 1 **>>source vlan 3001destinationerspan-id 1ip address 10.8.33.4!!monitor session 2 type erspan-sourcedescription <** N1k ERSPAN - originating from dcesx4n1 monitor session 2 **>>source vlan 3001destinationerspan-id 2ip address 10.8.33.4!!monitor session 3 type erspan-destinationdescription <** N1k ERSPAN to NAM - originating from dcesx4n1 **>>destination analysis-module 9 data-port 2sourceerspan-id 1ip address 10.8.33.4!!monitor session 4 type erspan-destinationdescription <** N1k ERSPAN to IDS-1 - originating from dcesx4n1 **>>destination interface Gi3/26sourceerspan-id 2ip address 10.8.33.4!!process cpu threshold type total rising 80 interval 5 falling 20 interval 5process cpu statistics limit entry-percentage 40 size 300ntp clock-period 17179890ntp server x.26.146.1mac-address-table aging-time 480!enddca-newSS1#Service Switch 2dca-newSS2>enPassword:dca-newSS2#sh runBuilding configuration...Current configuration : 18580 bytes!! Last configuration change at 12:08:19 EST Wed Mar 25 2009 by chris! NVRAM config last updated at 00:05:29 EST Thu May 14 2009!upgrade fpd autoversion 12.2no service padservice tcp-keepalives-inservice timestamps debug datetime msec localtime show-timezoneservice timestamps log datetime msec localtime show-timezoneservice password-encryptionservice counters max age 5!hostname dca-newSS2!boot-start-markerboot system flash bootflash:s72033-adventerprisek9_wan-mz.122-33.SXI.binboot-end-marker!enable secret 5 <encrypted password>!username admin privilege 15 secret 5 <encrypted password>aaa new-model!!aaa group server tacacs+ tacacs-groupserver x.26.191.94!aaa authentication login authen-exec-list group tacacs-group local-caseaaa authentication enable default group tacacs-group enableaaa authorization exec author-exec-list group tacacs-group if-authenticatedaaa authorization commands 15 author-15-list group tacacs-group noneaaa accounting send stop-record authentication failureaaa accounting exec default start-stop group tacacs-groupaaa accounting commands 15 default start-stop group tacacs-groupaaa accounting system default start-stop group tacacs-group!!!aaa session-id commonclock timezone EST -5clock summer-time EST recurringsvclc autostatesvclc multiple-vlan-interfacessvclc module 7 vlan-group 1svclc module 8 vlan-group 1,2,150,160,190,999svclc vlan-group 1 146svclc vlan-group 2 170svclc vlan-group 150 152,153svclc vlan-group 160 162,163svclc vlan-group 190 190,191svclc vlan-group 999 999firewall autostatefirewall multiple-vlan-interfacesfirewall module 7 vlan-group 1analysis module 9 management-port access-vlan 146ip subnet-zerono ip source-route!!!ip ftp source-interface GigabitEthernet5/3ip ftp username anonymousip ftp password 7 <encrypted password>no ip bootp serverip ssh authentication-retries 2ip ssh version 2no ip domain-lookupip domain-name cisco.comip name-server x.26.129.252login block-for 100 attempts 5 within 50login quiet-mode access-class 10login on-failure logvtp mode transparentmls ip slb purge globalmls netflow interfaceno mls flow ipno mls flow ipv6mls cef error action reset!!!!!!!!!archivepath ftp://test:test@x.26.129.252/NexusDCPhase1/$h-$twrite-memorymemory reserve critical 1000memory free low-watermark processor 91492memory free low-watermark IO 6710!spanning-tree mode rapid-pvstspanning-tree portfast network defaultspanning-tree extend system-idspanning-tree pathcost method longspanning-tree vlan 153 priority 24576spanning-tree vlan 163,170-172,191,999 priority 28672diagnostic bootup level minimaldiagnostic cns publish cisco.cns.device.diag_resultsdiagnostic cns subscribe cisco.cns.device.diag_commandsfabric timer 15fabric switching-mode allow truncated threshold 1fabric switching-mode allow truncatedport-channel hash-distribution adaptive!redundancymain-cpuauto-sync running-configmode sso!vlan internal allocation policy ascendingvlan access-log ratelimit 2000!vlan 146name flash!vlan 152-153,162-164,170-172!vlan 190name waf!vlan 191name waas!vlan 999!vlan 3001name erspan!!!!!interface Port-channel32switchportswitchport access vlan 191switchport mode accesslogging event link-statusspanning-tree portfast edge!interface Port-channel2switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 163,164switchport mode trunkswitchport nonegotiatemtu 9216!interface Port-channel99switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 170-172switchport mode trunklogging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusspanning-tree portfast network!interface GigabitEthernet3/23description <<** G3/23 to dca-wae2 G1/0 **>>switchportswitchport access vlan 191switchport mode accesslogging event link-statusspanning-tree portfast edgechannel-group 32 mode on!interface GigabitEthernet3/24description <<** G3/24 to dc-wae1 G2/0 **>>switchportswitchport access vlan 191switchport mode accesslogging event link-statusspanning-tree portfast edgechannel-group 32 mode on!interface TenGigabitEthernet1/1description <<** T1/1 to dca-n7k1-vdc2 **>>switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 152,153,162-164,191,999,3001switchport mode trunkmtu 9216logging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusrmon collection stats 6000 owner monitorspanning-tree portfast network!interface TenGigabitEthernet1/2description <<** T1/2 to dca-n7k2-vdc2 **>>switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 152,153,162-164,191,999,3001switchport mode trunkmtu 9216logging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusrmon collection stats 6001 owner monitorspanning-tree portfast network!interface TenGigabitEthernet1/3description to ips2switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 163,164switchport mode trunkswitchport nonegotiatemtu 9216logging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusrmon collection stats 6002 owner monitorchannel-group 2 mode on!interface TenGigabitEthernet1/4description to ips1 7/0switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 163,164switchport mode trunkswitchport nonegotiatemtu 9216logging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusshutdownrmon collection stats 6003 owner monitorchannel-group 2 mode on!interface TenGigabitEthernet1/5no ip addressrmon collection stats 6004 owner monitor!interface TenGigabitEthernet1/6no ip addressrmon collection stats 6005 owner monitor!interface TenGigabitEthernet1/7switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 170-172switchport mode trunklogging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusrmon collection stats 6006 owner monitorspanning-tree portfast networkchannel-protocol lacpchannel-group 99 mode active!interface TenGigabitEthernet1/8switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 170-172switchport mode trunklogging event link-statuslogging event trunk-statuslogging event bundle-statuslogging event spanning-tree statusrmon collection stats 6007 owner monitorspanning-tree portfast networkchannel-protocol lacpchannel-group 99 mode active!interface GigabitEthernet3/1no ip addressno ip redirectsno ip proxy-arprmon collection stats 6008 owner monitor!interface GigabitEthernet3/2no ip addressno ip redirectsno ip proxy-arprmon collection stats 6009 owner monitor!interface GigabitEthernet3/3no ip addressno ip redirectsno ip proxy-arprmon collection stats 6010 owner monitor!interface GigabitEthernet3/4no ip addressno ip redirectsno ip proxy-arprmon collection stats 6011 owner monitor!interface GigabitEthernet3/5no ip addressno ip redirectsno ip proxy-arprmon collection stats 6012 owner monitor!interface GigabitEthernet3/6no ip addressno ip redirectsno ip proxy-arprmon collection stats 6013 owner monitor!interface GigabitEthernet3/7no ip addressno ip redirectsno ip proxy-arprmon collection stats 6014 owner monitor!interface GigabitEthernet3/8no ip addressno ip redirectsno ip proxy-arprmon collection stats 6015 owner monitor!interface GigabitEthernet3/9no ip addressno ip redirectsno ip proxy-arprmon collection stats 6016 owner monitor!interface GigabitEthernet3/10no ip addressno ip redirectsno ip proxy-arprmon collection stats 6017 owner monitor!interface GigabitEthernet3/11no ip addressno ip redirectsno ip proxy-arprmon collection stats 6018 owner monitor!interface GigabitEthernet3/12no ip addressno ip redirectsno ip proxy-arprmon collection stats 6019 owner monitor!interface GigabitEthernet3/13no ip addressno ip redirectsno ip proxy-arprmon collection stats 6020 owner monitor!interface GigabitEthernet3/14no ip addressno ip redirectsno ip proxy-arprmon collection stats 6021 owner monitor!interface GigabitEthernet3/15no ip addressno ip redirectsno ip proxy-arprmon collection stats 6022 owner monitor!interface GigabitEthernet3/16no ip addressno ip redirectsno ip proxy-arprmon collection stats 6023 owner monitor!interface GigabitEthernet3/17no ip addressno ip redirectsno ip proxy-arprmon collection stats 6024 owner monitor!interface GigabitEthernet3/18no ip addressno ip redirectsno ip proxy-arprmon collection stats 6025 owner monitor!interface GigabitEthernet3/19no ip addressno ip redirectsno ip proxy-arprmon collection stats 6026 owner monitor!interface GigabitEthernet3/20no ip addressno ip redirectsno ip proxy-arprmon collection stats 6027 owner monitor!interface GigabitEthernet3/21no ip addressno ip redirectsno ip proxy-arprmon collection stats 6028 owner monitor!interface GigabitEthernet3/22no ip addressno ip redirectsno ip proxy-arprmon collection stats 6029 owner monitor!interface GigabitEthernet3/25no ip addressno ip redirectsno ip proxy-arprmon collection stats 6032 owner monitor!interface GigabitEthernet3/26no ip addressno ip redirectsno ip proxy-arprmon collection stats 6033 owner monitor!interface GigabitEthernet3/27no ip addressno ip redirectsno ip proxy-arprmon collection stats 6034 owner monitor!interface GigabitEthernet3/28no ip addressno ip redirectsno ip proxy-arprmon collection stats 6035 owner monitor!interface GigabitEthernet3/29no ip addressno ip redirectsno ip proxy-arprmon collection stats 6036 owner monitor!interface GigabitEthernet3/30no ip addressno ip redirectsno ip proxy-arprmon collection stats 6037 owner monitor!interface GigabitEthernet3/31no ip addressno ip redirectsno ip proxy-arprmon collection stats 6038 owner monitor!interface GigabitEthernet3/32no ip addressno ip redirectsno ip proxy-arprmon collection stats 6039 owner monitor!interface GigabitEthernet3/33no ip addressno ip redirectsno ip proxy-arprmon collection stats 6040 owner monitor!interface GigabitEthernet3/34no ip addressno ip redirectsno ip proxy-arprmon collection stats 6041 owner monitor!interface GigabitEthernet3/35no ip addressno ip redirectsno ip proxy-arprmon collection stats 6042 owner monitor!interface GigabitEthernet3/36no ip addressno ip redirectsno ip proxy-arprmon collection stats 6043 owner monitor!interface GigabitEthernet3/37no ip addressno ip redirectsno ip proxy-arprmon collection stats 6044 owner monitor!interface GigabitEthernet3/38no ip addressno ip redirectsno ip proxy-arprmon collection stats 6045 owner monitor!interface GigabitEthernet3/39no ip addressno ip redirectsno ip proxy-arprmon collection stats 6046 owner monitor!interface GigabitEthernet3/40no ip addressno ip redirectsno ip proxy-arprmon collection stats 6047 owner monitor!interface GigabitEthernet3/41no ip addressno ip redirectsno ip proxy-arprmon collection stats 6048 owner monitor!interface GigabitEthernet3/42no ip addressno ip redirectsno ip proxy-arprmon collection stats 6049 owner monitor!interface GigabitEthernet3/43no ip addressno ip redirectsno ip proxy-arprmon collection stats 6050 owner monitor!interface GigabitEthernet3/44no ip addressno ip redirectsno ip proxy-arprmon collection stats 6051 owner monitor!interface GigabitEthernet3/45no ip addressno ip redirectsno ip proxy-arprmon collection stats 6052 owner monitor!interface GigabitEthernet3/46no ip addressno ip redirectsno ip proxy-arprmon collection stats 6053 owner monitor!interface GigabitEthernet3/47no ip addressno ip redirectsno ip proxy-arprmon collection stats 6054 owner monitor!interface GigabitEthernet3/48no ip addressno ip redirectsno ip proxy-arprmon collection stats 6055 owner monitor!interface GigabitEthernet5/1no ip addressshutdownrmon collection stats 6056 owner monitor!interface GigabitEthernet5/2no ip addressshutdownrmon collection stats 6057 owner monitor!interface GigabitEthernet5/3switchportswitchport access vlan 146switchport mode accessspeed 1000duplex fullrmon collection stats 6058 owner monitor!interface TenGigabitEthernet5/4no ip addressshutdownrmon collection stats 6059 owner monitor!interface TenGigabitEthernet5/5no ip addressshutdownrmon collection stats 6060 owner monitor!interface Vlan1no ip addressshutdown!interface Vlan146ip address x.26.147.210 255.255.254.0ip access-group 133 inip access-group 134 out!interface Vlan3001mtu 9216ip address 10.8.33.5 255.255.255.0!ip classlessip route 0.0.0.0 0.0.0.0 x.26.146.1ip route 10.8.0.0 255.255.0.0 10.8.33.2ip route 10.8.0.0 255.255.0.0 10.8.33.3!!no ip http serverno ip http secure-serverip tacacs source-interface GigabitEthernet5/3!ip access-list extended coppacl-filemanagementremark CoPP File transfer traffic classpermit tcp x.26.0.0 0.0.255.255 eq ftp host x.26.146.210 gt 1023 establishedpermit tcp x.26.0.0 0.0.255.255 eq ftp-data host x.26.146.210 gt 1023permit tcp x.26.0.0 0.0.255.255 gt 1023 host x.26.146.210 gt 1023 establishedpermit udp x.26.0.0 0.0.255.255 gt 1023 host x.26.146.210 gt 1023ip access-list extended coppacl-managementremark CoPP management traffic classpermit tcp x.26.0.0 0.0.255.255 eq tacacs host x.26.146.210 establishedpermit tcp x.26.0.0 0.0.255.255 host x.26.146.210 eq 22permit tcp x.26.0.0 0.0.255.255 host x.26.146.210 eq telnetpermit udp x.26.0.0 0.0.255.255 host x.26.146.210 eq snmppermit udp x.26.0.0 0.0.255.255 host x.26.146.210 eq ntp!kron occurrence daily-config-backup at 0:05 recurringpolicy-list backup-config!kron policy-list backup-configcli write memory!logging trap criticallogging source-interface GigabitEthernet5/3logging x.26.191.94access-list 10 permit x.26.191.92access-list 10 remark a 100-second quiet period if 5 failed login attempts is exceededaccess-list 111 remark ACL for SSHaccess-list 111 permit tcp x.26.0.0 0.0.255.255 any eq 22access-list 111 deny ip any any log-inputaccess-list 112 remark ACL for last resort accessaccess-list 112 permit tcp host x.26.191.92 any eq 22access-list 112 deny ip any any log-inputaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.147.210 ttl-exceededaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.147.210 port-unreachableaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.147.210 echo-replyaccess-list 133 permit icmp x.26.0.0 0.0.255.255 host x.26.147.210 echoaccess-list 133 permit tcp x.26.0.0 0.0.255.255 eq tacacs host x.26.147.210 establishedaccess-list 133 permit tcp x.26.0.0 0.0.255.255 host x.26.147.210 eq tacacsaccess-list 133 permit udp x.26.0.0 0.0.255.255 host x.26.147.210 eq ntpaccess-list 133 permit tcp x.26.0.0 0.0.255.255 host x.26.147.210 eq 22access-list 133 permit tcp x.26.0.0 0.0.255.255 eq ftp host x.26.147.210 gt 1023 establishedaccess-list 133 permit tcp x.26.0.0 0.0.255.255 eq ftp-data host x.26.147.210 gt 1023access-list 133 permit tcp x.26.0.0 0.0.255.255 gt 1023 host x.26.147.210 gt 1023 establishedaccess-list 133 permit udp x.26.0.0 0.0.255.255 gt 1023 host x.26.147.210 gt 1023access-list 134 permit ip host x.26.147.210 x.26.0.0 0.0.255.255access-list 134 deny ip any any log!!!!snmp-server engineID local 8000000903000021D72C4400snmp-server enable traps cpu thresholdsnmp-server host x.26.191.94 public cputacacs-server host x.26.191.94 single-connection key 7 104D000A061843595Ftacacs-server directed-request!!control-plane!!dial-peer cor custom!!!banner login ^C UNAUTHORIZED ACCESS TO THIS DEVICE IS PROHIBITEDYou must have explicit, authorized permission to access or configure this device.Unauthorized attempts and actions to access or use this system may result in civil and/or criminal penalties.All activities performed on this device are logged and monitored.^C!line con 0login authentication authen-exec-listline vty 0 3access-class 111 inexec-timeout 0 0password 7 <encrypted password>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listtransport preferred nonetransport input sshtransport output noneline vty 4access-class 112 inexec-timeout 0 0password 7 <encrypted password>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listtransport preferred nonetransport input sshtransport output noneline vty 5 15exec-timeout 0 0transport input lat pad udptn telnet rlogin ssh!exception protocol ftpexception dump x.26.129.252!monitor session 1 type erspan-sourceshutdowndescription <** N1k ERSPAN - originating from dcesx4n1 monitor session 1 **>>source vlan 3001destinationerspan-id 1ip address 10.8.33.5origin ip address 10.8.3.100!!monitor session 2 type erspan-sourceshutdowndescription <** N1k ERSPAN - originating from dcesx4n1 monitor session 2 **>>source vlan 3001destinationerspan-id 2ip address 10.8.33.5origin ip address 10.8.3.100!!monitor session 3 type erspan-destinationshutdowndescription <** N1k ERSPAN to NAM - originating from dcesx4n1 **>>destination analysis-module 9 data-port 2sourceerspan-id 1ip address 10.8.33.5!!monitor session 4 type erspan-destinationshutdowndescription <** N1k ERSPAN to IDS-1 - originating from dcesx4n1 **>>destination interface Gi3/26sourceerspan-id 2ip address 10.8.33.5!!process cpu threshold type total rising 80 interval 5 falling 20 interval 5process cpu statistics limit entry-percentage 40 size 300ntp clock-period 17179808ntp server x.26.129.252mac-address-table aging-time 480!endServices Layer ACE
ACE 1
switch/Admin# sh runGenerating configuration....logging enablelogging standbylogging timestamplogging buffered 5login timeout 0boot system image:c6ace-t1k9-mz.A2_2_0.binresource-class dc-goldlimit-resource all minimum 0.00 maximum unlimitedlimit-resource sticky minimum 10.00 maximum unlimitedclock timezone standard ESTclock summer-time standard EDTaccess-list IPANYANY line 8 extended permit ip any anyaccess-list IPANYANY line 16 extended permit icmp any anyaccess-list ipanyany line 8 extended permit ip any anyprobe icmp ICMPProbedescription Ping probeclass-map type management match-any MANAGEMENT3 match protocol snmp any4 match protocol telnet any5 match protocol ssh any6 match protocol icmp any7 match protocol https any8 match protocol http anyclass-map type management match-all class-Query2 match protocol icmp source-address 10.8.99.0 255.255.255.0policy-map type management first-match MANAGEMENTclass MANAGEMENTpermitpolicy-map type management first-match QUERYclass class-Querypermitinterface vlan 146ip address x.26.146.140 255.255.254.0peer ip address x.26.146.141 255.255.254.0service-policy input MANAGEMENTno shutdownft interface vlan 170ip address 10.8.170.1 255.255.255.0peer ip address 10.8.170.2 255.255.255.0no shutdownft peer 1heartbeat interval 100heartbeat count 10ft-interface vlan 170ip route 0.0.0.0 0.0.0.0 x.26.146.1ip route x.26.129.252 255.255.255.255 x.26.146.1context dca-ace-onedescription ** ACE Transparent Mode - **allocate-interface vlan 146allocate-interface vlan 162-163allocate-interface vlan 190-191member dc-goldcontext dca-ace-twodescription ** 2nd ACE Transp. context **allocate-interface vlan 146allocate-interface vlan 152-153snmp-server contact "ANM"snmp-server location "ANM"snmp-server community public group Network-Monitorft group 1peer 1priority 150peer priority 50ft group 2peer 1priority 150peer priority 50associate-context dca-ace-oneinserviceft group 3peer 1priority 50peer priority 150associate-context dca-ace-twoinserviceusername admin password 5 <encrypted password>. role Admin domain default-domainusername www password 5 <encrypted password> role Admin domain default-domainswitch/Admin#switch/Admin# changeto dca-ace-oneswitch/dca-ace-one# sh runGenerating configuration....logging enablelogging standbylogging timestamplogging buffered 5switch-modecrypto csr-params CSR_PARAMS_1country USstate North Carolinalocality RTPorganization-name ESEorganization-unit BANK VAULTcommon-name crackme.comcrypto csr-params CSR_ORACLE12icountry USstate North Carolinalocality RTPorganization-name ESEorganization-unit OracleAppscommon-name oapp.eselab.comaccess-list BPDU ethertype permit bpduaccess-list ALLOW_TRAFFIC line 8 extended permit icmp any anyaccess-list ALLOW_TRAFFIC line 16 extended permit ospf any anyaccess-list ALLOW_TRAFFIC line 48 extended permit ip any anyaccess-list test line 2 extended permit tcp 10.7.53.0 255.255.255.0 anyaccess-list test line 3 extended permit tcp any 10.7.53.0 255.255.255.0probe http 12idescription probes Oracle front endport 8000interval 5passdetect interval 5passdetect count 5expect status 200 200probe http CRACKMEport 81interval 2passdetect interval 5request method get url /Kelev/view/home.phpexpect status 200 200probe icmp TrackHostProbedescription this is a ping probeinterval 2faildetect 1passdetect interval 2passdetect count 1receive 1probe http UBERport 8081interval 2passdetect interval 5request method get url /Kelev/view/home.phpexpect status 200 200parameter-map type http PERSISTpersistence-rebalanceparameter-map type http cookiesecuritycase-insensitiveheader modify per-requestset header-maxparse-length 65535parameter-map type ssl testsession-cache timeout 1800version TLS1action-list type modify http HTTPONLYheader rewrite response Set-Cookie header-value "(.*)*secure*(.*)*" replace "%1secure; HTTPOnly;"rserver redirect OAPP-Redirectdescription Oracle Login Redirectionwebhost-redirection https://oapp.eselab.com/OA_HTML/AppsLocalLogin.jspinservicerserver host dc-wae1ip address 10.8.191.101inservicerserver host dc-wae2ip address 10.8.191.102inservicerserver host ix_server800ip address 10.8.180.100inservicerserver host ix_server801ip address 10.8.180.101inservicerserver host ix_server802ip address 10.8.180.102inservicerserver host ix_server803ip address 10.8.180.103inservicerserver host ix_server804ip address 10.8.180.104inservicerserver host ix_server805ip address 10.8.180.105inservicerserver host ix_server806ip address 10.8.180.106inservicerserver host ix_server807ip address 10.8.180.107inservicerserver host ix_server808ip address 10.8.180.108inservicerserver host ix_server809ip address 10.8.180.109inservicerserver host oelnode1ip address 10.8.180.250inservicerserver host oelnode2ip address 10.8.180.252inservicerserver host oelnode3ip address 10.8.180.253inservicerserver host tbox1ip address 10.8.180.8inservicerserver host uber0ip address 10.8.180.230inservicerserver host uber1description USING 10.8.141.231 IP ADDRESSip address 10.8.180.231rserver host uber2ip address 10.8.180.232rserver host uber3ip address 10.8.180.233rserver host uber4ip address 10.8.180.234rserver host uber5ip address 10.8.180.235rserver host waf1ip address 10.8.190.210inservicerserver host waf2ip address 10.8.190.211inservicerserver host websrv1ip address 10.8.180.153inservicessl-proxy service SSL_OAPPkey oappkeycert oapp-cert.pemssl-proxy service SSL_PSERVICE_CRACKMEkey my2048RSAkey.PEMcert crackme-cert.pemserverfarm redirect sf-oapp-redirectrserver OAPP-Redirectinserviceserverfarm host sf_180rserver ix_server800inservicerserver ix_server801inservicerserver ix_server802inservicerserver ix_server803inservicerserver ix_server804inservicerserver ix_server805inservicerserver ix_server806inservicerserver ix_server807inservicerserver ix_server808inservicerserver ix_server809inserviceserverfarm host sf_bankrserver tbox1 8081inservicerserver uber0 8081inservicerserver uber1 8081rserver uber2 8081inservicerserver uber3 8081inservicerserver uber4 8081inservicerserver uber5 8081inserviceserverfarm host sf_booksrserver uber0 8989inserviceserverfarm host sf_oapppredictor leastconnsrserver oelnode1 8000inservicerserver oelnode2 8000inservicerserver oelnode3 8000inserviceserverfarm host sf_waetransparentpredictor hash address source 255.255.255.255probe TrackHostProberserver dc-wae1inservicerserver dc-wae2inserviceserverfarm host sf_wafrserver waf1 81inservicerserver waf2 81probe TrackHostProbeinserviceserverfarm host sf_waf_booksrserver waf1 82rserver waf2 82inservicesticky http-cookie wafcookie wafstkygrpcookie insertreplicate stickyserverfarm sf_wafsticky http-cookie bankcookie bnkstygrpcookie insertreplicate stickyserverfarm sf_banksticky http-cookie oracookie oapp-stkygrpcookie inserttimeout 720replicate stickyserverfarm sf_oappclass-map type management match-any ANMManagement201 match protocol snmp any202 match protocol http any203 match protocol https any204 match protocol icmp any205 match protocol ssh any206 match protocol telnet anyclass-map match-all ANY_TCP2 match virtual-address 0.0.0.0 0.0.0.0 tcp anyclass-map match-all L4_HTTPS_VIP_ADDRESS2 match virtual-address 10.8.162.200 tcp eq httpsclass-map match-all L4_HTTP_VIP_ADDRESS2 match virtual-address 10.8.162.200 tcp eq wwwclass-map match-all L4_OAPP_VIP2 match virtual-address 10.8.162.250 tcp anyclass-map match-all OELNODES2 match source-address 10.8.180.0 255.255.255.0class-map match-all VIP_180description *VIP for VLAN 180*2 match virtual-address 10.8.162.100 anyclass-map match-all cm-acl-tcp2 match access-list testpolicy-map type management first-match ANMManagementclass ANMManagementpermitpolicy-map type loadbalance first-match pm-forwardclass class-defaultforwardpolicy-map type loadbalance http first-match pm-oappclass class-defaultsticky-serverfarm oapp-stkygrpaction HTTPONLYinsert-http ACEForwarded header-value "%is"policy-map type loadbalance first-match pm-slbclass class-defaultserverfarm sf_180policy-map type loadbalance first-match pm-waasclass class-defaultserverfarm sf_waepolicy-map type loadbalance http first-match pm-wafclass class-defaultsticky-serverfarm wafstkygrpinsert-http ACEForwarded header-value "%is"policy-map type loadbalance http first-match pm-waf2class class-defaultserverfarm sf_waf_bookspolicy-map type loadbalance first-match pm-webbankclass class-defaultsticky-serverfarm bnkstygrppolicy-map type loadbalance first-match pm_booksclass class-defaultserverfarm sf_bookspolicy-map multi-match L4_LB_VIP_HTTP_POLICYclass L4_HTTP_VIP_ADDRESSloadbalance vip inserviceloadbalance policy pm-webbankloadbalance vip icmp-replypolicy-map multi-match LB_WAAS_POLICYclass ANY_TCPloadbalance vip inserviceloadbalance policy pm-waasloadbalance vip icmp-replyclass L4_HTTP_VIP_ADDRESSloadbalance vip inserviceloadbalance policy pm-waasclass L4_OAPP_VIPloadbalance vip inserviceloadbalance policy pm-waasloadbalance vip icmp-replypolicy-map multi-match aggregate-slb-policyclass VIP_180loadbalance vip inserviceloadbalance policy pm-slbloadbalance vip icmp-replyloadbalance vip advertise activeclass L4_HTTP_VIP_ADDRESSloadbalance vip inserviceloadbalance policy pm-wafloadbalance vip icmp-replyclass L4_HTTPS_VIP_ADDRESSloadbalance vip inserviceloadbalance policy pm-wafloadbalance vip icmp-replyssl-proxy server SSL_PSERVICE_CRACKMEclass L4_OAPP_VIPloadbalance vip inserviceloadbalance policy pm-oapploadbalance vip icmp-replyappl-parameter http advanced-options cookiesecurityssl-proxy server SSL_OAPPclass ANY_TCPloadbalance vip inserviceloadbalance policy pm-forwardinterface vlan 146ip address x.26.146.142 255.255.254.0peer ip address x.26.146.143 255.255.254.0service-policy input ANMManagementno shutdowninterface vlan 162description ** North Side facing FWSM **bridge-group 161no normalizationmac-sticky enableno icmp-guardaccess-group input BPDUaccess-group input ALLOW_TRAFFICservice-policy input LB_WAAS_POLICYno shutdowninterface vlan 163description ** South Side facing Servers **bridge-group 161no normalizationmac-sticky enableno icmp-guardaccess-group input BPDUaccess-group input ALLOW_TRAFFICno shutdowninterface vlan 190ip address 10.8.190.2 255.255.255.0alias 10.8.190.1 255.255.255.0peer ip address 10.8.190.3 255.255.255.0no normalizationmac-sticky enableno icmp-guardaccess-group input ALLOW_TRAFFICservice-policy input L4_LB_VIP_HTTP_POLICYservice-policy input LB_WAAS_POLICYno shutdowninterface vlan 191description waas farm vlan 191ip address 10.8.191.2 255.255.255.0alias 10.8.191.1 255.255.255.0peer ip address 10.8.191.3 255.255.255.0no normalizationmac-sticky enableno icmp-guardaccess-group input ALLOW_TRAFFICservice-policy input aggregate-slb-policyno shutdowninterface bvi 161ip address 10.8.162.20 255.255.255.0alias 10.8.162.22 255.255.255.0peer ip address 10.8.162.21 255.255.255.0no shutdownft track interface TrackVlan163track-interface vlan 163peer track-interface vlan 163priority 150peer priority 50ip route 0.0.0.0 0.0.0.0 10.8.162.1ip route 10.8.180.0 255.255.255.0 10.8.162.7snmp-server contact "ANM"snmp-server location "ANM"snmp-server community public group Network-Monitorsnmp-server trap-source vlan 146switch/dca-ace-two# sh runGenerating configuration....logging enablelogging standbylogging timestamplogging buffered 5access-list BPDU ethertype permit bpduaccess-list ALLOW_TRAFFIC line 8 extended permit icmp any anyaccess-list ALLOW_TRAFFIC line 16 extended permit ospf any anyaccess-list ALLOW_TRAFFIC line 48 extended permit ip any anyprobe icmp TrackHostProbedescription this is a ping probeinterval 2faildetect 1passdetect interval 2passdetect count 1receive 1rserver host ix_server810ip address 10.8.181.100inservicerserver host ix_server811ip address 10.8.181.101inservicerserver host ix_server812ip address 10.8.181.102inservicerserver host ix_server813ip address 10.8.181.103inservicerserver host ix_server814ip address 10.8.181.104inservicerserver host ix_server815ip address 10.8.181.105inservicerserver host ix_server816ip address 10.8.181.106inservicerserver host ix_server817ip address 10.8.181.107inservicerserver host ix_server818ip address 10.8.181.108inservicerserver host ix_server819ip address 10.8.181.109inserviceserverfarm host sf_181probe TrackHostProberserver ix_server810inservicerserver ix_server811inservicerserver ix_server812inservicerserver ix_server813inservicerserver ix_server814inservicerserver ix_server815inservicerserver ix_server816inservicerserver ix_server817inservicerserver ix_server818inservicerserver ix_server819inserviceclass-map type management match-any ANMManagement201 match protocol snmp any202 match protocol http any203 match protocol https any204 match protocol icmp any205 match protocol ssh any206 match protocol telnet anyclass-map match-all VIP_181description *VIP for VLAN 181*2 match virtual-address 10.8.152.100 anypolicy-map type management first-match ANMManagementclass ANMManagementpermitpolicy-map type loadbalance first-match pm-slb1class class-defaultserverfarm sf_181policy-map multi-match aggregate-slb-policyclass VIP_181loadbalance vip inserviceloadbalance policy pm-slb1loadbalance vip icmp-replyloadbalance vip advertise activeinterface vlan 146ip address x.26.146.252 255.255.254.0peer ip address x.26.146.253 255.255.254.0service-policy input ANMManagementno shutdowninterface vlan 152description ** North Side facing FWSM2 **bridge-group 151no normalizationmac-sticky enableno icmp-guardaccess-group input BPDUaccess-group input ALLOW_TRAFFICservice-policy input aggregate-slb-policyno shutdowninterface vlan 153description ** South Side facing Servers2 **bridge-group 151no normalizationmac-sticky enableno icmp-guardaccess-group input BPDUaccess-group input ALLOW_TRAFFICno shutdowninterface bvi 151ip address 10.8.152.20 255.255.255.0alias 10.8.152.22 255.255.255.0peer ip address 10.8.152.21 255.255.255.0no shutdownft track interface TrackVlan153track-interface vlan 153peer track-interface vlan 153priority 150peer priority 50ip route 10.8.181.0 255.255.255.0 10.8.152.7ip route 0.0.0.0 0.0.0.0 10.8.152.1snmp-server contact "ANM"snmp-server location "ANM"snmp-server community public group Network-Monitorsnmp-server trap-source vlan 146ACE 2switch/Admin# sh runGenerating configuration....logging enablelogging standbylogging timestamplogging buffered 5boot system image:c6ace-t1k9-mz.A2_2_0.binresource-class dc-goldlimit-resource all minimum 0.00 maximum unlimitedlimit-resource sticky minimum 10.00 maximum unlimitedclock timezone standard ESTclock summer-time standard EDTaccess-list IPANYANY line 8 extended permit ip any anyaccess-list IPANYANY line 16 extended permit icmp any anyaccess-list ipanyany line 8 extended permit ip any anyprobe icmp ICMPProbedescription Ping probeclass-map type management match-any MANAGEMENT3 match protocol snmp any4 match protocol telnet any5 match protocol ssh any6 match protocol icmp any7 match protocol https any8 match protocol http anyclass-map type management match-all class-Query2 match protocol icmp source-address 10.8.99.0 255.255.255.0policy-map type management first-match MANAGEMENTclass MANAGEMENTpermitpolicy-map type management first-match QUERYclass class-Querypermitinterface vlan 146ip address x.26.146.141 255.255.254.0peer ip address x.26.146.140 255.255.254.0service-policy input MANAGEMENTno shutdownft interface vlan 170ip address 10.8.170.2 255.255.255.0peer ip address 10.8.170.1 255.255.255.0no shutdownft peer 1heartbeat interval 100heartbeat count 10ft-interface vlan 170ft group 1peer 1priority 50peer priority 150associate-context Admininserviceip route 0.0.0.0 0.0.0.0 x.26.146.1ip route x.26.129.252 255.255.255.255 x.26.146.1context dca-ace-onedescription ** ACE Transparent Mode - **allocate-interface vlan 146allocate-interface vlan 162-163allocate-interface vlan 190-191member dc-goldcontext dca-ace-twodescription ** 2nd ACE Transp. context **allocate-interface vlan 146allocate-interface vlan 152-153snmp-server contact "ANM"snmp-server location "ANM"snmp-server community public group Network-Monitorft group 2peer 1priority 50peer priority 150associate-context dca-ace-oneinserviceft group 3peer 1priority 150peer priority 50associate-context dca-ace-twoinserviceusername admin password 5 <encrypted password> . role Admin domain default-domainusername www password 5 <encrypted password> role Admin domain default-domainswitch/Admin#switch/dca-ace-one# sh runGenerating configuration....logging enablelogging standbylogging timestamplogging buffered 5switch-modecrypto csr-params CSR_PARAMS_1country USstate North Carolinalocality RTPorganization-name ESEorganization-unit BANK VAULTcommon-name crackme.comcrypto csr-params CSR_ORACLE12icountry USstate North Carolinalocality RTPorganization-name ESEorganization-unit OracleAppscommon-name oapp.eselab.comaccess-list BPDU ethertype permit bpduaccess-list ALLOW_TRAFFIC line 8 extended permit icmp any anyaccess-list ALLOW_TRAFFIC line 16 extended permit ospf any anyaccess-list ALLOW_TRAFFIC line 48 extended permit ip any anyaccess-list test line 2 extended permit tcp 10.7.53.0 255.255.255.0 anyaccess-list test line 3 extended permit tcp any 10.7.53.0 255.255.255.0probe http 12idescription probes Oracle front endport 8000interval 5passdetect interval 5passdetect count 5expect status 200 200probe http CRACKMEport 81interval 2passdetect interval 5request method get url /Kelev/view/home.phpexpect status 200 200probe icmp TrackHostProbedescription this is a ping probeinterval 2faildetect 1passdetect interval 2passdetect count 1receive 1probe http UBERport 8081interval 2passdetect interval 5request method get url /Kelev/view/home.phpexpect status 200 200parameter-map type http PERSISTpersistence-rebalanceparameter-map type http cookiesecuritycase-insensitiveheader modify per-requestset header-maxparse-length 65535parameter-map type ssl testsession-cache timeout 1800version TLS1action-list type modify http HTTPONLYheader rewrite response Set-Cookie header-value "(.*)*secure*(.*)*" replace "%1secure; HTTPOnly;"rserver redirect OAPP-Redirectdescription Oracle Login Redirectionwebhost-redirection https://oapp.eselab.com/OA_HTML/AppsLocalLogin.jspinservicerserver host dc-wae1ip address 10.8.191.101inservicerserver host dc-wae2ip address 10.8.191.102inservicerserver host ix_server800ip address 10.8.180.100inservicerserver host ix_server801ip address 10.8.180.101inservicerserver host ix_server802ip address 10.8.180.102inservicerserver host ix_server803ip address 10.8.180.103inservicerserver host ix_server804ip address 10.8.180.104inservicerserver host ix_server805ip address 10.8.180.105inservicerserver host ix_server806ip address 10.8.180.106inservicerserver host ix_server807ip address 10.8.180.107inservicerserver host ix_server808ip address 10.8.180.108inservicerserver host ix_server809ip address 10.8.180.109inservicerserver host oelnode1ip address 10.8.180.250inservicerserver host oelnode2ip address 10.8.180.252inservicerserver host oelnode3ip address 10.8.180.253inservicerserver host tbox1ip address 10.8.180.8inservicerserver host uber0ip address 10.8.180.230inservicerserver host uber1description USING 10.8.141.231 IP ADDRESSip address 10.8.180.231rserver host uber2ip address 10.8.180.232rserver host uber3ip address 10.8.180.233rserver host uber4ip address 10.8.180.234rserver host uber5ip address 10.8.180.235rserver host waf1ip address 10.8.190.210inservicerserver host waf2ip address 10.8.190.211inservicerserver host websrv1ip address 10.8.180.153inservicessl-proxy service SSL_OAPPkey oappkeycert oapp-cert.pemssl-proxy service SSL_PSERVICE_CRACKMEkey my2048RSAkey.PEMcert crackme-cert.pemserverfarm redirect sf-oapp-redirectrserver OAPP-Redirectinserviceserverfarm host sf_180rserver ix_server800inservicerserver ix_server801inservicerserver ix_server802inservicerserver ix_server803inservicerserver ix_server804inservicerserver ix_server805inservicerserver ix_server806inservicerserver ix_server807inservicerserver ix_server808inservicerserver ix_server809inserviceserverfarm host sf_bankrserver tbox1 8081inservicerserver uber0 8081inservicerserver uber1 8081rserver uber2 8081inservicerserver uber3 8081inservicerserver uber4 8081inservicerserver uber5 8081inserviceserverfarm host sf_booksrserver uber0 8989inserviceserverfarm host sf_oapppredictor leastconnsrserver oelnode1 8000inservicerserver oelnode2 8000inservicerserver oelnode3 8000inserviceserverfarm host sf_waetransparentpredictor hash address source 255.255.255.255probe TrackHostProberserver dc-wae1inservicerserver dc-wae2inserviceserverfarm host sf_wafrserver waf1 81inservicerserver waf2 81probe TrackHostProbeinserviceserverfarm host sf_waf_booksrserver waf1 82rserver waf2 82inservicesticky http-cookie wafcookie wafstkygrpcookie insertreplicate stickyserverfarm sf_wafsticky http-cookie bankcookie bnkstygrpcookie insertreplicate stickyserverfarm sf_banksticky http-cookie oracookie oapp-stkygrpcookie inserttimeout 720replicate stickyserverfarm sf_oappclass-map type management match-any ANMManagement201 match protocol snmp any202 match protocol http any203 match protocol https any204 match protocol icmp any205 match protocol ssh any206 match protocol telnet anyclass-map match-all ANY_TCP2 match virtual-address 0.0.0.0 0.0.0.0 tcp anyclass-map match-all L4_HTTPS_VIP_ADDRESS2 match virtual-address 10.8.162.200 tcp eq httpsclass-map match-all L4_HTTP_VIP_ADDRESS2 match virtual-address 10.8.162.200 tcp eq wwwclass-map match-all L4_OAPP_VIP2 match virtual-address 10.8.162.250 tcp anyclass-map match-all OELNODES2 match source-address 10.8.180.0 255.255.255.0class-map match-all VIP_180description *VIP for VLAN 180*2 match virtual-address 10.8.162.100 anyclass-map match-all cm-acl-tcp2 match access-list testpolicy-map type management first-match ANMManagementclass ANMManagementpermitpolicy-map type loadbalance first-match pm-forwardclass class-defaultforwardpolicy-map type loadbalance http first-match pm-oappclass class-defaultsticky-serverfarm oapp-stkygrpaction HTTPONLYinsert-http ACEForwarded header-value "%is"policy-map type loadbalance first-match pm-slbclass class-defaultserverfarm sf_180policy-map type loadbalance first-match pm-waasclass class-defaultserverfarm sf_waepolicy-map type loadbalance http first-match pm-wafclass class-defaultsticky-serverfarm wafstkygrpinsert-http ACEForwarded header-value "%is"policy-map type loadbalance http first-match pm-waf2class class-defaultserverfarm sf_waf_bookspolicy-map type loadbalance first-match pm-webbankclass class-defaultsticky-serverfarm bnkstygrppolicy-map type loadbalance first-match pm_booksclass class-defaultserverfarm sf_bookspolicy-map multi-match L4_LB_VIP_HTTP_POLICYclass L4_HTTP_VIP_ADDRESSloadbalance vip inserviceloadbalance policy pm-webbankloadbalance vip icmp-replypolicy-map multi-match LB_WAAS_POLICYclass ANY_TCPloadbalance vip inserviceloadbalance policy pm-waasloadbalance vip icmp-replyclass L4_HTTP_VIP_ADDRESSloadbalance vip inserviceloadbalance policy pm-waasclass L4_OAPP_VIPloadbalance vip inserviceloadbalance policy pm-waasloadbalance vip icmp-replypolicy-map multi-match aggregate-slb-policyclass VIP_180loadbalance vip inserviceloadbalance policy pm-slbloadbalance vip icmp-replyloadbalance vip advertise activeclass L4_HTTP_VIP_ADDRESSloadbalance vip inserviceloadbalance policy pm-wafloadbalance vip icmp-replyclass L4_HTTPS_VIP_ADDRESSloadbalance vip inserviceloadbalance policy pm-wafloadbalance vip icmp-replyssl-proxy server SSL_PSERVICE_CRACKMEclass L4_OAPP_VIPloadbalance vip inserviceloadbalance policy pm-oapploadbalance vip icmp-replyappl-parameter http advanced-options cookiesecurityssl-proxy server SSL_OAPPclass ANY_TCPloadbalance vip inserviceloadbalance policy pm-forwardinterface vlan 146ip address x.26.146.143 255.255.254.0peer ip address x.26.146.142 255.255.254.0service-policy input ANMManagementno shutdowninterface vlan 162description ** North Side facing FWSM **bridge-group 161no normalizationmac-sticky enableno icmp-guardaccess-group input BPDUaccess-group input ALLOW_TRAFFICservice-policy input LB_WAAS_POLICYno shutdowninterface vlan 163description ** South Side facing Servers **bridge-group 161no normalizationmac-sticky enableno icmp-guardaccess-group input BPDUaccess-group input ALLOW_TRAFFICno shutdowninterface vlan 190ip address 10.8.190.3 255.255.255.0alias 10.8.190.1 255.255.255.0peer ip address 10.8.190.2 255.255.255.0no normalizationmac-sticky enableno icmp-guardaccess-group input ALLOW_TRAFFICservice-policy input L4_LB_VIP_HTTP_POLICYservice-policy input LB_WAAS_POLICYno shutdowninterface vlan 191description waas farm vlan 191ip address 10.8.191.3 255.255.255.0alias 10.8.191.1 255.255.255.0peer ip address 10.8.191.2 255.255.255.0no normalizationmac-sticky enableno icmp-guardaccess-group input ALLOW_TRAFFICservice-policy input aggregate-slb-policyno shutdowninterface bvi 161ip address 10.8.162.21 255.255.255.0alias 10.8.162.22 255.255.255.0peer ip address 10.8.162.20 255.255.255.0no shutdownft track interface TrackVlan163track-interface vlan 163peer track-interface vlan 163priority 50peer priority 150ip route 0.0.0.0 0.0.0.0 10.8.162.1ip route 10.8.180.0 255.255.255.0 10.8.162.7snmp-server contact "ANM"snmp-server location "ANM"snmp-server community public group Network-Monitorsnmp-server trap-source vlan 146switch/dca-ace-two# sh runGenerating configuration....logging enablelogging standbylogging timestamplogging buffered 5access-list BPDU ethertype permit bpduaccess-list ALLOW_TRAFFIC line 8 extended permit icmp any anyaccess-list ALLOW_TRAFFIC line 16 extended permit ospf any anyaccess-list ALLOW_TRAFFIC line 48 extended permit ip any anyprobe icmp TrackHostProbedescription this is a ping probeinterval 2faildetect 1passdetect interval 2passdetect count 1receive 1rserver host ix_server810ip address 10.8.181.100inservicerserver host ix_server811ip address 10.8.181.101inservicerserver host ix_server812ip address 10.8.181.102inservicerserver host ix_server813ip address 10.8.181.103inservicerserver host ix_server814ip address 10.8.181.104inservicerserver host ix_server815ip address 10.8.181.105inservicerserver host ix_server816ip address 10.8.181.106inservicerserver host ix_server817ip address 10.8.181.107inservicerserver host ix_server818ip address 10.8.181.108inservicerserver host ix_server819ip address 10.8.181.109inserviceserverfarm host sf_181probe TrackHostProberserver ix_server810inservicerserver ix_server811inservicerserver ix_server812inservicerserver ix_server813inservicerserver ix_server814inservicerserver ix_server815inservicerserver ix_server816inservicerserver ix_server817inservicerserver ix_server818inservicerserver ix_server819inserviceclass-map type management match-any ANMManagement201 match protocol snmp any202 match protocol http any203 match protocol https any204 match protocol icmp any205 match protocol ssh any206 match protocol telnet anyclass-map match-all VIP_181description *VIP for VLAN 181*2 match virtual-address 10.8.152.100 anypolicy-map type management first-match ANMManagementclass ANMManagementpermitpolicy-map type loadbalance first-match pm-slb1class class-defaultserverfarm sf_181policy-map multi-match aggregate-slb-policyclass VIP_181loadbalance vip inserviceloadbalance policy pm-slb1loadbalance vip icmp-replyloadbalance vip advertise activeinterface vlan 146ip address x.26.146.253 255.255.254.0peer ip address x.26.146.252 255.255.254.0service-policy input ANMManagementno shutdowninterface vlan 152description ** North Side facing FWSM2 **bridge-group 151no normalizationmac-sticky enableno icmp-guardaccess-group input BPDUaccess-group input ALLOW_TRAFFICservice-policy input aggregate-slb-policyno shutdowninterface vlan 153description ** South Side facing Servers2 **bridge-group 151no normalizationmac-sticky enableno icmp-guardaccess-group input BPDUaccess-group input ALLOW_TRAFFICno shutdowninterface bvi 151ip address 10.8.152.21 255.255.255.0alias 10.8.152.22 255.255.255.0peer ip address 10.8.152.20 255.255.255.0no shutdownft track interface TrackVlan153track-interface vlan 153peer track-interface vlan 153priority 50peer priority 150ip route 10.8.181.0 255.255.255.0 10.8.152.7ip route 0.0.0.0 0.0.0.0 10.8.152.1snmp-server contact "ANM"snmp-server location "ANM"snmp-server community public group Network-Monitorsnmp-server trap-source vlan 146switch/dca-ace-two#Services Layer IPS
IPS 1
dca-ips1# sh configuration! ------------------------------! Current configuration last modified Thu Mar 05 14:27:20 2009! ------------------------------! Version 6.2(1)! Host:! Realm Keys key1.0! Signature Definition:! Signature Update S386.0 2009-03-09! Virus Update V1.4 2007-03-02! ------------------------------service interfacephysical-interfaces GigabitEthernet3/0admin-state disabledsubinterface-type noneexitphysical-interfaces GigabitEthernet3/3description to ss1 gig3/26admin-state enabledduplex autospeed autodefault-vlan 0alt-tcp-reset-interface noneexitphysical-interfaces TenGigabitEthernet7/0description to ss2admin-state disabledduplex autospeed autodefault-vlan 0alt-tcp-reset-interface nonesubinterface-type inline-vlan-pairsubinterface 1description to ss2vlan1 163vlan2 164exitexitexitphysical-interfaces TenGigabitEthernet7/1no descriptionadmin-state enabledduplex autospeed autodefault-vlan 1alt-tcp-reset-interface nonesubinterface-type inline-vlan-pairsubinterface 1description ss1vlan1 163vlan2 164exitexitexitbypass-mode autocdp-mode forward-cdp-packetsexit! ------------------------------service authenticationexit! ------------------------------service event-action-rules rules0overrides deny-packet-inlineoverride-item-status Disabledrisk-rating-range 90-100exitoverrides log-attacker-packetsoverride-item-status Enabledrisk-rating-range 90-100exitoverrides log-victim-packetsoverride-item-status Enabledrisk-rating-range 90-100exitoverrides log-pair-packetsoverride-item-status Enabledrisk-rating-range 90-100exitoverrides produce-alertoverride-item-status Enabledrisk-rating-range 90-100exitoverrides produce-verbose-alertoverride-item-status Enabledrisk-rating-range 1-69exitfilters edit Q00000signature-id-range 1301subsignature-id-range 0attacker-address-range 10.8.162.20victim-address-range 10.8.180.232victim-port-range 8081actions-to-remove log-attacker-packets|produce-alert|produce-verbose-alertos-relevance relevant|not-relevant|unknownexitfilters move Q00000 beginexit! ------------------------------service hostnetwork-settingshost-ip x.26.146.87/24,x.26.146.1host-name dca-ips1telnet-option disabledaccess-list 10.0.0.0/8access-list 64.0.0.0/8access-list x.0.0.0/8exittime-zone-settingsoffset -300standard-time-zone-name GMT-05:00exitntp-option enabledntp-keys 10 md5-key cisco123ntp-servers x.26.170.13 key-id 10exitsummertime-option disabledauto-upgradecisco-server enabledschedule-option calendar-scheduletimes-of-day 17:20:00days-of-week mondaydays-of-week tuesdaydays-of-week wednesdaydays-of-week thursdaydays-of-week fridayexitcisco-url https://198.133.219.25//cgi-bin/front.x/ida/locator/locator.plexitexitexit! ------------------------------service loggerexit! ------------------------------service network-accessgeneralblock-enable falseexitexit! ------------------------------service notificationexit! ------------------------------service signature-definition sig0signatures 1301 0engine normalizerevent-action produce-alertexitexitsignatures 1302 0engine normalizerevent-action produce-alertexitexitsignatures 1303 0engine normalizerevent-action produce-alertexitexitsignatures 1304 0engine normalizerevent-action produce-alertexitexitsignatures 1305 0engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1306 1engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1306 2engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1306 3engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1306 4engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1306 5engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1306 6engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1312 0engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1313 0engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1316 0engine normalizerevent-action produce-alertexitexitsignatures 1330 0engine normalizerevent-action produce-alert|deny-packet-inlineexitexitsignatures 1330 1engine normalizerevent-action produce-alert|deny-packet-inlineexitexitsignatures 1330 2engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 5engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 6engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 7engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 8engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 9engine normalizerevent-action produce-alert|deny-packet-inlineexitexitsignatures 1330 10engine normalizerevent-action produce-alert|deny-packet-inlineexitexitsignatures 1330 12engine normalizerevent-action produce-alertexitexitsignatures 1330 17engine normalizerevent-action produce-alertexitexitsignatures 1330 18engine normalizerevent-action produce-alert|deny-packet-inlineexitexitsignatures 1330 19engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 20engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 21engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 2000 0statusenabled falseexitexitsignatures 2004 0statusenabled falseexitexitsignatures 2007 0statusenabled falseexitexitsignatures 2008 0statusenabled falseexitexitsignatures 2100 0statusenabled falseexitexitsignatures 2151 0statusenabled trueexitexitexit! ------------------------------service ssh-known-hostsexit! ------------------------------service trusted-certificatestrusted-certificates x.26.191.99 certificate MIICaDCCAdECBEhdNM4wDQYJKoZIhvcNAQEEBQAwezELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExET APBgNVBAcTCFNhbiBKb3NlMRYwFAYDVQQKEw1DaXNjbyBTeXN0ZW1zMRQwEgYDVQQLEwtTVEcgQ1MtTUFSUzEWMBQG A1UEAxMNd3d3LmNpc2NvLmNvbTAeFw0wODA2MjExNzA1MThaFw0yMzA2MTgxNzA1MThaMHsxCzAJBgNVBAYTAlVTMR MwEQYDVQQIEwpDYWxpZm9ybmlhMREwDwYDVQQHEwhTYW4gSm9zZTEWMBQGA1UEChMNQ2lzY28gU3lzdGVtczEUMBIG A1UECxMLU1RHIENTLU1BUlMxFjAUBgNVBAMTDXd3dy5jaXNjby5jb20wgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAo GBAM/IsMmkz4/gg6cuqu2CylSBqc+YlMELHTnU20Rfx05oaYIl4YBFJwgQ9Y9w0G7N7LIjrmWwUCmwnwFsHkn8BwLN r5+qVCT6Y+5GXzD8zC2kdRud06T4n4l5Oj1dfxb2GuMnYSK+tKO0R1/fYIK5zvhYJ/8AVfRZ4okWdiGfu/EdAgMBAA EwDQYJKoZIhvcNAQEEBQADgYEAtvqJE5f9XqDrSxTh5bL75A1/taePqpaYgpS4rLvP2OZ7Rf0tU7SCANS6OmykM5OB xCPsdzoGreHymP7v4exnesJZp3ptCFNAW67COoWA29UfKYrIamXopBh1tTWzI+3igrlyZnHEQVXgsHx9lbyHXGE/GV 7y0LrS4Qhr5OPKjQk=exit! ------------------------------service web-serverport 443exit! ------------------------------service anomaly-detection ad0ignoresource-ip-address-range 10.7.52.30dest-ip-address-range 10.8.180.153,10.8.162.200exitexit! ------------------------------service external-product-interfaceexit! ------------------------------service health-monitorexit! ------------------------------service analysis-enginevirtual-sensor vs0physical-interface TenGigabitEthernet7/0 subinterface-number 1physical-interface TenGigabitEthernet7/1 subinterface-number 1inline-TCP-session-tracking-mode virtual-sensorinline-TCP-evasion-protection-mode strictexitvirtual-sensor vs1signature-definition sig0event-action-rules rules0anomaly-detectionanomaly-detection-name ad0exitphysical-interface GigabitEthernet3/3 subinterface-number 0exitexitIPS 2dca-ips2# sh configuration! ------------------------------! Current configuration last modified Thu Mar 05 14:03:20 2009! ------------------------------! Version 6.2(1)! Host:! Realm Keys key1.0! Signature Definition:! Signature Update S386.0 2009-03-09! Virus Update V1.4 2007-03-02! ------------------------------service interfacephysical-interfaces TenGigabitEthernet7/0admin-state enabledsubinterface-type inline-vlan-pairsubinterface 1no descriptionvlan1 163vlan2 164exitexitexitphysical-interfaces TenGigabitEthernet7/1description to ss2admin-state enabledduplex autospeed autodefault-vlan 0alt-tcp-reset-interface nonesubinterface-type inline-vlan-pairsubinterface 1description ss2vlan1 163vlan2 164exitexitexitbypass-mode autoexit! ------------------------------service authenticationexit! ------------------------------service event-action-rules rules0overrides deny-packet-inlineoverride-item-status Disabledrisk-rating-range 90-100exitexit! ------------------------------service hostnetwork-settingshost-ip x.26.146.88/24,x.26.146.1host-name dca-ips2telnet-option disabledaccess-list 10.0.0.0/8access-list 64.0.0.0/8access-list x.0.0.0/8exittime-zone-settingsoffset -300standard-time-zone-name GMT-05:00exitntp-option enabledntp-keys 10 md5-key cisco123ntp-servers x.26.170.13 key-id 10exitsummertime-option recurringsummertime-zone-name GMT-05:00exitauto-upgradecisco-server enabledschedule-option calendar-scheduletimes-of-day 17:20:00days-of-week mondaydays-of-week tuesdaydays-of-week wednesdaydays-of-week thursdaydays-of-week fridayexitcisco-url https://198.133.219.25//cgi-bin/front.x/ida/locator/locator.plexitexitexit! ------------------------------service loggerexit! ------------------------------service network-accessexit! ------------------------------service notificationexit! ------------------------------service signature-definition sig0signatures 1301 0engine normalizerevent-action produce-alertexitexitsignatures 1302 0engine normalizerevent-action produce-alertexitexitsignatures 1303 0engine normalizerevent-action produce-alertexitexitsignatures 1304 0engine normalizerevent-action produce-alertexitexitsignatures 1305 0engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1306 1engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1306 2engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1306 3engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1306 4engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1306 5engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1306 6engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1312 0engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1313 0engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1316 0engine normalizerevent-action produce-alertexitexitsignatures 1330 0engine normalizerevent-action produce-alert|deny-packet-inlineexitexitsignatures 1330 1engine normalizerevent-action produce-alert|deny-packet-inlineexitexitsignatures 1330 2engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 5engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 6engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 7engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 8engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 9engine normalizerevent-action produce-alert|deny-packet-inlineexitexitsignatures 1330 10engine normalizerevent-action produce-alert|deny-packet-inlineexitexitsignatures 1330 12engine normalizerevent-action produce-alertexitexitsignatures 1330 17engine normalizerevent-action produce-alertexitexitsignatures 1330 18engine normalizerevent-action produce-alert|deny-packet-inlineexitexitsignatures 1330 19engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 20engine normalizerevent-action produce-alert|modify-packet-inlineexitexitsignatures 1330 21engine normalizerevent-action produce-alert|modify-packet-inlineexitexitexit! ------------------------------service ssh-known-hostsexit! ------------------------------service trusted-certificatestrusted-certificates x.26.191.99 certificate MIICaDCCAdECBEhdNM4wDQYJKoZIhvcNAQEEBQAwezELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExET APBgNVBAcTCFNhbiBKb3NlMRYwFAYDVQQKEw1DaXNjbyBTeXN0ZW1zMRQwEgYDVQQLEwtTVEcgQ1MtTUFSUzEWMBQG A1UEAxMNd3d3LmNpc2NvLmNvbTAeFw0wODA2MjExNzA1MThaFw0yMzA2MTgxNzA1MThaMHsxCzAJBgNVBAYTAlVTMR MwEQYDVQQIEwpDYWxpZm9ybmlhMREwDwYDVQQHEwhTYW4gSm9zZTEWMBQGA1UEChMNQ2lzY28gU3lzdGVtczEUMBIG A1UECxMLU1RHIENTLU1BUlMxFjAUBgNVBAMTDXd3dy5jaXNjby5jb20wgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAo GBAM/IsMmkz4/gg6cuqu2CylSBqc+YlMELHTnU20Rfx05oaYIl4YBFJwgQ9Y9w0G7N7LIjrmWwUCmwnwFsHkn8BwLN r5+qVCT6Y+5GXzD8zC2kdRud06T4n4l5Oj1dfxb2GuMnYSK+tKO0R1/fYIK5zvhYJ/8AVfRZ4okWdiGfu/EdAgMBAA EwDQYJKoZIhvcNAQEEBQADgYEAtvqJE5f9XqDrSxTh5bL75A1/taePqpaYgpS4rLvP2OZ7Rf0tU7SCANS6OmykM5OB xCPsdzoGreHymP7v4exnesJZp3ptCFNAW67COoWA29UfKYrIamXopBh1tTWzI+3igrlyZnHEQVXgsHx9lbyHXGE/GV 7y0LrS4Qhr5OPKjQk=exit! ------------------------------service web-serverexit! ------------------------------service anomaly-detection ad0ignoresource-ip-address-range 10.7.52.30dest-ip-address-range 10.8.180.153,10.8.162.200exitexit! ------------------------------service external-product-interfaceexit! ------------------------------service health-monitorexit! ------------------------------service analysis-enginevirtual-sensor vs0physical-interface TenGigabitEthernet7/0 subinterface-number 1physical-interface TenGigabitEthernet7/1 subinterface-number 1inline-TCP-session-tracking-mode virtual-sensorinline-TCP-evasion-protection-mode strictexitexitAccess Layer Nexus 5000
Nexus 5000 1
dc10-5020-1# sh runversion 4.0(1a)N1(1)feature tacacs+feature lacpfeature fcoeusername admin password 5 <encrypted password> role network-adminusername dma password 5 <encrypted password>/ role network-adminusername chris password 5 <encrypted password> role network-adminssh key rsa 2048 forcentp server x.26.146.1 use-vrf managementip host dc10-5020-1 x.26.146.191tacacs-server key 7 "<key>"tacacs-server host x.26.191.94 key 7 "<key>"aaa group server tacacs+ tacacs-groupserver x.26.191.94use-vrf managementaaa group server tacacs+ tacacssystem default switchportservice unsupported-transceiverip access-list 13410 permit ip x.26.146.191/32 x.26.0.0/1620 deny ip any anyip access-list 13310 permit icmp x.26.0.0/16 x.26.146.191/32 ttl-exceeded20 permit icmp x.26.0.0/16 x.26.146.191/32 port-unreachable30 permit icmp x.26.0.0/16 x.26.146.191/32 echo-reply40 permit icmp x.26.0.0/16 x.26.146.191/32 echo50 permit tcp x.26.0.0/16 eq tacacs x.26.146.191/32 established60 permit tcp x.26.0.0/16 x.26.146.191/32 eq tacacs70 permit udp x.26.0.0/16 x.26.146.191/32 eq ntp80 permit tcp x.26.0.0/16 x.26.146.191/32 eq 2290 permit tcp x.26.0.0/16 eq ftp x.26.146.191/32 gt 1023 established100 permit tcp x.26.0.0/16 eq ftp-data x.26.146.191/32 gt 1023110 permit tcp x.26.0.0/16 gt 1023 x.26.146.191/32 gt 1023 established120 permit udp x.26.0.0/16 gt 1023 x.26.146.191/32 gt 1023130 permit udp x.26.191.99/32 x.26.146.191/32 eq snmp140 deny ip any anysnmp-server user dma network-admin auth md5 0x9087aa934c0a90dc2e7456b14f13cb31 priv 0x9087aa934c0a90dc2e7456b14f13cb31 localizedkeysnmp-server user admin network-admin auth md5 0x9087aa934c0a90dc2e7456b14f13cb31priv 0x9087aa934c0a90dc2e7456b14f13cb31 localizedkeysnmp-server user chris network-admin auth md5 0x9087aa934c0a90dc2e7456b14f13cb31priv 0x9087aa934c0a90dc2e7456b14f13cb31 localizedkeysnmp-server host 10.116.132.2 version 2c public udp-port 2162snmp-server host 192.168.174.131 version 2c public udp-port 2162aaa authentication login console group tacacs-groupaaa accounting default group tacacs-groupaaa authentication login error-enablevrf context managementip route 0.0.0.0/0 x.26.146.1ip route x.26.0.0/16 x.26.146.1switchname dc10-5020-1vlan 1,15vlan 98name serviceconsolevlan 142name dbvlanvlan 180-183vlan 3000name erspanvlan 3002name vemcontrolvlan 3003name vempacketspanning-tree pathcost method longspanning-tree port type network defaultvsan databasevsan 60 name "SAN_VSAN"class-map iSCSImatch cos 2class-map VMotionmatch cos 1class-map Service-Consolematch cos 4policy-map VMWare-Classesclass class-defaultclass class-fcoeclass iSCSIpause no-dropclass VMotionclass Service-Consolepolicy-map jumboclass class-defaultmtu 9216system qosservice-policy jumbointerface vfc1no shutdownbind interface Ethernet1/1interface vfc2no shutdownbind interface Ethernet1/2interface vfc3no shutdownbind interface Ethernet1/3interface vfc4no shutdownbind interface Ethernet1/4interface vfc5no shutdownbind interface Ethernet1/5interface vfc6no shutdownbind interface Ethernet1/6vsan databasevsan 60 interface vfc1vsan 60 interface vfc2vsan 60 interface vfc3vsan 60 interface vfc4vsan 60 interface vfc5vsan 60 interface vfc6vsan 60 interface fc2/1interface fc2/1no shutdownswitchport trunk allowed vsan 60interface fc2/2interface fc2/3interface fc2/4interface fc3/1interface fc3/2interface fc3/3interface fc3/4interface Ethernet1/1switchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/2switchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/3switchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/4switchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/5switchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/6shutdownswitchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/7shutdownswitchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/8shutdownswitchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/9shutdownswitchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/10shutdownswitchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/11interface Ethernet1/12interface Ethernet1/13interface Ethernet1/14interface Ethernet1/15interface Ethernet1/16interface Ethernet1/17interface Ethernet1/18interface Ethernet1/19interface Ethernet1/20interface Ethernet1/21interface Ethernet1/22interface Ethernet1/23interface Ethernet1/24interface Ethernet1/25interface Ethernet1/26interface Ethernet1/27interface Ethernet1/28interface Ethernet1/29interface Ethernet1/30interface Ethernet1/31interface Ethernet1/32interface Ethernet1/33interface Ethernet1/34interface Ethernet1/35interface Ethernet1/36interface Ethernet1/37interface Ethernet1/38interface Ethernet1/39interface Ethernet1/40interface Ethernet2/1switchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type networkinterface Ethernet2/2interface Ethernet2/3interface Ethernet2/4interface Ethernet3/1switchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type networkinterface Ethernet3/2interface Ethernet3/3interface Ethernet3/4interface mgmt0vrf member managementip address x.26.146.191/23no ip redirectsinterface fc2/1interface fc2/2interface fc2/3interface fc2/4interface fc3/1interface fc3/2interface fc3/3interface fc3/4snmp-server enable traps entity frusnmp-server enable traps licenseboot kickstart bootflash:/n5000-uk9-kickstart.4.0.1a.N1.1.binboot system bootflash:/n5000-uk9.4.0.1a.N1.1.bindevice-alias databasedevice-alias name Atto1 pwwn 22:00:00:10:86:13:36:48device-alias name Atto2 pwwn 22:00:00:10:86:13:36:40device-alias name HPBlade1 pwwn 50:05:08:b2:00:b1:68:63device-alias name HPBlade2 pwwn 50:05:08:b2:00:b0:d6:83device-alias name HPBlade3 pwwn 50:05:08:b2:00:b1:66:93device-alias name DellBlade3 pwwn 21:00:00:14:22:73:ce:c2device-alias name DellBlade5 pwwn 21:00:00:14:22:73:ce:e4device-alias name dc-dl580-1 pwwn 10:00:00:00:c9:57:fa:ccdevice-alias name dc-dl580-2 pwwn 10:00:00:00:c9:57:fc:c6device-alias name dc-dl580-3 pwwn 10:00:00:00:c9:57:e8:20device-alias name dc-dl580-4 pwwn 10:00:00:00:c9:57:e7:b8device-alias name dc-dl580-5 pwwn 10:00:00:00:c9:57:fb:d0device-alias name dc-dl580-6 pwwn 10:00:00:00:c9:57:fd:cedevice-alias commitip route 0.0.0.0/23 x.26.146.1ip route x.26.0.0/16 x.26.146.1no system default switchport shutdownzoneset activate name RTP-DataCenter1 vsan 1zoneset activate name RTP-DataCenter1 vsan 60Nexus 5000 2dc10-5020-2# sh runversion 4.0(1a)N1(1)feature tacacs+feature udldfeature interface-vlanfeature lacpfeature fcoeusername admin password 5 <encrypted password>role network-adminusername chris password 5 <encrypted password>role network-adminusername dma password 5 <encrypted password>. role network-adminssh key rsa 2048 forcentp server x.26.146.1 use-vrf managementtacacs-server key 7 "<key>"tacacs-server host x.26.191.94 key 7 "<key>"aaa group server tacacs+ tacacs-groupserver x.26.191.94use-vrf managementaaa group server tacacs+ tacacssystem default switchportservice unsupported-transceiversnmp-server user dma network-admin auth md5 0x7f5109316dadcd2bd3322c3baa49167e priv 0x7f5109316dadcd2bd3322c3baa49167e localizedkeysnmp-server user admin network-admin auth md5 0x7f5109316dadcd2bd3322c3baa49167epriv 0x7f5109316dadcd2bd3322c3baa49167e localizedkeysnmp-server user chris network-admin auth md5 0x7f5109316dadcd2bd3322c3baa49167epriv 0x7f5109316dadcd2bd3322c3baa49167e localizedkeysnmp-server host 10.116.132.3 version 2c public udp-port 1163snmp-server host 192.168.174.131 version 2c public udp-port 2162aaa authentication login console group tacacs-groupaaa accounting default group tacacs-groupaaa authentication login error-enablevrf context managementip route 0.0.0.0/0 x.26.146.1switchname dc10-5020-2vlan 1vlan 15name vmkernelvlan 98name vmprodvlan 142name dbvlan 180-183vlan 3000name erspanvlan 3002name vemcontrolvlan 3003name vempacketspanning-tree pathcost method longspanning-tree port type network defaultpolicy-map jumboclass class-defaultmtu 9216system qosservice-policy jumbointerface Vlan1interface fc2/1interface fc2/2interface fc2/3interface fc2/4interface fc3/1interface fc3/2interface fc3/3interface fc3/4interface Ethernet1/1switchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/2switchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/3switchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/4switchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/5switchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/6shutdownswitchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/7shutdownswitchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/8shutdownswitchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/9shutdownswitchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/10shutdownswitchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003spanning-tree port type edge trunkinterface Ethernet1/11interface Ethernet1/12interface Ethernet1/13interface Ethernet1/14interface Ethernet1/15interface Ethernet1/16interface Ethernet1/17interface Ethernet1/18interface Ethernet1/19interface Ethernet1/20interface Ethernet1/21interface Ethernet1/22interface Ethernet1/23interface Ethernet1/24interface Ethernet1/25interface Ethernet1/26interface Ethernet1/27interface Ethernet1/28interface Ethernet1/29interface Ethernet1/30interface Ethernet1/31interface Ethernet1/32interface Ethernet1/33interface Ethernet1/34interface Ethernet1/35interface Ethernet1/36interface Ethernet1/37interface Ethernet1/38interface Ethernet1/39interface Ethernet1/40interface Ethernet2/1switchport mode trunkdescription to dca-n7k1-vdc2 port 1/28logging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type networkinterface Ethernet2/2interface Ethernet2/3interface Ethernet2/4interface Ethernet3/1switchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,142,180-183,3000,3002-3003spanning-tree port type networkinterface Ethernet3/2shutdownswitchport mode trunklogging event port link-statuslogging event port trunk-statusswitchport trunk allowed vlan 15,98,180-183spanning-tree port type networkinterface Ethernet3/3interface Ethernet3/4interface mgmt0vrf member managementip address x.26.146.192/23clock timezone EST -5 0clock summer-time EST 1 Sunday April 00:00 5 Saturday Oct 00:00 60system default switchport trunk mode autointerface fc2/1interface fc2/2interface fc2/3interface fc2/4interface fc3/1interface fc3/2interface fc3/3interface fc3/4snmp-server enable traps entity frusnmp-server enable traps licenseboot kickstart bootflash:/n5000-uk9-kickstart.4.0.1a.N1.1.binboot system bootflash:/n5000-uk9.4.0.1a.N1.1.binip route 0.0.0.0/0 x.26.146.0/23ip route 0.0.0.0/0 x.26.146.1no system default switchport shutdownmonitor session 1Access Layer Nexus 1000V
dcvsm# sh runversion 4.0(1)feature port-securityusername admin password 5 $<encrypted password>role network-admintelnet server enablessh key rsa 1024 forcekernel core target 0.0.0.0kernel core limit 1system default switchportmac access-list x.1vem 3host vmware id <encrypted password>vem 4host vmware id <encrypted password>vem 5host vmware id <encrypted password>vem 6host vmware id 4998d511-622d-da10-bd0c-0019bbe97d20snmp-server user admin network-admin auth md5 <encrypted password> priv<encrypted password> localizedkeysnmp-server enable traps licensevrf context managementip route 0.0.0.0/0 x.26.146.1switchname dcvsmflow exporter dc-mgmtdescription Netflow Collector v9destination x.26.146.164transport udp 3000source mgmt0version 9template data timeout 300option exporter-stats timeout 120flow exporter lnxnfdescription Cisco Netflow Collectordestination x.26.147.141transport udp 3000source mgmt0version 9template data timeout 300option exporter-stats timeout 120flow monitor ESE-flowdescription Flow to Collectorrecord netflow-originalexporter lnxnftimeout active 1800cache size 4096flow monitor testrecord ipv4 protocol-portexporter lnxnftimeout active 1800cache size 4096vlan 15,98vlan 180private-vlan primaryprivate-vlan association 500-501vlan 181-183vlan 500private-vlan isolatedvlan 501private-vlan communityvlan 3000name erspanvlan 3002name controlvlan 3003name packetvdc dcvsm id 1limit-resource vlan minimum 16 maximum 256limit-resource monitor-session minimum 0 maximum 64limit-resource vrf minimum 16 maximum 8192limit-resource port-channel minimum 0 maximum 256limit-resource u4route-mem minimum 32 maximum 256limit-resource u6route-mem minimum 16 maximum 256port-profile system-mgmtcapability uplinkvmware port-group SystemUplinksswitchport mode trunkswitchport trunk allowed vlan 15,98,180-183,3000,3002-3003switchport private-vlan mapping trunk 180 500-501channel-group auto mode on sub-group cdpip flow monitor ESE-flow inputip flow monitor ESE-flow outputno shutdownsystem vlan 3002-3003state enabledport-profile vm180vmware port-group pg180switchport mode accessswitchport access vlan 180ip flow monitor ESE-flow inputip flow monitor ESE-flow outputno shutdownstate enabledport-profile vmotiondescription VMOTIONvmware port-group pgVM15switchport access vlan 15ip flow monitor ESE-flow inputip flow monitor ESE-flow outputno shutdownstate enabledport-profile erspancapability l3controlvmware port-groupswitchport access vlan 3000no shutdownsystem vlan 3000state enabledinterface port-channel1mtu 1500inherit port-profile system-mgmtinterface port-channel2inherit port-profile system-mgmtinterface port-channel3inherit port-profile system-mgmtinterface Ethernet3/3mtu 1500channel-group 1inherit port-profile system-mgmtinterface Ethernet3/4mtu 1500channel-group 1inherit port-profile system-mgmtinterface Ethernet4/3channel-group 2inherit port-profile system-mgmtinterface Ethernet4/4channel-group 2inherit port-profile system-mgmtinterface Ethernet5/3channel-group 3inherit port-profile system-mgmtinterface Ethernet5/4channel-group 3inherit port-profile system-mgmtinterface mgmt0ip address x.26.147.240/23interface Vethernet1inherit port-profile vm180interface Vethernet2inherit port-profile vmotioninterface Vethernet3mtu 9216inherit port-profile erspaninterface Vethernet4inherit port-profile vmotioninterface Vethernet5mtu 9216inherit port-profile erspaninterface Vethernet6inherit port-profile vmotioninterface Vethernet7mtu 9216inherit port-profile erspaninterface Vethernet8switchport private-vlan host-association 180 500no shutdowninherit port-profile vm180interface Vethernet9interface Vethernet10interface Vethernet11inherit port-profile vm180interface Vethernet12interface Vethernet13interface Vethernet14interface Vethernet15interface Vethernet16interface Vethernet17inherit port-profile vm180interface Vethernet18inherit port-profile vm180interface Vethernet19inherit port-profile vm180boot kickstart bootflash:/nexus-1000v-kickstart-mz.4.0.1a.S1.0.149.bin sup-1boot system bootflash:/nexus-1000v-mz.4.0.1a.S1.0.149.bin sup-1boot kickstart bootflash:/nexus-1000v-kickstart-mz.4.0.1a.S1.0.149.bin sup-2boot system bootflash:/nexus-1000v-mz.4.0.1a.S1.0.149.bin sup-2monitor session 1 type erspan-sourcedescription - to SS1 NAM via VLAN 3000source interface Vethernet1 bothsource interface Vethernet8 bothsource interface Vethernet9 bothsource interface Vethernet10 bothsource interface Vethernet11 bothsource interface Vethernet12 bothsource interface Vethernet13 bothdestination ip 10.8.33.4erspan-id 1ip ttl 64ip prec 0ip dscp 0mtu 1500no shutmonitor session 2 type erspan-sourcedescription - to SS1 IDS1 via VLAN 3000source interface Vethernet1 bothsource interface Vethernet8 bothsource interface Vethernet9 bothsource interface Vethernet10 bothsource interface Vethernet11 bothsource interface Vethernet12 bothsource interface Vethernet13 bothdestination ip 10.8.33.4erspan-id 2ip ttl 64ip prec 0ip dscp 0mtu 1500no shutsvs-domaindomain id 1control vlan 3002packet vlan 3003svs connection VCprotocol vmware-vimremote ip address x.26.146.133vmware dvs datacenter-name ESERTPconnectdcvsm#Enterprise Campus
Figure 4 Enterprise Campus Network Diagram
Core Switch—Catalyst 6500
See Enterprise Core, for configurations.
Distribution Layer Switch - Catalyst 6500
Sfx13-Cat6504E-1!! Last configuration change at 20:15:03 GMT Wed Apr 1 2009 by danhamil-ops! NVRAM config last updated at 20:22:35 GMT Wed Apr 1 2009 by danhamil-ops!upgrade fpd autoversion 12.2no service padservice tcp-keepalives-inservice timestamps debug datetime msec localtime show-timezoneservice timestamps log datetime msec localtime show-timezoneservice password-encryptionservice counters max age 5!hostname SFX13-6504E-1!boot-start-markerboot system flash sup-bootdisk:s72033-advipservicesk9_wan-mz.122-33.SXH4.binboot-end-marker!enable secret 5 <encrypted password>!username admin privilege 15 secret 5 <encrypted password>aaa new-modelaaa group server tacacs+ tacacs-groupserver <tacacs+-server>!aaa authentication login authen-exec-list group tacacs-group local-caseaaa authentication enable default group tacacs-group enableaaa authorization exec author-exec-list group tacacs-group if-authenticatedaaa authorization commands 15 author-15-list group tacacs-group noneaaa accounting send stop-record authentication failureaaa accounting exec default start-stop group tacacs-groupaaa accounting commands 15 default start-stop group tacacs-groupaaa accounting system default start-stop group tacacs-group!aaa session-id commonclock timezone GMT 0call-homealert-group configurationalert-group diagnosticalert-group environmentalert-group inventoryalert-group syslogprofile "CiscoTAC-1"no activeno destination transport-method httpdestination transport-method emaildestination address email callhome@cisco.comdestination address http https://tools.cisco.com/its/service/oddce/services/DDCEServicesubscribe-to-alert-group diagnostic severity minorsubscribe-to-alert-group environment severity minorsubscribe-to-alert-group syslog severity major pattern ".*"subscribe-to-alert-group configuration periodic monthly 23 11:17subscribe-to-alert-group inventory periodic monthly 23 11:02ip subnet-zerono ip source-route!!!ip ftp source-interface GigabitEthernet1/3ip ftp username adminip ftp password 7 <encrypted password>no ip bootp serverip vrf accessrd 13:1route-target export 13:1route-target import 13:1!ip ssh time-out 60ip ssh authentication-retries 2ip scp server enableno ip domain-lookupip domain-name cisco.comlogin block-for 100 attempts 5 within 50login quiet-mode access-class 10login on-failure log!!mls ip slb purge globalmls netflow interfacemls flow ip interface-fullno mls flow ipv6mls nde sender version 5mls sampling packet-based 128 16000mls qosmls cef error action reset!flow-sampler-map csmars-samplemode random one-out-of 100!key chain eigrp-chainkey 10key-string 7 <key>!!!!!!!!!memory reserve critical 1000memory free low-watermark processor 91492memory free low-watermark IO 6710!redundancykeepalive-enablemode ssomain-cpuauto-sync running-configspanning-tree mode pvstspanning-tree extend system-iddiagnostic cns publish cisco.cns.device.diag_resultsdiagnostic cns subscribe cisco.cns.device.diag_commandsfabric timer 15!vlan internal allocation policy ascendingvlan access-log ratelimit 2000!class-map match-all coppclass-igpmatch access-group name coppacl-igpclass-map match-all coppclass-monitoringmatch access-group name coppacl-monitoringclass-map match-all coppclass-filemanagementmatch access-group name coppacl-filemanagementclass-map match-all coppclass-managementmatch access-group name coppacl-management!!policy-map copp-policyclass coppclass-igppolice cir 300000 bc 3000 be 3000 conform-action transmit exceed-action drop violate-action dropclass coppclass-filemanagementpolice cir 6000000 bc 60000 be 60000 conform-action transmit exceed-action drop violate-action dropclass coppclass-managementpolice cir 500000 bc 5000 be 5000 conform-action transmit exceed-action drop violate-action dropclass coppclass-monitoringpolice cir 900000 bc 9000 be 9000 conform-action transmit exceed-action drop violate-action dropclass class-defaultpolice cir 500000 bc 5000 be 5000 conform-action transmit exceed-action drop violate-action drop!!!!!!interface Port-channel1switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 12,13switchport mode trunk!interface GigabitEthernet1/1no ip address!interface GigabitEthernet1/2no ip addressshutdown!interface GigabitEthernet1/3description FLASH NETip address <management IP> 255.255.254.0ip access-group 133 inip access-group 134 outload-interval 60!interface TenGigabitEthernet1/4description CAMPUS ACCESS SFX13-4500-1 Ten 1/1ip vrf forwarding accessip address 10.240.10.4 255.255.255.254ip hello-interval eigrp 1 1ip hold-time eigrp 1 3ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainip policy route-map nac_redirectload-interval 60!interface TenGigabitEthernet1/5description CAMPUS ACCESS SFX13-4500-2 Ten 1/2ip vrf forwarding accessip address 10.240.10.6 255.255.255.254ip hello-interval eigrp 1 1ip hold-time eigrp 1 3ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainip policy route-map nac_redirectload-interval 60!interface TenGigabitEthernet3/1description Connection to SFX13-ASA5580-1 T5/0switchportswitchport access vlan 50switchport mode accessload-interval 30!interface TenGigabitEthernet3/2description Connection to SFX13-ASA5580-1 T5/1switchportswitchport access vlan 16switchport mode accessload-interval 30!interface TenGigabitEthernet3/3no ip addressshutdown!interface TenGigabitEthernet3/4no ip addressshutdown!interface TenGigabitEthernet3/5no ip addressshutdown!interface TenGigabitEthernet3/6no ip addressshutdown!interface TenGigabitEthernet3/7no ip addressshutdown!interface TenGigabitEthernet3/8no ip addressshutdown!interface TenGigabitEthernet3/9no ip addressshutdown!interface TenGigabitEthernet3/10no ip addressshutdown!interface TenGigabitEthernet3/11no ip addressshutdown!interface TenGigabitEthernet3/12no ip addressshutdown!interface TenGigabitEthernet3/13no ip addressshutdown!interface TenGigabitEthernet3/14no ip addressshutdown!interface TenGigabitEthernet3/15no ip addressshutdown!interface TenGigabitEthernet3/16no ip addressshutdown!interface GigabitEthernet4/1no ip addressshutdown!interface GigabitEthernet4/2no ip addressshutdown!interface GigabitEthernet4/3no ip addressshutdown!interface GigabitEthernet4/4no ip addressshutdown!interface GigabitEthernet4/5no ip addressshutdown!interface GigabitEthernet4/6no ip addressshutdown!interface GigabitEthernet4/7no ip addressshutdown!interface GigabitEthernet4/8no ip addressshutdown!interface GigabitEthernet4/9no ip addressshutdown!interface GigabitEthernet4/10no ip addressshutdown!interface GigabitEthernet4/11no ip addressshutdown!interface GigabitEthernet4/12description IPS bypassswitchportswitchport access vlan 12switchport mode accessshutdown!interface GigabitEthernet4/13description IPS bypassswitchportswitchport access vlan 13switchport mode accessshutdown!interface GigabitEthernet4/14no ip addressshutdown!interface GigabitEthernet4/15no ip addressshutdown!interface GigabitEthernet4/16no ip addressshutdown!interface GigabitEthernet4/17no ip addressshutdown!interface GigabitEthernet4/18no ip addressshutdown!interface GigabitEthernet4/19no ip addressshutdown!interface GigabitEthernet4/20no ip addressshutdown!interface GigabitEthernet4/21no ip addressshutdown!interface GigabitEthernet4/22no ip addressshutdown!interface GigabitEthernet4/23description description Connection to SFX13-CAS-1 Trusted port (eth0)switchportswitchport access vlan 400switchport mode access!interface GigabitEthernet4/24description Connection to SFX13-CAS-1 untrusted port (eth1)switchportswitchport access vlan 300switchport mode access!interface GigabitEthernet4/25no ip addressshutdown!interface GigabitEthernet4/26no ip addressshutdown!interface GigabitEthernet4/27no ip addressshutdown!interface GigabitEthernet4/28no ip addressshutdown!interface GigabitEthernet4/29description trunk to sfx14-c6506-1switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 12,13switchport mode trunkchannel-group 1 mode on!interface GigabitEthernet4/30description trunk to sfx14-c6506-1switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 12,13switchport mode trunkchannel-group 1 mode on!interface GigabitEthernet4/31description trunk to sfx14-c6506-1switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 12,13switchport mode trunkchannel-group 1 mode on!interface GigabitEthernet4/32description trunk to sfx14-c6506-1switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 12,13switchport mode trunkchannel-group 1 mode on!interface GigabitEthernet4/33no ip addressshutdown!interface GigabitEthernet4/34no ip addressshutdown!interface GigabitEthernet4/35no ip addressshutdown!interface GigabitEthernet4/36no ip addressshutdown!interface GigabitEthernet4/37description Connection to sfx14-c6506-1 g3/37switchportswitchport access vlan 50switchport mode accessload-interval 30!interface GigabitEthernet4/38no ip addressshutdown!interface GigabitEthernet4/39no ip addressshutdown!interface GigabitEthernet4/40no ip addressshutdown!interface GigabitEthernet4/41no ip addressshutdown!interface GigabitEthernet4/42no ip addressshutdown!interface GigabitEthernet4/43description connection to SFX-6504E-2 4/43 for CAS HAswitchportswitchport access vlan 300switchport mode access!interface GigabitEthernet4/44description RSPAN Connection to SFX13-6504E-2 port G4/44switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 500,501switchport mode trunkload-interval 60!interface GigabitEthernet4/45no ip address!interface GigabitEthernet4/46description SAFE CORE SFX14-6504E-2 Gig 4/46ip address 10.242.10.31 255.255.255.254ip flow ingressip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60mls netflow samplingflow-sampler csmars-sample!interface GigabitEthernet4/47description SAFE CORE SFX14-6504E-1 Gig 4/47ip address 10.242.10.29 255.255.255.254ip flow ingressip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60mls netflow samplingflow-sampler csmars-sample!interface GigabitEthernet4/48description trunk to SFX13-6504E-2 Gig 4/48switchportswitchport trunk encapsulation dot1qswitchport trunk allowed vlan 2,16,40,400switchport mode trunkload-interval 60!interface Vlan1no ip addressshutdown!interface Vlan2description layer 3 connection to SFX13-6504E-2 Gig 4/48ip address 10.240.10.2 255.255.255.254ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainload-interval 60!interface Vlan12description Outside IPSmac-address 0000.0000.0012ip address 10.240.10.12 255.255.255.254ip flow ingressip hello-interval eigrp 1 1ip hold-time eigrp 1 3ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chainmls netflow samplingflow-sampler csmars-sample!interface Vlan13description Inside IPSmac-address 0000.0000.0013ip vrf forwarding accessip address 10.240.10.13 255.255.255.254ip hello-interval eigrp 1 1ip hold-time eigrp 1 3ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chain!interface Vlan16description Layer-3 connection to ASA Outside Interfacesip address 10.240.10.17 255.255.255.248ip authentication mode eigrp 1 md5ip authentication key-chain eigrp 1 eigrp-chain!interface Vlan40description trunk port to SFX13-6504E-1 for access VRFmac-address 0000.0000.0040ip vrf forwarding accessip address 10.240.10.40 255.255.255.254!interface Vlan300description Routing interface for NAC CAS untrusted VLAN interfacemac-address 0000.0000.0300ip vrf forwarding accessip address 10.240.10.26 255.255.255.248standby 1 ip 10.240.10.25standby 1 priority 105standby 1 preemptstandby 1 track TenGigabitEthernet1/4standby 1 track TenGigabitEthernet1/5!interface Vlan400description Routing interface for NAC CAS trusted VLAN interfaceip address 10.240.10.34 255.255.255.248!router eigrp 1passive-interface Vlan300passive-interface Vlan400network 10.0.0.0auto-summary!address-family ipv4 vrf accessnetwork 10.0.0.0auto-summaryautonomous-system 1exit-address-family!ip classlessip route 172.26.0.0 255.255.0.0 172.26.170.1!ip flow-export source GigabitEthernet1/3ip flow-export version 5ip flow-export destination <CS-MARS> 2055!no ip http serverno ip http secure-serverip tacacs source-interface GigabitEthernet1/3!ip access-list extended coppacl-filemanagementremark CoPP File transfer traffic classpermit tcp 172.26.0.0 0.0.255.255 eq ftp host <management IP> gt 1023 establishedpermit tcp 172.26.0.0 0.0.255.255 eq ftp-data host <management IP> gt 1023permit tcp 172.26.0.0 0.0.255.255 gt 1023 host <management IP> gt 1023 establishedpermit udp 172.26.0.0 0.0.255.255 gt 1023 host <management IP> gt 1023ip access-list extended coppacl-igpremark IGP traffic classpermit eigrp any host 224.0.0.10permit eigrp 10.0.0.0 0.255.255.255 host <management IP>ip access-list extended coppacl-managementremark CoPP management traffic classpermit tcp 172.26.0.0 0.0.255.255 eq tacacs host <management IP> establishedpermit tcp 172.26.0.0 0.0.255.255 host <management IP> eq 22permit tcp 172.26.0.0 0.0.255.255 host <management IP> eq telnetpermit udp 172.26.0.0 0.0.255.255 host <management IP> eq snmppermit udp 172.26.0.0 0.0.255.255 host <management IP> eq ntpip access-list extended coppacl-monitoringremark CoPP monitoring traffic classpermit icmp any any ttl-exceededpermit icmp any any port-unreachablepermit icmp any any echo-replypermit icmp any any echoip access-list extended nac_redirect_acldeny tcp 10.240.120.0 0.0.0.255 host 10.8.51.10 eq wwwdeny tcp 10.240.220.0 0.0.0.255 host 10.8.51.10 eq wwwdeny tcp 10.240.120.0 0.0.0.255 host 10.8.51.10 eq 443deny tcp 10.240.220.0 0.0.0.255 host 10.8.51.10 eq 443permit tcp 10.240.220.0 0.0.0.255 any eq wwwpermit tcp 10.240.220.0 0.0.0.255 any eq 443permit tcp 10.240.120.0 0.0.0.255 any eq wwwpermit tcp 10.240.120.0 0.0.0.255 any eq 443!logging trap criticallogging source-interface GigabitEthernet1/3logging <CS-MARS>access-list 10 permit 172.26.191.92access-list 55 remark ACL for SNMP access to deviceaccess-list 55 permit <CS-MARS>access-list 55 deny any logaccess-list 111 remark ACL for SSHaccess-list 111 permit tcp 172.26.0.0 0.0.255.255 any eq 22access-list 111 deny ip any any log-inputaccess-list 112 remark ACL for last resort accessaccess-list 112 permit tcp host 172.26.191.92 any eq 22access-list 112 permit tcp host <CS-MARS> any eq 22access-list 112 deny ip any any log-inputaccess-list 133 permit icmp 172.26.0.0 0.0.255.255 host <management IP> ttl-exceededaccess-list 133 permit icmp 172.26.0.0 0.0.255.255 host <management IP> port-unreachableaccess-list 133 permit icmp 172.26.0.0 0.0.255.255 host <management IP> echo-replyaccess-list 133 permit icmp 172.26.0.0 0.0.255.255 host <management IP> echoaccess-list 133 permit tcp 172.26.0.0 0.0.255.255 eq tacacs host <management IP> establishedaccess-list 133 permit tcp 172.26.0.0 0.0.255.255 host <management IP> eq tacacsaccess-list 133 permit udp 172.26.0.0 0.0.255.255 host <management IP> eq ntpaccess-list 133 permit tcp 172.26.0.0 0.0.255.255 host <management IP> eq 22access-list 133 permit tcp 172.26.0.0 0.0.255.255 eq ftp host <management IP> gt 1023 establishedaccess-list 133 permit tcp 172.26.0.0 0.0.255.255 eq ftp-data host <management IP> gt 1023access-list 133 permit tcp 172.26.0.0 0.0.255.255 gt 1023 host <management IP> gt 1023 establishedaccess-list 133 permit udp 172.26.0.0 0.0.255.255 gt 1023 host <management IP> gt 1023access-list 133 permit udp host <CS-MARS> host <management IP> eq snmpaccess-list 133 deny ip any any logaccess-list 134 permit ip host <management IP> 172.26.0.0 0.0.255.255access-list 134 deny ip any any log!route-map nac_redirect permit 10match ip address nac_redirect_aclset ip vrf access next-hop 10.240.10.30!snmp-server community csmars RO 55snmp-server enable traps cpu thresholdsnmp-server host <CS-MARS> csmars memory cputacacs-server host <tacacs+-server> single-connection key 7 <secret-key>tacacs-server directed-request!radius-server source-ports 1645-1646!control-planeservice-policy input copp-policy!!dial-peer cor custom!!!banner loginUNAUTHORIZED ACCESS TO THIS DEVICE IS PROHIBITEDYou must have explicit, authorized permission to access or configure this device.Unauthorized attempts and actions to access or use this system may result in civil and/or criminal penalties.All activities performed on this device are logged and monitored.!line con 0session-timeout 3exec-timeout 3 0login authentication authen-exec-listline vty 0 3session-timeout 3access-class 111 inexec-timeout 3 0password 7 <encrypted password>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listtransport preferred nonetransport input sshtransport output noneline vty 4session-timeout 3access-class 112 inexec-timeout 3 0password 7 <encrypted password>authorization commands 15 author-15-listauthorization exec author-exec-listlogin authentication authen-exec-listtransport preferred nonetransport input sshtransport output noneline vty 5 15no exec!exception protocol ftpexception dump <core-dump-host>!monitor session 1 source interface Te1/4 - 5monitor session 1 destination interface Gi4/45monitor session 2 destination interface Gi4/45monitor sessi



