[Nocrancid] autopop-onenet.net router config diffs

rancid at rancid.noc.onenet.net rancid at rancid.noc.onenet.net
Mon Nov 23 15:02:05 CST 2015


Index: configs/core.end.onenet.net
===================================================================
--- configs/core.end.onenet.net	(revision 136997)
+++ configs/core.end.onenet.net	(working copy)
@@ -1,12 +1,12 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at ENID-MX480-RE0> show system commit 
+#   2015-11-23 14:37:03 CST by sky via cli commit synchronize
 #   2015-11-11 11:37:59 CST by andrew via cli commit synchronize
 #   2015-11-11 00:41:24 CST by andrew via cli commit confirmed, rollback in 3mins synchronize
 #   2015-11-11 00:36:16 CST by andrew via cli commit confirmed, rollback in 3mins synchronize
 #   2015-11-11 00:35:17 CST by andrew via cli commit confirmed, rollback in 3mins synchronize
 #   2015-11-11 00:33:51 CST by andrew via cli commit confirmed, rollback in 3mins synchronize
-#   2015-11-11 00:29:39 CST by andrew via cli commit confirmed, rollback in 3mins synchronize
 # grnoc-mon at ENID-MX480-RE0> show chassis environment 
 # Class Item                           Status     Measurement
 # Temp  PEM 0                          OK        
@@ -257,7 +257,7 @@
 # grnoc-mon at ENID-MX480-RE0> show system uptime 
 # System booted: 2015-06-06 23:35 CDT 
 # Protocols started: 2015-06-06 23:37 CDT 
-# Last configured: 2015-11-11 11:37 CST  by andrew
+# Last configured: 2015-11-23 14:37 CST  by sky
 # 
 # {master}
 # grnoc-mon at ENID-MX480-RE0> show interface terse 
@@ -295,6 +295,7 @@
 #xe-0/1/1.423 up up
 #xe-0/1/1.424 up up
 #xe-0/1/1.425 up up
+#xe-0/1/1.426 up up
 #xe-0/1/1.1414 up up
 #xe-0/1/1.32767 up up
 #ge-0/2/0 up up
@@ -414,7 +415,7 @@
 #pp0 up up
 #tap up up
 # grnoc-mon at ENID-MX480-RE0> show configuration 
-## Last commit: 2015-11-11 11:37:59 CST by andrew
+## Last commit: 2015-11-23 14:37:03 CST by sky
 version 13.3R6.5;
 groups {
     re0 {
@@ -913,6 +914,10 @@
                 address 164.58.9.109/30;
             }
         }
+        unit 426 {
+            description "SHARE-MEDICAL-CENTER-PROFESSIONAL-BLDG-20M-CIR000XXXX [ORDERED]";
+            vlan-id 426;
+        }
         unit 1414 {
             description COMANCHE-PS-HS-1G-CIR0005881-LR;
             vlan-tags outer 414 inner 501;
Index: configs/maysville-es.client.onenet.net
===================================================================
--- configs/maysville-es.client.onenet.net	(revision 137061)
+++ configs/maysville-es.client.onenet.net	(working copy)
@@ -112,7 +112,7 @@
 # WARNING: / was not properly dismounted
 # 
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show version 
-# Hostname: MAYSVILLE-ES-LEASED-ASSET-TAG-004945 # file list /var/tmp detail # Model: srx240h2 # JUNOS Software Release [12.1X44-D35.5] #  # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> file list /var/tmp detail # lrw-r--r--  1 root  wheel         11 May 19  2014 /var/tmp@ -> /cf/var/tmp
+# Hostname: MAYSVILLE-ES-LEASED-ASSET-TAG-004945 # Model: srx240h2 # file list /var/tmp detail # JUNOS Software Release [12.1X44-D35.5] #  # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> file list /var/tmp detail # lrw-r--r--  1 root  wheel         11 May 19  2014 /var/tmp@ -> /cf/var/tmp
 # total files: 1
 # 
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show system uptime 
Index: configs/core1.lan-mx80.onenet.net
===================================================================
--- configs/core1.lan-mx80.onenet.net	(revision 137061)
+++ configs/core1.lan-mx80.onenet.net	(working copy)
@@ -196,7 +196,7 @@
 # -rw-rw----  1 root  field   52711424 Jun 10 15:37 ifinfo.core.1
 # -rw-rw----  1 root  field   52711424 Jun 10 15:40 ifinfo.core.2
 # -rw-rw----  1 root  field   52711424 Jun 10 15:47 ifinfo.core.3
-# -rw-rw----  1 root  field   52711424 Nov 23 13:55 ifinfo.core.4
+# -rw-rw----  1 root  field   52711424 Nov 23 14:55 ifinfo.core.4
 # drwxrwxrwx  2 root  wheel        512 Aug 13  2012 install/
 # -rw-r--r--  1 eng   field   99542994 May 30  2013 jinstall-ppc-11.4R7.5-domestic-signed.tgz
 # -rw-r--r--  1 upgrades field 150276951 Aug 8   2014 jinstall-ppc-12.3R7.7-domestic-signed.tgz
Index: configs/hub.dur.onenet.net
===================================================================
--- configs/hub.dur.onenet.net	(revision 137061)
+++ configs/hub.dur.onenet.net	(working copy)
@@ -309,11 +309,11 @@
 #t1-2/0/2:9 up up
 #t1-2/0/2:9.0 up up
 #t1-2/0/2:10 down down
-#t1-2/0/2:11 up down
-#t1-2/0/2:11.0 up down
+#t1-2/0/2:11 up up
+#t1-2/0/2:11.0 up up
 #t1-2/0/2:12 down down
-#t1-2/0/2:13 up down
-#t1-2/0/2:13.0 up down
+#t1-2/0/2:13 up up
+#t1-2/0/2:13.0 up up
 #t1-2/0/2:14 up up
 #t1-2/0/2:14.0 up up
 #t1-2/0/2:15 down down
@@ -321,10 +321,10 @@
 #t1-2/0/2:16.0 up up
 #t1-2/0/2:17 down down
 #t1-2/0/2:18 down down
-#t1-2/0/2:19 up down
-#t1-2/0/2:19.0 up down
-#t1-2/0/2:20 up down
-#t1-2/0/2:20.0 up down
+#t1-2/0/2:19 up up
+#t1-2/0/2:19.0 up up
+#t1-2/0/2:20 up up
+#t1-2/0/2:20.0 up up
 #t1-2/0/2:21 up up
 #t1-2/0/2:21.0 up up
 #t1-2/0/2:22 down down
@@ -374,7 +374,7 @@
 #fe-2/1/1.0 up up
 #fe-2/1/2 up up
 #fe-2/1/2.0 up up
-#fe-2/1/3 down down
+#fe-2/1/3 down up
 #ge-2/2/0 down down
 #pc-2/2/0 up up
 #pc-2/2/0.16383 up up
@@ -385,7 +385,7 @@
 #gr-2/3/0 up up
 #ip-2/3/0 up up
 #lsq-2/3/0 up up
-#lsq-2/3/0.2 up down
+#lsq-2/3/0.2 up up
 #lsq-2/3/0.9 up up
 #lsq-2/3/0.10 up up
 #mt-2/3/0 up up
Index: configs/core3.okc-m120.onenet.net
===================================================================
--- configs/core3.okc-m120.onenet.net	(revision 137058)
+++ configs/core3.okc-m120.onenet.net	(working copy)
@@ -527,8 +527,8 @@
 #t1-2/3/0:3:9.0 up up
 #t1-2/3/0:3:10 up up
 #t1-2/3/0:3:10.0 up up
-#t1-2/3/0:3:11 up up
-#t1-2/3/0:3:11.0 up up
+#t1-2/3/0:3:11 up down
+#t1-2/3/0:3:11.0 up down
 #t1-2/3/0:3:12 up up
 #t1-2/3/0:3:12.0 up up
 #t1-2/3/0:3:13 up down
Index: configs/rpswi2.rp1f3.onenet.net
===================================================================
--- configs/rpswi2.rp1f3.onenet.net	(revision 137061)
+++ configs/rpswi2.rp1f3.onenet.net	(working copy)
@@ -598,8 +598,8 @@
 #ge-1/0/47.0 up down
 #ge-2/0/0 up up
 #ge-2/0/0.0 up up
-#ge-2/0/1 up down
-#ge-2/0/1.0 up down
+#ge-2/0/1 up up
+#ge-2/0/1.0 up up
 #ge-2/0/2 up up
 #ge-2/0/2.0 up up
 #ge-2/0/3 up up
Index: configs/core1.ptc.onenet.net
===================================================================
--- configs/core1.ptc.onenet.net	(revision 137058)
+++ configs/core1.ptc.onenet.net	(working copy)
@@ -1,12 +1,12 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at TULSA-PTC1-MX480-RE0> show system commit 
+#   2015-11-23 14:37:28 CST by joel via cli commit synchronize
 #   2015-11-23 11:17:29 CST by joel via cli commit synchronize
 #   2015-11-20 18:41:14 CST by andrew via cli commit synchronize
 #   2015-11-20 18:32:57 CST by andrew via cli commit synchronize
 #   2015-11-20 18:27:53 CST by andrew via cli commit confirmed, rollback in 3mins synchronize
 #   2015-11-20 16:51:09 CST by sean via cli commit synchronize
-#   2015-11-20 10:40:06 CST by joel via cli commit synchronize
 # grnoc-mon at TULSA-PTC1-MX480-RE0> show chassis environment 
 # Class Item                           Status     Measurement
 # Temp  PEM 0                          OK        
@@ -321,7 +321,7 @@
 # grnoc-mon at TULSA-PTC1-MX480-RE0> show system uptime 
 # System booted: 2015-06-07 23:52 CDT 
 # Protocols started: 2015-06-07 23:55 CDT 
-# Last configured: 2015-11-23 11:17 CST  by joel
+# Last configured: 2015-11-23 14:37 CST  by joel
 # 
 # {master}
 # grnoc-mon at TULSA-PTC1-MX480-RE0> show interface terse 
@@ -440,7 +440,7 @@
 #pp0 up up
 #tap up up
 # grnoc-mon at TULSA-PTC1-MX480-RE0> show configuration 
-## Last commit: 2015-11-23 11:17:29 CST by joel
+## Last commit: 2015-11-23 14:37:28 CST by joel
 version 13.3R6.5;
 groups {
     re0 {
@@ -850,7 +850,7 @@
             family inet {
                 rpf-check;
                 filter {
-                    inactive: input Avant-Public-Schools-20M-CIR0006288-LR;
+                    input Avant-Public-Schools-20M-CIR0006288-LR;
                 }
                 policer {
                     input 20M-POL;
Index: configs/acx.cai.hart-acx2100.onenet.net
===================================================================
--- configs/acx.cai.hart-acx2100.onenet.net	(revision 137058)
+++ configs/acx.cai.hart-acx2100.onenet.net	(working copy)
@@ -73,6 +73,7 @@
 # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> show chassis sfm detail 
 # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> show chassis ssb 
 # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> show system boot-messages 
+# show version
 # platform_early_bootinit: MX-PPC Series Early Boot Initialization
 # mxppc_set_re_type: hw.board.type is ACX-2100
 # WDOG initialized
@@ -141,7 +142,8 @@
 # WARNING: /var was not properly dismounted
 # 
 # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> show version 
-# Hostname: HARTSHORNE-PUBLIC-LIBRARY-ACX2100 # Model: acx2100 # JUNOS Crypto Software Suite [12.3X54-D10.6] # JUNOS Base OS Software Suite [12.3X54-D10.6] # JUNOS Kernel Software Suite [12.3X54-D10.6] # JUNOS Base OS boot [12.3X54-D10.6] # JUNOS Packet Forwarding Engine Support (ACX) [12.3X54-D10.6] # JUNOS Online Documentation [12.3X54-D10.6] # JUNOS Routing Software Suite [12.3X54-D10.6] #  # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> file list /var/tmp detail # 
+# Hostname: HARTSHORNE-PUBLIC-LIBRARY-ACX2100 # Model: acx2100 # JUNOS Crypto Software Suite [12.3X54-D10.6] # JUNOS Base OS Software Suite [12.3X54-D10.6] # JUNOS Kernel Software Suite [12.3X54-D10.6] # JUNOS Base OS boot [12.3X54-D10.6] # JUNOS Packet Forwarding Engine Support (ACX) [12.3X54-D10.6] # JUNOS Online Documentation [12.3X54-D10.6] # JUNOS Routing Software Suite [12.3X54-D10.6] #  # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> file list /var/tmp detail # show system uptime
+# 
 # /var/tmp:
 # total blocks: 291872
 # drwxr-xr-x  2 root  field        512 Dec 31  2009 gres-tp/
Index: configs/avant-ps-srx220.client.onenet.net
===================================================================
--- configs/avant-ps-srx220.client.onenet.net	(revision 137057)
+++ configs/avant-ps-srx220.client.onenet.net	(working copy)
@@ -1,12 +1,12 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at AVANT-PS-LR-004643> show system commit 
+#   2015-11-23 14:24:51 CST by joel via cli commit confirmed, rollback in 5mins
 #   2015-11-23 10:50:15 CST by joel via cli
 #   2015-10-30 11:51:13 CDT by admin via cli commit confirmed, rollback in 5mins
 #   2015-10-30 11:05:17 CDT by joel via cli commit confirmed, rollback in 5mins
 #   2015-10-29 14:49:53 CDT by joel via cli
 #   2015-10-06 17:37:44 CDT by admin via cli
-#   2015-10-06 17:34:59 CDT by admin via cli
 # grnoc-mon at AVANT-PS-LR-004643> show chassis environment 
 # Class Item                           Status     Measurement
 # Temp  Routing Engine                 OK        
@@ -104,7 +104,7 @@
 # grnoc-mon at AVANT-PS-LR-004643> show system uptime 
 # System booted: 2015-09-14 13:40 CDT 
 # Protocols started: 2015-09-14 13:42 CDT 
-# Last configured: 2015-11-23 10:50 CST  by joel
+# Last configured: 2015-11-23 14:24 CST  by joel
 # 
 # grnoc-mon at AVANT-PS-LR-004643> show interface terse 
 #Interface Admin Link
@@ -151,7 +151,7 @@
 #vlan.4 up up
 #vlan.999 up down
 # grnoc-mon at AVANT-PS-LR-004643> show configuration 
-## Last commit: 2015-11-23 10:50:15 CST by joel
+## Last commit: 2015-11-23 14:24:51 CST by joel
 version 12.1X46-D20.5;
 system {
     host-name AVANT-PS-LR-004643;
@@ -390,6 +390,28 @@
     }
 }
 security {
+    address-book {
+        global {
+            address HOST-10.2.0.2 {
+                wildcard-address 10.2.0.2/32;
+            }
+            address HOST-10.2.0.135 {
+                wildcard-address 10.2.0.135/32;
+            }
+            address HOST-10.2.0.130 {
+                wildcard-address 10.2.0.130/32;
+            }
+            address HOST-10.2.0.27 {
+                wildcard-address 10.2.0.27/32;
+            }
+            address HOST-10.2.0.4 {
+                wildcard-address 10.2.0.4/32;
+            }
+            address HOST-10.2.0.10 {
+                wildcard-address 10.2.0.10/32;
+            }
+        }
+    }
     screen {
         ids-option UNTRUST-SCREEN {
             icmp {
@@ -413,6 +435,11 @@
     }
     nat {
         source {
+            pool AVANT-NAT-OUTSIDE {
+                address {
+                    164.58.139.193/32 to 164.58.139.254/32;
+                }
+            }
             rule-set TRUST-TO-UNTRUST-NAT {
                 from zone TRUST;
                 to zone UNTRUST;
@@ -422,7 +449,9 @@
                     }
                     then {
                         source-nat {
-                            interface;
+                            pool {
+                                AVANT-NAT-OUTSIDE;
+                            }
                         }
                     }
                 }
@@ -442,6 +471,83 @@
                 }
             }
         }
+        static {
+            rule-set STATIC-NAT {
+                from zone UNTRUST;
+                rule NAT-194 {
+                    match {
+                        destination-address 164.58.139.194/32;
+                    }
+                    then {
+                        static-nat {
+                            prefix {
+                                10.2.0.2/32;
+                            }
+                        }
+                    }
+                }
+                rule NAT-254 {
+                    match {
+                        destination-address 164.58.139.254/32;
+                    }
+                    then {
+                        static-nat {
+                            prefix {
+                                10.2.0.135/32;
+                            }
+                        }
+                    }
+                }
+                rule NAT-253 {
+                    match {
+                        destination-address 164.58.139.253/32;
+                    }
+                    then {
+                        static-nat {
+                            prefix {
+                                10.2.0.130/32;
+                            }
+                        }
+                    }
+                }
+                rule NAT-252 {
+                    match {
+                        destination-address 164.58.139.252/32;
+                    }
+                    then {
+                        static-nat {
+                            prefix {
+                                10.2.0.27/32;
+                            }
+                        }
+                    }
+                }
+                rule NAT-251 {
+                    match {
+                        destination-address 164.58.139.251/32;
+                    }
+                    then {
+                        static-nat {
+                            prefix {
+                                10.2.0.4/32;
+                            }
+                        }
+                    }
+                }
+                rule NAT-193 {
+                    match {
+                        destination-address 164.58.139.193/32;
+                    }
+                    then {
+                        static-nat {
+                            prefix {
+                                10.2.0.10/32;
+                            }
+                        }
+                    }
+                }
+            }
+        }
     }
     policies {
         from-zone TRUST to-zone UNTRUST {
@@ -468,6 +574,68 @@
                 }
             }
         }
+        from-zone UNTRUST to-zone TRUST {
+            policy NAT-194 {
+                match {
+                    source-address any;
+                    destination-address HOST-10.2.0.2;
+                    application [ TIMBUKTU junos-http junos-https junos-ssh ];
+                }
+                then {
+                    permit;
+                }
+            }
+            policy NAT-254 {
+                match {
+                    source-address any;
+                    destination-address HOST-10.2.0.135;
+                    application [ junos-http NAT-254 ];
+                }
+                then {
+                    permit;
+                }
+            }
+            policy NAT-253 {
+                match {
+                    source-address any;
+                    destination-address HOST-10.2.0.130;
+                    application junos-http;
+                }
+                then {
+                    permit;
+                }
+            }
+            policy NAT-252 {
+                match {
+                    source-address any;
+                    destination-address HOST-10.2.0.27;
+                    application any;
+                }
+                then {
+                    permit;
+                }
+            }
+            policy NAT-251 {
+                match {
+                    source-address any;
+                    destination-address HOST-10.2.0.4;
+                    application MS-RDP;
+                }
+                then {
+                    permit;
+                }
+            }
+            policy NAT-193 {
+                match {
+                    source-address any;
+                    destination-address HOST-10.2.0.10;
+                    application any;
+                }
+                then {
+                    permit;
+                }
+            }
+        }
     }
     zones {
         security-zone TRUST {
@@ -562,6 +730,22 @@
         }
     }
 }
+applications {
+    application TIMBUKTU {
+        term tcp-407 protocol tcp destination-port 407;
+        term tcp-1417-1420 protocol tcp destination-port 1417-1420;
+        term tcp-8901 protocol tcp destination-port 8901;
+        term udp-407 protocol udp destination-port 407;
+        term udp-1419 protocol udp destination-port 1419;
+    }
+    application NAT-254 {
+        term tcp-8001 protocol tcp destination-port 8001;
+        term tcp-8105 protocol tcp destination-port 8105;
+    }
+    application MS-RDP {
+        term tcp-3389 protocol tcp destination-port 3389;
+    }
+}
 ethernet-switching-options {
     secure-access-port {
         interface ge-0/0/1.0 {
Index: configs/maysville-hs.client.onenet.net
===================================================================
--- configs/maysville-hs.client.onenet.net	(revision 137061)
+++ configs/maysville-hs.client.onenet.net	(working copy)
@@ -45,6 +45,7 @@
 #     Serial ID                      ACLC7669
 # 
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show chassis scb 
+# show chassis sfm detail
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show chassis sfm detail
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show chassis ssb 
 # show system boot-messages
@@ -618,6 +619,7 @@
 # OSPF instance is not running
 # 
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show bfd session 
+quit
 
 0 sessions, 0 clients
 Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
Index: configs/hub.tsb.onenet.net
===================================================================
--- configs/hub.tsb.onenet.net	(revision 137061)
+++ configs/hub.tsb.onenet.net	(working copy)
@@ -199,7 +199,7 @@
 # -rw-rw----  1 root  field   51994624 Oct 24  2013 ifinfo.core.1
 # -rw-rw----  1 root  field   51974144 Oct 24  2013 ifinfo.core.2
 # -rw-rw----  1 root  field   52744192 Oct 24  2013 ifinfo.core.3
-# -rw-rw----  1 root  field   52727808 Nov 23 13:55 ifinfo.core.4
+# -rw-rw----  1 root  field   52727808 Nov 23 14:55 ifinfo.core.4
 # drwxrwxrwx  2 root  wheel        512 Oct 12  2012 install/
 # -rw-rw----  1 root  field   33464320 Mar 3   2014 jdiameterd.core.0
 # -rw-r--r--  1 eng   field   99542994 Apr 23  2013 jinstall-ppc-11.4R7.5-domestic-signed.tgz
Index: configs/odmhsas.central-office.okc.client.onenet.net
===================================================================
--- configs/odmhsas.central-office.okc.client.onenet.net	(revision 137045)
+++ configs/odmhsas.central-office.okc.client.onenet.net	(working copy)
@@ -188,7 +188,7 @@
 #st0.21 up up
 #st0.22 up up
 #st0.23 up up
-#st0.24 up up
+#st0.24 up down
 #st0.25 up up
 #st0.26 up up
 #st0.27 up up



More information about the Nocrancid mailing list