[Nocrancid] autopop-onenet.net router config diffs

rancid at rancid.noc.onenet.net rancid at rancid.noc.onenet.net
Mon Apr 4 11:03:07 CDT 2016


Index: configs/maysville-es.client.onenet.net
===================================================================
--- configs/maysville-es.client.onenet.net	(revision 141383)
+++ configs/maysville-es.client.onenet.net	(working copy)
@@ -20,7 +20,6 @@
 # Power Power Supply 0                 OK        
 # 
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show chassis firmware 
-# show chassis fpc detail
 # Part                     Type       Version
 # FPC 0                    O/S        Version 12.1X44-D35.5 by builder on 2014-05
 # FWDD                     O/S        Version 12.1X44-D35.5 by builder on 2014-05
@@ -45,10 +44,8 @@
 #     Serial ID                      ACDT6307
 # 
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show chassis scb 
-# show chassis sfm detail
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show chassis sfm detail
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show chassis ssb 
-# show system boot-messages
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show system boot-messages 
 # kld_map_v: 0x8ff80000, kld_map_p: 0x0
 # Copyright (c) 1996-2014, Juniper Networks, Inc.
@@ -113,11 +110,10 @@
 # WARNING: / was not properly dismounted
 # 
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show version 
-# Hostname: MAYSVILLE-ES-LEASED-ASSET-TAG-004945 # Model: srx240h2 # file list /var/tmp detail # JUNOS Software Release [12.1X44-D35.5] #  # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> file list /var/tmp detail # lrw-r--r--  1 root  wheel         11 May 19  2014 /var/tmp@ -> /cf/var/tmp
+# Hostname: MAYSVILLE-ES-LEASED-ASSET-TAG-004945 # Model: srx240h2 # JUNOS Software Release [12.1X44-D35.5] #  # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> file list /var/tmp detail # lrw-r--r--  1 root  wheel         11 May 19  2014 /var/tmp@ -> /cf/var/tmp
 # total files: 1
 # 
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show system uptime 
-# show interface terse
 # System booted: 2016-03-25 14:07 CDT 
 # Protocols started: 2016-03-25 14:10 CDT 
 # Last configured: 2016-03-25 14:17 CDT  by joel
@@ -173,7 +169,6 @@
 #vlan up up
 #vlan.999 up down
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show configuration 
-show ospf neighbor
 ## Last commit: 2016-03-25 14:17:43 CDT by joel
 version 12.1X44-D35.5;
 system {
@@ -619,7 +614,6 @@
 # OSPF instance is not running
 # 
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show bfd session 
-quit
 
 0 sessions, 0 clients
 Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
Index: configs/core3.okc-m120.onenet.net
===================================================================
--- configs/core3.okc-m120.onenet.net	(revision 141383)
+++ configs/core3.okc-m120.onenet.net	(working copy)
@@ -427,8 +427,8 @@
 #t1-2/3/0:1:11.0 up up
 #t1-2/3/0:1:12 up up
 #t1-2/3/0:1:12.0 up up
-#t1-2/3/0:1:13 up down
-#t1-2/3/0:1:13.0 up down
+#t1-2/3/0:1:13 up up
+#t1-2/3/0:1:13.0 up up
 #t1-2/3/0:1:14 up up
 #t1-2/3/0:1:14.0 up up
 #t1-2/3/0:1:15 up up
@@ -1354,8 +1354,8 @@
 #t1-3/3/0:10:9 down down
 #t1-3/3/0:10:10 down down
 #t1-3/3/0:10:11 down down
-#t1-3/3/0:10:12 up up
-#t1-3/3/0:10:12.0 up up
+#t1-3/3/0:10:12 up down
+#t1-3/3/0:10:12.0 up down
 #t1-3/3/0:10:13 up up
 #t1-3/3/0:10:13.0 up up
 #t1-3/3/0:10:14 down down
@@ -11607,6 +11607,7 @@
 # 172.23.3.194     lsq-5/1/0.137          Full      10.199.2.22
 # 172.23.3.6       lsq-5/1/0.37           Full      10.199.2.27
 # 172.23.3.102     lsq-5/1/0.97           Full      10.199.2.125
+# 172.23.0.162     t1-2/3/0:1:13.0        Full      10.199.2.59
 # 172.23.2.134     t1-2/3/0:1:16.0        Full      10.199.2.108
 # 172.23.4.150     t1-2/3/0:2:28.0        Full      10.199.2.29
 # 172.23.0.230     t1-2/3/0:2:8.0         Full      10.199.2.111
@@ -11656,13 +11657,12 @@
 # grnoc-mon at OKC-CORE3-M120-RE0> show bfd session 
                                                   Detect   Transmit
 Address                  State     Interface      Time     Interval  Multiplier
-10.119.20.121            Up        t1-3/3/0:10:12.0 6.000   2.000        3   
 10.119.20.125            Up        t1-3/3/0:10:13.0 6.000   2.000        3   
 164.58.15.37             Up        xe-0/0/0.36    1.200     0.400        3   
 164.58.15.53             Up        xe-1/0/0.52    1.200     0.400        3   
 fe80::8618:8800:2428:3801 Down     xe-0/0/0.36    0.000     1.000        3   
 
-5 sessions, 7 clients
-Cumulative transmit rate 7.0 pps, cumulative receive rate 6.0 pps
+4 sessions, 6 clients
+Cumulative transmit rate 6.5 pps, cumulative receive rate 5.5 pps
 
 {master}
Index: configs/swi.cai.sei.onenet.net
===================================================================
--- configs/swi.cai.sei.onenet.net	(revision 141369)
+++ configs/swi.cai.sei.onenet.net	(working copy)
@@ -11,6 +11,7 @@
 # 
 # {master:0}
 # grnoc-mon at SWI-SEI-MUNICIPAL-HOSPITAL-EX-3300> show chassis environment 
+# show chassis firmware
 # Class Item                           Status     Measurement
 # Power FPC 0 Power Supply 0           OK        
 # Temp  FPC 0 CPU                      OK        
Index: configs/rpswi2.rp1f3.onenet.net
===================================================================
--- configs/rpswi2.rp1f3.onenet.net	(revision 141381)
+++ configs/rpswi2.rp1f3.onenet.net	(working copy)
@@ -522,8 +522,8 @@
 #ge-1/0/9.0 up down
 #ge-1/0/10 up up
 #ge-1/0/10.0 up up
-#ge-1/0/11 up down
-#ge-1/0/11.0 up down
+#ge-1/0/11 up up
+#ge-1/0/11.0 up up
 #ge-1/0/12 up down
 #ge-1/0/12.0 up down
 #ge-1/0/13 up down
@@ -552,8 +552,8 @@
 #ge-1/0/24.0 up down
 #ge-1/0/25 up up
 #ge-1/0/25.0 up up
-#ge-1/0/26 up up
-#ge-1/0/26.0 up up
+#ge-1/0/26 up down
+#ge-1/0/26.0 up down
 #ge-1/0/27 up down
 #ge-1/0/27.0 up down
 #ge-1/0/28 up down
Index: configs/stringtown-high-school.client.onenet.net
===================================================================
--- configs/stringtown-high-school.client.onenet.net	(revision 141383)
+++ configs/stringtown-high-school.client.onenet.net	(working copy)
@@ -1,7 +1,6 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at STRINGTOWN-HIGH-SCHOOL-TAG-004909> show system commit 
-# show chassis environment
 #   2016-02-17 16:01:39 CST by sean via cli commit confirmed, rollback in 3mins
 #   2016-01-19 09:16:22 CST by joel via cli
 #   2016-01-11 10:33:48 CST by joel via cli
Index: configs/core5.okc.onenet.net
===================================================================
--- configs/core5.okc.onenet.net	(revision 141368)
+++ configs/core5.okc.onenet.net	(working copy)
@@ -1,12 +1,12 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at OKC-CORE5-MX480-RE0> show system commit 
+#   2016-04-04 10:59:20 CDT by andrew via cli commit confirmed, rollback in 5mins synchronize
 #   2016-03-30 16:10:17 CDT by andrew via cli commit synchronize
 #   2016-03-24 15:43:55 CDT by andrew via cli commit synchronize
 #   2016-03-24 11:27:33 CDT by andrew via cli commit synchronize
 #   2016-03-24 10:34:19 CDT by andrew via cli commit synchronize
 #   2016-03-24 09:16:26 CDT by andrew via cli commit synchronize
-#   2016-03-22 09:17:34 CDT by andrew via cli commit synchronize
 # grnoc-mon at OKC-CORE5-MX480-RE0> show chassis environment 
 # Class Item                           Status     Measurement
 # Temp  PEM 0                          OK        
@@ -477,7 +477,7 @@
 # grnoc-mon at OKC-CORE5-MX480-RE0> show system uptime 
 # System booted: 2014-09-16 23:50 CDT 
 # Protocols started: 2014-09-16 23:51 CDT 
-# Last configured: 2016-03-30 16:10 CDT  by andrew
+# Last configured: 2016-04-04 10:59 CDT  by andrew
 # 
 # {master}
 # grnoc-mon at OKC-CORE5-MX480-RE0> show interface terse 
@@ -606,7 +606,6 @@
 #ge-1/3/3.32767 up up
 #ge-1/3/4 up up
 #ge-1/3/4.756 up up
-#ge-1/3/4.1756 up up
 #ge-1/3/4.3756 up up
 #ge-1/3/4.32767 up up
 #ge-1/3/5 up up
@@ -699,6 +698,8 @@
 #xe-2/1/1.32767 up up
 #ge-2/2/0 up up
 #ge-2/2/0.80 up up
+#ge-2/2/0.201 up up
+#ge-2/2/0.202 up up
 #ge-2/2/0.203 up up
 #ge-2/2/0.204 up up
 #ge-2/2/0.211 up up
@@ -874,7 +875,7 @@
 #pp0 up up
 #tap up up
 # grnoc-mon at OKC-CORE5-MX480-RE0> show configuration 
-## Last commit: 2016-03-30 16:10:17 CDT by andrew
+## Last commit: 2016-04-04 10:59:20 CDT by andrew
 version 12.3R7.7;
 groups {
     re0 {
@@ -1713,10 +1714,6 @@
                 address 164.58.215.149/30;
             }
         }
-        unit 1756 {
-            encapsulation vlan-ccc;
-            vlan-tags outer 756 inner 501;
-        }
         unit 3756 {
             description PIONEER-LIBRARY-SYSTEM-TECUMSEH-NID-MGMT-CIR0005505;
             vlan-tags outer 756 inner 80;
@@ -2601,6 +2598,28 @@
                 address 10.199.208.34/31;
             }
         }
+        unit 201 {
+            description "OETA-BOISE-CITY-TOWER-HQ-50M-CIR0019159 [ORDERED]";
+            encapsulation vlan-ccc;
+            vlan-id 201;
+            family ccc {
+                policer {
+                    input 50M-POL;
+                    output 50M-POL;
+                }
+            }
+        }
+        unit 202 {
+            description "OETA-GUYMON-TOWER-HQ-CIR0019156 [ORDERED]";
+            encapsulation vlan-ccc;
+            vlan-id 202;
+            family ccc {
+                policer {
+                    input 50M-POL;
+                    output 50M-POL;
+                }
+            }
+        }
         unit 203 {
             description "OETA-BEAVER-TOWER-HQ-50M-CIR0019164 [ORDERED]";
             encapsulation vlan-ccc;
@@ -3571,13 +3590,6 @@
                 ignore-mtu-mismatch;
             }
         }
-        inactive: neighbor 164.58.199.194 {
-            interface ge-1/3/4.1756 {
-                virtual-circuit-id 8888;
-                ignore-encapsulation-mismatch;
-                ignore-mtu-mismatch;
-            }
-        }
         neighbor 164.58.199.69 {
             interface xe-2/1/0.3905 {
                 virtual-circuit-id 1313;
@@ -3596,6 +3608,16 @@
                 ignore-encapsulation-mismatch;
                 ignore-mtu-mismatch;
             }
+            interface ge-2/2/0.202 {
+                virtual-circuit-id 2604;
+                ignore-encapsulation-mismatch;
+                ignore-mtu-mismatch;
+            }
+            interface ge-2/2/0.201 {
+                virtual-circuit-id 2601;
+                ignore-encapsulation-mismatch;
+                ignore-mtu-mismatch;
+            }
         }
     }
     lldp {
Index: configs/maysville-hs.client.onenet.net
===================================================================
--- configs/maysville-hs.client.onenet.net	(revision 141383)
+++ configs/maysville-hs.client.onenet.net	(working copy)
@@ -10,6 +10,7 @@
 # rescue  2015-10-26 17:25:18 CDT by root via recovery-mgmt
 # 
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show chassis environment 
+# show chassis firmware
 # Class Item                           Status     Measurement
 # Temp  Routing Engine                 OK        
 #       Routing Engine CPU             OK        
@@ -46,9 +47,9 @@
 #     Serial ID                      ACLC7669
 # 
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show chassis scb 
+# show chassis sfm detail
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show chassis sfm detail
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show chassis ssb 
-# show system boot-messages
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show system boot-messages 
 # kld_map_v: 0x8ff80000, kld_map_p: 0x0
 # Copyright (c) 1996-2014, Juniper Networks, Inc.
@@ -113,11 +114,10 @@
 # WARNING: / was not properly dismounted
 # 
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show version 
-# Hostname: MAYSVILLE-HS-LEASED-ASSET-TAG-004887 # Model: srx240h2 # file list /var/tmp detail # JUNOS Software Release [12.1X44-D35.5] #  # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> file list /var/tmp detail # lrw-r--r--  1 root  wheel         11 May 19  2014 /var/tmp@ -> /cf/var/tmp
+# Hostname: MAYSVILLE-HS-LEASED-ASSET-TAG-004887 # Model: srx240h2 # JUNOS Software Release [12.1X44-D35.5] #  # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> file list /var/tmp detail # lrw-r--r--  1 root  wheel         11 May 19  2014 /var/tmp@ -> /cf/var/tmp
 # total files: 1
 # 
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show system uptime 
-# show interface terse
 # System booted: 2016-01-11 12:47 CST 
 # Protocols started: 2016-01-11 12:50 CST 
 # Last configured: 2016-01-27 15:43 CST  by joel
@@ -173,7 +173,6 @@
 #vlan up up
 #vlan.999 up down
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show configuration 
-show ospf neighbor
 ## Last commit: 2016-01-27 15:43:17 CST by joel
 version 12.1X44-D35.5;
 system {
@@ -601,7 +600,6 @@
 # OSPF instance is not running
 # 
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show bfd session 
-quit
 
 0 sessions, 0 clients
 Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
Index: configs/opt.okc.onenet.net
===================================================================
--- configs/opt.okc.onenet.net	(revision 141302)
+++ configs/opt.okc.onenet.net	(working copy)
@@ -194,7 +194,6 @@
         <interface name="VFAC-2-17-1-1" abbr_name="VFAC-2-17-1-1" admin_state="up" spanning_tree_metric="" description="" type="VFAC" monitoring_state="monitor"></interface>
         <interface name="VFAC-2-17-2-1" abbr_name="VFAC-2-17-2-1" admin_state="up" spanning_tree_metric="" description="Core1 xe-4/3/1" type="VFAC" monitoring_state="monitor"></interface>
         <interface name="VFAC-2-17-3-1" abbr_name="VFAC-2-17-3-1" admin_state="up" spanning_tree_metric="" description="" type="VFAC" monitoring_state="monitor"></interface>
-        <interface name="VFAC-2-17-4-1" abbr_name="VFAC-2-17-4-1" admin_state="up" spanning_tree_metric="" description="" type="VFAC" monitoring_state="monitor"></interface>
       </part>
       <part name="AIP-2" description="AIP" hw_version="B1" part_id="AIP" part_num="73-7665-05" serial_number="SPE1550011D" slot="AIP-2" vendor_id="Cisco"></part>
       <part name="FAN-2-1" description="FTA" hw_version="C0" part_id="FTA" part_num="800-27558-02" serial_number="SMG1604F024" slot="FAN-2-1" vendor_id="Cisco"></part>
Index: configs/rpswi1.okc.onenet.net
===================================================================
--- configs/rpswi1.okc.onenet.net	(revision 141381)
+++ configs/rpswi1.okc.onenet.net	(working copy)
@@ -261,8 +261,8 @@
 #ge-0/0/42.0 up down
 #ge-0/0/43 up down
 #ge-0/0/43.0 up down
-#ge-0/0/44 up up
-#ge-0/0/44.0 up up
+#ge-0/0/44 up down
+#ge-0/0/44.0 up down
 #ge-0/0/45 up down
 #ge-0/0/45.0 up down
 #ge-0/0/46 up down
Index: configs/odmhsas.central-office.okc.client.onenet.net
===================================================================
--- configs/odmhsas.central-office.okc.client.onenet.net	(revision 141364)
+++ configs/odmhsas.central-office.okc.client.onenet.net	(working copy)
@@ -1,12 +1,12 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at ODMHSAS-CENTRAL-OFFICE-OKC-SRX550> show system commit 
-#   2016-01-06 13:13:14 CST by andrew via cli commit confirmed, rollback in 3mins
-#   2016-01-06 08:56:45 CST by andrew via cli commit confirmed, rollback in 3mins
-#   2016-01-05 15:56:07 CST by andrew via cli commit confirmed, rollback in 3mins
-#   2016-01-05 13:20:26 CST by andrew via cli
-#   2016-01-05 13:20:03 CST by root via other
-#   2016-01-05 13:15:55 CST by andrew via cli commit confirmed, rollback in 3mins
+#   2016-04-04 10:58:26 CDT by admin via cli
+#   2016-04-04 10:53:00 CDT by admin via cli
+#   2016-04-04 10:46:03 CDT by admin via cli
+#   2016-04-04 10:22:35 CDT by admin via cli
+#   2016-04-04 10:22:01 CDT by admin via cli
+#   2016-04-04 10:20:14 CDT by admin via cli commit confirmed, rollback in 3mins
 # grnoc-mon at ODMHSAS-CENTRAL-OFFICE-OKC-SRX550> show chassis environment 
 # Class Item                           Status     Measurement
 # Temp  Routing Engine                 OK        
@@ -130,7 +130,7 @@
 # grnoc-mon at ODMHSAS-CENTRAL-OFFICE-OKC-SRX550> show system uptime 
 # System booted: 2015-05-23 14:42 CDT 
 # Protocols started: 2015-05-23 14:43 CDT 
-# Last configured: 2016-01-06 13:13 CST  by andrew
+# Last configured: 2016-04-04 10:58 CDT  by admin
 # 
 # grnoc-mon at ODMHSAS-CENTRAL-OFFICE-OKC-SRX550> show interface terse 
 #Interface Admin Link
@@ -191,6 +191,8 @@
 #st0.25 up up
 #st0.26 up up
 #st0.27 up up
+#st0.28 up up
+#st0.29 up up
 #st0.30 up up
 #st0.31 up up
 #st0.32 up up
@@ -212,7 +214,7 @@
 #vlan.50 up down
 #vlan.90 up up
 # grnoc-mon at ODMHSAS-CENTRAL-OFFICE-OKC-SRX550> show configuration 
-## Last commit: 2016-01-06 13:13:14 CST by andrew
+## Last commit: 2016-04-04 10:58:26 CDT by admin
 version 12.1X46-D20.5;
 system {
     host-name ODMHSAS-CENTRAL-OFFICE-OKC-SRX550;
@@ -508,6 +510,18 @@
                 address 10.119.21.134/31;
             }
         }
+        unit 28 {
+            description "Backup-VPN-to-ODMHSAS-COCMHC-NORMAN [Ack to Ticket 13591:134]";
+            family inet {
+                address 10.119.21.136/31;
+            }
+        }
+        unit 29 {
+            description "Backup-VPN-to-ODMHSAS-GRIFFIN-MEMORIAL-NORMAN [Ack to Ticket 13591:134]";
+            family inet {
+                address 10.119.21.138/31;
+            }
+        }
         unit 30 {
             description "Backup-VPN-to-ODMHSAS-Leland-Wolf-Users [Ack to Ticket 13591:134]";
             family inet {
@@ -775,6 +789,14 @@
                 description "Backup-BGP-to-ODMHSAS-Lawton-Other [Ack to Ticket 13591:134]";
 #                authentication-#key <removed>;
             }
+            neighbor 110.119.21.137 {
+                description "Backup-BGP-to-ODMHSAS-COCMHC-NORMAN [Ack to Ticket 13591:134]";
+#                authentication-#key <removed>;
+            }
+            neighbor 10.119.21.139 {
+                description "Backup-BGP-to-ODMHSAS-GGRIFFIN-MEMORIAL-NORMAN [Ack to Ticket 13591:134]";
+#                authentication-#key <removed>;
+            }
         }
     }
     lldp {
@@ -1052,6 +1074,16 @@
             proposals PRE-G2-AES128-SHA;
 #            pre-shared-#key <removed>;
         }
+        policy IKE-COCMHC-NORMAN {
+            mode main;
+            proposals PRE-G2-AES128-SHA;
+#            pre-shared-#key <removed>;
+        }
+        policy IKE-GRIFFIN-NORMAN {
+            mode main;
+            proposals PRE-G2-AES128-SHA;
+#            pre-shared-#key <removed>;
+        }
         gateway IKE-GATE-ODMHSAS-TEST {
             ike-policy IKE-ODMHSAS-TEST;
             address 166.130.131.48;
@@ -1192,6 +1224,16 @@
             address 166.130.4.159;
             external-interface vlan.3;
         }
+        gateway IKE-GATE-COCMHC-NORMAN {
+            ike-policy IKE-COCMHC-NORMAN;
+            address 166.130.0.93;
+            external-interface vlan.3;
+        }
+        gateway IKE-GATE-GRIFFIN-NORMAN {
+            ike-policy IKE-GRIFFIN-NORMAN;
+            address 166.130.29.134;
+            external-interface vlan.3;
+        }
     }
     ipsec {
         vpn-monitor-options {
@@ -1292,6 +1334,12 @@
         policy VPN-POLICY-LAWTON-OTHER {
             proposals G2-ESP-AES128-SHA;
         }
+        policy VPN-POLICY-COCMHC-NORMAN {
+            proposals G2-ESP-AES128-SHA;
+        }
+        policy VPN-POLICY-GRIFFIN-NORMAN {
+            proposals G2-ESP-AES128-SHA;
+        }
         inactive: vpn IPSEC-VPN-ODMHSAS-TEST {
             bind-interface st0.63;
             vpn-monitor {
@@ -1650,6 +1698,32 @@
             }
             establish-tunnels immediately;
         }
+        vpn IPSEC-VPN-COCMHC-NORMAN {
+            bind-interface st0.28;
+            vpn-monitor {
+                optimized;
+                source-interface st0.28;
+                destination-ip 10.119.21.137;
+            }
+            ike {
+                gateway IKE-GATE-COCMHC-NORMAN;
+                ipsec-policy VPN-POLICY-COCMHC-NORMAN;
+            }
+            establish-tunnels immediately;
+        }
+        vpn IPSEC-VPN-GRIFFIN-NORMAN {
+            bind-interface st0.29;
+            vpn-monitor {
+                optimized;
+                source-interface st0.29;
+                destination-ip 10.119.21.139;
+            }
+            ike {
+                gateway IKE-GATE-GRIFFIN-NORMAN;
+                ipsec-policy VPN-POLICY-GRIFFIN-NORMAN;
+            }
+            establish-tunnels immediately;
+        }
     }
     address-book {
         global {
@@ -1972,6 +2046,8 @@
                 vlan.50;
                 vlan.90;
                 st0.26;
+                st0.28;
+                st0.29;
             }
         }
         security-zone UNTRUST {



More information about the Nocrancid mailing list