[Nocrancid] autopop-onenet.net router config diffs

rancid at rancid.noc.onenet.net rancid at rancid.noc.onenet.net
Fri Apr 15 13:03:21 CDT 2016


Index: configs/vinita-public-library.client.onenet.net
===================================================================
--- configs/vinita-public-library.client.onenet.net	(revision 141707)
+++ configs/vinita-public-library.client.onenet.net	(working copy)
@@ -22,6 +22,7 @@
 # grnoc-mon at VINITA-PUBLIC-LIBRARY-CLIENT-OWNED> show chassis firmware 
 # Part                     Type       Version
 # FPC 0                    O/S        Version 12.1X44-D30 by builder on 2013-12-1
+# show chassis fpc detail
 # FWDD                     O/S        Version 12.1X44-D30 by builder on 2013-12-1
 # 
 # grnoc-mon at VINITA-PUBLIC-LIBRARY-CLIENT-OWNED> show chassis fpc detail 
Index: configs/oja-sw-youth-academy-manitou.client.onenet.net
===================================================================
--- configs/oja-sw-youth-academy-manitou.client.onenet.net	(revision 141719)
+++ configs/oja-sw-youth-academy-manitou.client.onenet.net	(working copy)
@@ -139,7 +139,7 @@
 #ppd0 up up
 #ppe0 up up
 #st0 up up
-#st0.1 up down
+#st0.1 up up
 #tap up up
 #vlan up up
 #vlan.3 up up
Index: configs/tul-adva.p.onenet.net
===================================================================
--- configs/tul-adva.p.onenet.net	(revision 141719)
+++ configs/tul-adva.p.onenet.net	(working copy)
@@ -461,8 +461,8 @@
         <part name="PL-6-11-C1" description="XFP-G" hw_version="" part_id="XFP-G" part_num="" serial_number="FA94154302983" slot="PL-6-11-C1" vendor_id="ADVA"></part>
         <part name="PL-6-11-NE" description="XFPT-D" hw_version="" part_id="XFPT-D" part_num="" serial_number="FA27153832426" slot="PL-6-11-NE" vendor_id="ADVA"></part>
         <part name="PL-6-11-NW" description="XFPT-D" hw_version="" part_id="XFPT-D" part_num="" serial_number="FA86121900167" slot="PL-6-11-NW" vendor_id="ADVA"></part>
-        <interface name="CH-6-11-C1" abbr_name="CH-6-11-C1" admin_state="down" spanning_tree_metric="" description="" type="MUX" monitoring_state="no-monitor"></interface>
-        <interface name="CH-6-11-NE" abbr_name="CH-6-11-NE" admin_state="down" spanning_tree_metric="" description="" type="MUX" monitoring_state="no-monitor"></interface>
+        <interface name="CH-6-11-C1" abbr_name="CH-6-11-C1" admin_state="up" spanning_tree_metric="" description="" type="MUX" monitoring_state="no-monitor"></interface>
+        <interface name="CH-6-11-NE" abbr_name="CH-6-11-NE" admin_state="up" spanning_tree_metric="" description="" type="MUX" monitoring_state="no-monitor"></interface>
         <interface name="CH-6-11-NW" abbr_name="CH-6-11-NW" admin_state="down" spanning_tree_metric="" description="" type="MUX" monitoring_state="no-monitor"></interface>
       </part>
       <part name="MOD-6-19" description="PSU9HU-DC" hw_version="" part_id="PSU9HU-DC" part_num="" serial_number="FA93153901149" slot="MOD-6-19" vendor_id="ADVA"></part>
Index: configs/rpswi2.rp1f3.onenet.net
===================================================================
--- configs/rpswi2.rp1f3.onenet.net	(revision 141719)
+++ configs/rpswi2.rp1f3.onenet.net	(working copy)
@@ -424,8 +424,8 @@
 #ge-0/0/9.0 up down
 #ge-0/0/10 up up
 #ge-0/0/10.0 up up
-#ge-0/0/11 up up
-#ge-0/0/11.0 up up
+#ge-0/0/11 up down
+#ge-0/0/11.0 up down
 #ge-0/0/12 up up
 #ge-0/0/12.0 up up
 #ge-0/0/13 up up
@@ -556,8 +556,8 @@
 #ge-1/0/26.0 up down
 #ge-1/0/27 up down
 #ge-1/0/27.0 up down
-#ge-1/0/28 up down
-#ge-1/0/28.0 up down
+#ge-1/0/28 up up
+#ge-1/0/28.0 up up
 #ge-1/0/29 up up
 #ge-1/0/29.0 up up
 #ge-1/0/30 up up
Index: configs/acx.cai.hart-acx2100.onenet.net
===================================================================
--- configs/acx.cai.hart-acx2100.onenet.net	(revision 141719)
+++ configs/acx.cai.hart-acx2100.onenet.net	(working copy)
@@ -72,7 +72,6 @@
 # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> show chassis sfm detail 
 # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> show chassis ssb 
 # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> show system boot-messages 
-# show version
 # platform_early_bootinit: MX-PPC Series Early Boot Initialization
 # mxppc_set_re_type: hw.board.type is ACX-2100
 # WDOG initialized
Index: configs/core5.okc.onenet.net
===================================================================
--- configs/core5.okc.onenet.net	(revision 141719)
+++ configs/core5.okc.onenet.net	(working copy)
@@ -1,12 +1,12 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at OKC-CORE5-MX480-RE0> show system commit 
+#   2016-04-15 12:56:20 CDT by andrew via cli commit synchronize
 #   2016-04-15 11:53:38 CDT by andrew via cli commit synchronize
 #   2016-04-15 11:50:19 CDT by andrew via cli commit synchronize
 #   2016-04-15 11:48:40 CDT by andrew via cli commit synchronize
 #   2016-04-15 11:31:22 CDT by andrew via cli commit synchronize
 #   2016-04-14 15:43:18 CDT by andrew via cli commit synchronize
-#   2016-04-14 09:58:12 CDT by sean via cli commit synchronize
 # grnoc-mon at OKC-CORE5-MX480-RE0> show chassis environment 
 # Class Item                           Status     Measurement
 # Temp  PEM 0                          OK        
@@ -480,7 +480,7 @@
 # grnoc-mon at OKC-CORE5-MX480-RE0> show system uptime 
 # System booted: 2014-09-16 23:50 CDT 
 # Protocols started: 2014-09-16 23:51 CDT 
-# Last configured: 2016-04-15 11:53 CDT  by andrew
+# Last configured: 2016-04-15 12:56 CDT  by andrew
 # 
 # {master}
 # grnoc-mon at OKC-CORE5-MX480-RE0> show interface terse 
@@ -886,7 +886,7 @@
 #pp0 up up
 #tap up up
 # grnoc-mon at OKC-CORE5-MX480-RE0> show configuration 
-## Last commit: 2016-04-15 11:53:38 CDT by andrew
+## Last commit: 2016-04-15 12:56:20 CDT by andrew
 version 12.3R7.7;
 groups {
     re0 {
@@ -5048,7 +5048,7 @@
             from {
                 route-filter 10.119.0.0/26 orlonger;
             }
-            then reject;
+            then accept;
         }
         term SEND-ONENET-MGMT {
             from {
Index: configs/maysville-hs.client.onenet.net
===================================================================
--- configs/maysville-hs.client.onenet.net	(revision 141719)
+++ configs/maysville-hs.client.onenet.net	(working copy)
@@ -33,7 +33,6 @@
 # 
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show chassis hardware 
 # Hardware inventory:
-# show chassis hardware models
 # Item             Version  Part number  Serial number     Description
 # Chassis                                BU1214AK0530      SRX240H2
 # Routing Engine   REV 10   750-043609   ACLC7669          RE-SRX240H2
@@ -47,7 +46,6 @@
 #     Serial ID                      ACLC7669
 # 
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show chassis scb 
-# show chassis sfm detail
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show chassis sfm detail
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show chassis ssb 
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show system boot-messages 
@@ -118,7 +116,6 @@
 # total files: 1
 # 
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show system uptime 
-# show interface terse
 # System booted: 2016-01-11 12:47 CST 
 # Protocols started: 2016-01-11 12:50 CST 
 # Last configured: 2016-01-27 15:43 CST  by joel
@@ -174,7 +171,6 @@
 #vlan up up
 #vlan.999 up down
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show configuration 
-show ospf neighbor
 ## Last commit: 2016-01-27 15:43:17 CST by joel
 version 12.1X44-D35.5;
 system {
@@ -602,7 +598,6 @@
 # OSPF instance is not running
 # 
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show bfd session 
-quit
 
 0 sessions, 0 clients
 Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
Index: configs/meeker-ps.client.onenet.net
===================================================================
--- configs/meeker-ps.client.onenet.net	(revision 141719)
+++ configs/meeker-ps.client.onenet.net	(working copy)
@@ -1,18 +1,19 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at MEEKER-PS-LEASED-ASSET-TAG-004947> show system commit 
-# show chassis environment
 #   2015-12-14 15:34:07 CST by sean via cli
 #   2015-11-20 10:50:09 CST by joel via cli
 #   2015-11-20 10:48:21 CST by joel via cli
 #   2015-10-28 12:35:21 CDT by root via other
 #   2015-10-28 12:24:40 CDT by joel via cli commit confirmed, rollback in 10mins
 #   2015-10-28 20:20:23 CDT by root via cli commit confirmed, rollback in 5mins
+# show chassis environment
 # grnoc-mon at MEEKER-PS-LEASED-ASSET-TAG-004947> show chassis environment 
 # Class Item                           Status     Measurement
 # Temp  Routing Engine                 OK        
 #       Routing Engine CPU             OK        
 # Fans  SRX240 PowerSupply fan 1       OK
+# show chassis firmware
 #       SRX240 PowerSupply fan 2       OK
 #       SRX240 CPU fan 1               OK
 #       SRX240 CPU fan 2               OK
Index: configs/okc-vpn-cluster.okc.onenet.net
===================================================================
--- configs/okc-vpn-cluster.okc.onenet.net	(revision 141719)
+++ configs/okc-vpn-cluster.okc.onenet.net	(working copy)
@@ -1,12 +1,12 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at OKC-VPN-CLUSTER-NODE0> show system commit 
+#   2016-04-15 12:37:42 CDT by andrew via cli
 #   2016-04-15 11:39:32 CDT by andrew via cli
 #   2016-04-14 10:33:48 CDT by sky via cli
 #   2016-04-14 10:19:08 CDT by sky via cli
 #   2016-04-13 15:14:35 CDT by sky via cli
 #   2016-04-13 14:36:35 CDT by sky via cli
-#   2016-04-13 14:35:25 CDT by sky via cli
 # grnoc-mon at OKC-VPN-CLUSTER-NODE0> show chassis environment 
 # node0:
 # --------------------------------------------------------------------------
@@ -234,12 +234,12 @@
 # --------------------------------------------------------------------------
 # System booted: 2016-03-01 19:49 CST 
 # Protocols started: 2016-03-01 20:04 CST 
-# Last configured: 2016-04-15 11:39 CDT  by andrew
+# Last configured: 2016-04-15 12:37 CDT  by andrew
 # 
 # node1:
 # --------------------------------------------------------------------------
 # System booted: 2016-03-01 19:35 CST 
-# Last configured: 2016-04-15 11:39 CDT  by root
+# Last configured: 2016-04-15 12:37 CDT  by root
 # 
 # {primary:node0}
 # grnoc-mon at OKC-VPN-CLUSTER-NODE0> show interface terse 
@@ -354,12 +354,13 @@
 #st0.14 up down
 #st0.15 up up
 #st0.16 up up
+#st0.17 up up
 #swfab0 up down
 #swfab1 up down
 #tap up up
 #vlan up up
 # grnoc-mon at OKC-VPN-CLUSTER-NODE0> show configuration 
-## Last commit: 2016-04-15 11:39:32 CDT by andrew
+## Last commit: 2016-04-15 12:37:42 CDT by andrew
 version 12.1X46-D40.2;
 groups {
     node0 {
@@ -792,6 +793,13 @@
                 address 10.119.8.14/31;
             }
         }
+        unit 17 {
+            description "TAGNET-TEMP-1 [NO-MONITOR]";
+            family inet {
+                mtu 1440;
+                address 10.119.0.22/31;
+            }
+        }
     }
 }
 snmp {
@@ -958,6 +966,22 @@
             then accept;
         }
     }
+    policy-statement EBGP-TAGNET-REMOTE-EXPORT {
+        term SEND-ROUTES {
+            then accept;
+        }
+    }
+    policy-statement EBGP-TAGNET-REMOTE-IMPORT {
+        term REJECT-DEFAULT {
+            from {
+                route-filter 0.0.0.0/0 exact;
+            }
+            then reject;
+        }
+        term ACCEPT-ROUTES {
+            then accept;
+        }
+    }
 }
 security {
     ike {
@@ -1053,6 +1077,11 @@
             proposals PRE-G2-AES128-SHA;
 #            pre-shared-#key <removed>;
         }
+        policy IKE-TAGNET-TEMP-1 {
+            mode aggressive;
+            proposals PRE-G2-AES128-SHA;
+#            pre-shared-#key <removed>;
+        }
         gateway IKE-GATE-COMANCHE-PS {
             ike-policy IKE-COMANCHE-PS;
             address 166.141.5.145;
@@ -1156,6 +1185,12 @@
             external-interface lo0.0;
             local-address 164.58.0.252;
         }
+        gateway IKE-GATE-TAGNET-TEMP-1 {
+            ike-policy IKE-TAGNET-TEMP-1;
+            dynamic user-at-hostname "tagnet1 at tax.ok.gov";
+            external-interface lo0.0;
+            local-address 164.58.0.252;
+        }
     }
     ipsec {
         proposal ESP-AES128-SHA {
@@ -1215,6 +1250,9 @@
         policy VPN-POLICY-ODOT-MGMT-ALTUS {
             proposals ESP-AES128-SHA;
         }
+        policy VPN-POLICY-TAGNET-TEMP-1 {
+            proposals ESP-AES128-SHA;
+        }
         vpn IPSEC-VPN-COMANCHE-PS {
             bind-interface st0.0;
             ike {
@@ -1376,6 +1414,14 @@
             }
             establish-tunnels immediately;
         }
+        vpn IPSEC-VPN-TAGNET-TEMP-1 {
+            bind-interface st0.17;
+            ike {
+                gateway IKE-GATE-TAGNET-TEMP-1;
+                ipsec-policy VPN-POLICY-TAGNET-TEMP-1;
+            }
+            establish-tunnels immediately;
+        }
     }
     alg {
         msrpc disable;
@@ -1868,6 +1914,17 @@
                         }
                     }
                 }
+                st0.17 {
+                    host-inbound-traffic {
+                        system-services {
+                            ping;
+                            traceroute;
+                        }
+                        protocols {
+                            bgp;
+                        }
+                    }
+                }
             }
         }
     }
@@ -2021,6 +2078,7 @@
     TAGNET {
         instance-type virtual-router;
         interface reth1.606;
+        interface st0.17;
         protocols {
             bgp {
                 group ONENET-CORE {
@@ -2036,6 +2094,19 @@
                         peer-as 5078;
                     }
                 }
+                group TAGNET-REMOTE {
+                    type external;
+                    import EBGP-TAGNET-REMOTE-IMPORT;
+                    family inet {
+                        unicast;
+                    }
+#                    authentication-#key <removed>;
+                    export EBGP-TAGNET-REMOTE-EXPORT;
+                    peer-as 64591;
+                    neighbor 10.119.0.23 {
+                        description "EBGP-TAGNET-TEMP-1 [NO-MONITOR]";
+                    }
+                }
             }
         }
     }



More information about the Nocrancid mailing list