[Nocrancid] autopop-onenet.net router config diffs
rancid at rancid.noc.onenet.net
rancid at rancid.noc.onenet.net
Wed Jul 27 19:03:58 CDT 2016
Index: configs/hub.cla.onenet.net
===================================================================
--- configs/hub.cla.onenet.net (revision 145071)
+++ configs/hub.cla.onenet.net (working copy)
@@ -287,7 +287,7 @@
#t1-2/0/0:6.0 up up
#t1-2/0/0:7 up down
#t1-2/0/0:8 down up
-#t1-2/0/0:9 down up
+#t1-2/0/0:9 down down
#t1-2/0/0:10 down down
#t1-2/0/0:11 down down
#t1-2/0/0:12 down down
Index: configs/doh-shawnee.client.onenet.net
===================================================================
--- configs/doh-shawnee.client.onenet.net (revision 145063)
+++ configs/doh-shawnee.client.onenet.net (working copy)
@@ -0,0 +1,818 @@
+# RANCID-CONTENT-TYPE: juniper
+#
+# grnoc-mon at DOH-SHAWNEE-SRX220> show system commit
+# 2016-07-27 18:14:10 CDT by admin via cli
+# 2016-07-27 18:06:34 CDT by admin via cli commit confirmed, rollback in 5mins
+# 2016-01-26 22:51:25 CST by admin via cli commit confirmed, rollback in 3mins
+# 2016-01-26 22:47:32 CST by root via other
+# 2016-01-26 22:41:38 CST by admin via cli commit confirmed, rollback in 5mins
+# 2016-01-26 22:37:50 CST by root via other
+# grnoc-mon at DOH-SHAWNEE-SRX220> show chassis environment
+# Class Item Status Measurement
+# Temp Routing Engine OK
+# Routing Engine CPU Absent
+# Fans SRX220 Chassis fan 0 OK
+# SRX220 Chassis fan 1 OK
+# Power Power Supply 0 OK
+#
+# grnoc-mon at DOH-SHAWNEE-SRX220> show chassis firmware
+# Part Type Version
+# FPC 0 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FPC 1 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FPC 2 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FWDD O/S Version 12.1X46-D20.5 by builder on 2014-05
+#
+# grnoc-mon at DOH-SHAWNEE-SRX220> show chassis fpc detail
+# Slot 0 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+# Slot 1 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+# Slot 2 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+#
+# grnoc-mon at DOH-SHAWNEE-SRX220> show chassis hardware
+# Hardware inventory:
+# Item Version Part number Serial number Description
+# Chassis AR4012AA0017 SRX220H-POE
+# Routing Engine REV 20 750-031177 AAFB0563 RE-SRX220H-POE
+# FPC 0 FPC
+# PIC 0 8x GE Base PIC
+# FPC 1 REV 07 750-023367 AAEZ1653 FPC
+# PIC 0 1x T1E1 mPIM
+# FPC 2 REV 07 750-023367 AAEY8879 FPC
+# PIC 0 1x T1E1 mPIM
+# Power Supply 0
+#
+# grnoc-mon at DOH-SHAWNEE-SRX220> show chassis hardware models
+# grnoc-mon at DOH-SHAWNEE-SRX220> show chassis routing-engine
+# Routing Engine status:
+# Serial ID AAFB0563
+#
+# grnoc-mon at DOH-SHAWNEE-SRX220> show chassis scb
+# grnoc-mon at DOH-SHAWNEE-SRX220> show chassis sfm detail
+# grnoc-mon at DOH-SHAWNEE-SRX220> show chassis ssb
+# grnoc-mon at DOH-SHAWNEE-SRX220> show system boot-messages
+# kld_map_v: 0x8ff80000, kld_map_p: 0x0
+# Copyright (c) 1996-2014, Juniper Networks, Inc.
+# All rights reserved.
+# Copyright (c) 1992-2006 The FreeBSD Project.
+# Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
+# The Regents of the University of California. All rights reserved.
+# FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
+# Security policy loaded: JUNOS MAC/pcap (mac_pcap)
+# Security policy loaded: JUNOS MAC/runasnonroot (mac_runasnonroot)
+# netisr_init: !debug_mpsafenet, forcing maxthreads from 2 to 1
+# cpu0 on motherboard
+# : CAVIUM's OCTEON 5020 CPU Rev. 0.1 with no FPU implemented
+# L1 Cache: I size 32kb(128 line), D size 8kb(128 line), sixty four way.
+# L2 Cache: Size 128kb, 8 way
+# obio0 on motherboard
+# uart0: <Octeon-16550 channel 0> on obio0
+# uart0: console (9600,n,8,1)
+# twsi0 on obio0
+# dwc0: <Synopsis DWC OTG Controller Driver> on obio0
+# usb0: <USB Bus for DWC OTG Controller> on dwc0
+# usb0: USB revision 2.0
+# uhub0: vendor 0x0000 DWC OTG root hub, class 9/0, rev 2.00/1.00, addr 1
+# uhub0: 1 port with 1 removable, self powered
+# uhub1: vendor 0x0409 product 0x005a, class 9/0, rev 2.00/1.00, addr 2
+# uhub1: single transaction translator
+# uhub1: 3 ports with 2 removable, self powered
+# cpld0 on obio0
+# pcib0: <Cavium on-chip PCI bridge> on obio0
+# Disabling Octeon big bar support
+# PCI Status: PCI 32-bit: 0xc041b
+# pcib0: Initialized controller
+# pci0: <PCI bus> on pcib0
+# pci0: <simple comms> at device 1.0 (no driver attached)
+# atapci0: <SiI 0680 UDMA133 controller> port 0x8-0xb,0x10-0x17,0x18-0x1b,0x20-0x2f mem 0x8020000-0x80200ff irq 0 at device 2.0 on pci0
+# ata2: <ATA channel 0> on atapci0
+# ata3: <ATA channel 1> on atapci0
+# gblmem0 on obio0
+# octpkt0: <Octeon RGMII> on obio0
+# cfi0: <AMD/Fujitsu - 8MB> on obio0
+# Timecounter "mips" frequency 700000000 Hz quality 0
+# ###PCB Group initialized for udppcbgroup
+# ###PCB Group initialized for tcppcbgroup
+# ad0: Device does not support APM
+# ad0: 1006MB <CF 1GB 20080112> at ata2-master WDMA2
+# Trying to mount root from ufs:/dev/ad0s2a
+# WARNING: / was not properly dismounted
+# WARNING: / was not properly dismounted
+#
+# grnoc-mon at DOH-SHAWNEE-SRX220> show version
+# Hostname: DOH-SHAWNEE-SRX220 # Model: srx220h-poe # JUNOS Software Release [12.1X46-D20.5] # # grnoc-mon at DOH-SHAWNEE-SRX220> file list /var/tmp detail # lrw-r--r-- 1 root wheel 11 May 14 2014 /var/tmp@ -> /cf/var/tmp
+# total files: 1
+#
+# grnoc-mon at DOH-SHAWNEE-SRX220> show system uptime
+# System booted: 2016-07-27 18:17 CDT
+# Protocols started: 2016-07-27 18:19 CDT
+# Last configured: 2016-07-27 18:14 CDT by admin
+#
+# grnoc-mon at DOH-SHAWNEE-SRX220> show interface terse
+#Interface Admin Link
+#ge-0/0/0 up up
+#ge-0/0/0.0 up up
+#gr-0/0/0 up up
+#ip-0/0/0 up up
+#lsq-0/0/0 up up
+#lt-0/0/0 up up
+#mt-0/0/0 up up
+#sp-0/0/0 up up
+#sp-0/0/0.0 up up
+#sp-0/0/0.16383 up up
+#lsq-0/0/0:0 up up
+#lsq-0/0/0:0.16 up up
+#lsq-0/0/0:0.17 up up
+#lsq-0/0/0:0.18 up up
+#ge-0/0/1 up up
+#ge-0/0/1.0 up up
+#ge-0/0/2 down down
+#ge-0/0/3 down down
+#ge-0/0/4 down down
+#ge-0/0/5 down down
+#ge-0/0/6 down down
+#ge-0/0/7 down down
+#t1-1/0/0 up up
+#t1-1/0/0.0 up up
+#t1-2/0/0 up up
+#t1-2/0/0.0 up up
+#fxp2 up up
+#fxp2.0 up up
+#gre up up
+#ipip up up
+#irb up up
+#lo0 up up
+#lo0.0 up up
+#lo0.16384 up up
+#lo0.16385 up up
+#lo0.32768 up up
+#lsi up up
+#mtun up up
+#pimd up up
+#pime up up
+#pp0 up up
+#ppd0 up up
+#ppe0 up up
+#st0 up up
+#tap up up
+#vlan up up
+# grnoc-mon at DOH-SHAWNEE-SRX220> show configuration
+## Last commit: 2016-07-27 18:14:10 CDT by admin
+version 12.1X46-D20.5;
+system {
+ host-name DOH-SHAWNEE-SRX220;
+ domain-name onenet.net;
+ time-zone America/Chicago;
+ authentication-order [ password radius ];
+ ports {
+ console log-out-on-disconnect;
+ }
+ root-authentication {
+# encrypted-password <removed>;
+ }
+ name-server {
+ 10.119.255.3;
+ 10.119.255.4;
+ }
+ radius-server {
+ 10.119.255.7 {
+ port 1812;
+ accounting-port 1813;
+# secret "<removed>"; ## SECRET-DATA
+ source-address 10.119.78.35;
+ }
+ }
+ radius-options {
+ attributes {
+ nas-ip-address 10.119.78.35;
+ }
+ }
+ login {
+ message "\n+----------------------------------------------------------------------------+\n| |\n| Managed by Oklahoma State Regents for Higher Education |\n| Oklahoma Network for Education Enrichment (ONENET) |\n| |\n| *** Unauthorized Use or Access Prohibited *** |\n| |\n| For more information, contact: |\n| |\n| Oklahoma State Regents for Higher Education |\n| Educational Telecommunications Network -- ONENET |\n| (888) 566-3638 |\n| !
info at onenet.net |\n| |\n+----------------------------------------------------------------------------+\n";
+ class admin {
+ idle-timeout 30;
+ permissions all;
+ }
+ class lockdown {
+ idle-timeout 2;
+ permissions view;
+ deny-commands .*;
+ deny-configuration .*;
+ }
+ class operator-local {
+ idle-timeout 15;
+ permissions [ access admin configure firewall interface network routing snmp system trace view ];
+ allow-commands "show log messages";
+ }
+ class robot {
+ idle-timeout 10;
+ permissions [ admin configure firewall interface routing secret security snmp system trace view ];
+ }
+ user admin {
+ uid 1000;
+ class super-user;
+ authentication {
+# encrypted-password <removed>;
+ }
+ }
+ user client {
+ uid 2000;
+ class admin;
+ }
+ user eng {
+ uid 2018;
+ class admin;
+ }
+ user rancid {
+ uid 2001;
+ class robot;
+ }
+ user remote {
+ uid 2002;
+ class operator-local;
+ }
+ user upgrades {
+ uid 2003;
+ class operator;
+ authentication {
+# ssh-rsa <removed>;
+ }
+ }
+ }
+ services {
+ ssh {
+ root-login deny;
+ protocol-version v2;
+ }
+ }
+ syslog {
+ archive size 10m files 5;
+ user * {
+ any emergency;
+ }
+ file messages {
+ any critical;
+ authorization info;
+ }
+ file interactive-commands {
+ interactive-commands any;
+ }
+ file PROTECT-RE {
+ firewall any;
+ archive no-world-readable;
+ }
+ file updown {
+ any any;
+ match "SNMP_TRAP_LINK_|(TRAP_LINK)|bgp_rt_maxprefixes_check|RPD_BGP_NEIGHBOR_STATE";
+ }
+ }
+ max-configurations-on-flash 20;
+ max-configuration-rollbacks 20;
+ license {
+ autoupdate {
+ url https://ae1.juniper.net/junos/key_retrieval;
+ }
+ }
+ ntp {
+ server 10.119.255.5 prefer;
+ server 10.119.255.6;
+ }
+}
+chassis {
+ fpc 0 {
+ pic 0 {
+ mlfr-uni-nni-bundles 1;
+ }
+ }
+}
+interfaces {
+ ge-0/0/0 {
+ description DOH-DATA;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 172.23.92.1/25;
+ }
+ }
+ }
+ lsq-0/0/0:0 {
+ description "Link to OneNet";
+ encapsulation multilink-frame-relay-uni-nni;
+ unit 16 {
+ description "DATACOMM-MGMT to OneNet";
+ dlci 16;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.78.35/31;
+ }
+ }
+ unit 17 {
+ description "DOH-DATA to OneNet";
+ dlci 17;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.76.35/31;
+ }
+ }
+ unit 18 {
+ description "DOH-PUBLIC to OneNet";
+ dlci 18;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 172.23.3.194/30;
+ }
+ }
+ }
+ ge-0/0/1 {
+ description DOH-PUBLIC;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 156.110.115.73/29;
+ }
+ }
+ }
+ ge-0/0/2 {
+ disable;
+ }
+ ge-0/0/3 {
+ disable;
+ }
+ ge-0/0/4 {
+ disable;
+ }
+ ge-0/0/5 {
+ disable;
+ }
+ ge-0/0/6 {
+ disable;
+ }
+ ge-0/0/7 {
+ disable;
+ }
+ t1-1/0/0 {
+ clocking external;
+ encapsulation multilink-frame-relay-uni-nni;
+ t1-options {
+ remote-loopback-respond;
+ }
+ unit 0 {
+ family mlfr-uni-nni {
+ bundle lsq-0/0/0:0;
+ }
+ }
+ }
+ t1-2/0/0 {
+ clocking external;
+ encapsulation multilink-frame-relay-uni-nni;
+ t1-options {
+ remote-loopback-respond;
+ }
+ unit 0 {
+ family mlfr-uni-nni {
+ bundle lsq-0/0/0:0;
+ }
+ }
+ }
+ lo0 {
+ unit 0 {
+ family inet {
+ filter {
+ input PROTECT-RE;
+ }
+ }
+ }
+ }
+}
+snmp {
+ client-list snmp-management {
+ 10.119.255.0/24;
+ 204.61.5.128/27;
+ 0.0.0.0/0 {
+ restrict;
+ }
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+}
+routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.78.34;
+ }
+}
+protocols {
+ lldp {
+ interface all;
+ }
+ lldp-med {
+ interface all;
+ }
+}
+policy-options {
+ prefix-list PRE-MGMT-SOURCES {
+ 10.119.255.0/24;
+ 164.58.253.0/24;
+ }
+ prefix-list PRE-LOCALIPv4-SOURCES {
+ apply-path "interfaces <*> unit <*> family inet address <*>";
+ }
+ prefix-list PRE-SNMP-SOURCES {
+ 10.119.255.0/24;
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ 204.61.5.128/27;
+ }
+ prefix-list DOH-TIME-SEN-LOW-BW {
+ 172.23.32.70/32;
+ 172.23.32.72/32;
+ 172.23.32.73/32;
+ 172.23.48.10/32;
+ 172.23.48.49/32;
+ 172.23.48.210/32;
+ 172.23.49.158/32;
+ 172.23.49.160/32;
+ 172.23.49.167/32;
+ 172.23.49.208/32;
+ 204.87.86.20/32;
+ }
+ prefix-list TIME-SEN-TRANS {
+ 172.23.48.13/32;
+ 172.23.48.20/32;
+ 172.23.48.72/32;
+ 172.23.48.105/32;
+ 172.23.48.156/32;
+ 172.23.48.193/32;
+ 172.23.49.4/32;
+ 172.23.49.9/32;
+ 172.23.49.39/32;
+ 172.23.49.70/32;
+ 172.23.49.72/32;
+ }
+}
+class-of-service {
+ classifiers {
+ dscp dscp-default {
+ import default;
+ forwarding-class scavenger-service {
+ loss-priority high code-points ss;
+ }
+ }
+ }
+ code-point-aliases {
+ dscp {
+ ss 001000;
+ }
+ exp {
+ ss 001;
+ }
+ }
+ forwarding-classes {
+ queue 0 best-effort;
+ queue 1 assured-forwarding;
+ queue 2 expedited-forwarding;
+ queue 3 network-control;
+ queue 4 scavenger-service;
+ }
+ interfaces {
+ ge-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ t1-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ }
+ rewrite-rules {
+ exp exp-inet-table {
+ forwarding-class best-effort {
+ loss-priority low code-point 000;
+ loss-priority high code-point 001;
+ }
+ forwarding-class assured-forwarding {
+ loss-priority low code-point 010;
+ loss-priority high code-point 011;
+ }
+ forwarding-class expedited-forwarding {
+ loss-priority low code-point 111;
+ loss-priority high code-point 110;
+ }
+ forwarding-class network-control {
+ loss-priority low code-point 100;
+ loss-priority high code-point 101;
+ }
+ }
+ }
+ scheduler-maps {
+ t1-sch-map {
+ forwarding-class best-effort scheduler best-effort-sch;
+ forwarding-class expedited-forwarding scheduler t1-expedited-forwarding-sch;
+ forwarding-class network-control scheduler network-control-sch;
+ forwarding-class assured-forwarding scheduler t1-assured-forwarding-sch;
+ forwarding-class scavenger-service scheduler scavenger-service-sch;
+ }
+ }
+ schedulers {
+ best-effort-sch {
+ transmit-rate {
+ remainder;
+ }
+ buffer-size {
+ remainder;
+ }
+ priority low;
+ }
+ network-control-sch {
+ transmit-rate percent 5;
+ buffer-size percent 5;
+ priority high;
+ }
+ scavenger-service-sch {
+ transmit-rate percent 0;
+ buffer-size percent 0;
+ priority low;
+ }
+ t1-assured-forwarding-sch {
+ transmit-rate percent 45;
+ buffer-size percent 5;
+ priority high;
+ }
+ t1-expedited-forwarding-sch {
+ transmit-rate percent 35;
+ buffer-size percent 5;
+ priority high;
+ }
+ }
+}
+security {
+ policies {
+ from-zone DOH-DATA to-zone DOH-DATA {
+ policy DOH-DATA {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DOH-PUBLIC to-zone DOH-PUBLIC {
+ policy DOH-PUBLIC {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DATACOMM-MGMT to-zone DATACOMM-MGMT {
+ policy DATACOMM-MGMT {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ }
+ zones {
+ security-zone DOH-DATA {
+ interfaces {
+ lsq-0/0/0:0.17 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/0.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DOH-PUBLIC {
+ interfaces {
+ lsq-0/0/0:0.18 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/1.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DATACOMM-MGMT {
+ interfaces {
+ lsq-0/0/0:0.16 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ }
+}
+firewall {
+ family inet {
+ filter PROTECT-RE {
+ term SSH-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-MGMT-SOURCES;
+ PRE-LOCALIPv4-SOURCES;
+ }
+ protocol tcp;
+ destination-port ssh;
+ }
+ then accept;
+ }
+ term SSH-DENY {
+ from {
+ protocol tcp;
+ destination-port ssh;
+ }
+ then {
+ discard;
+ }
+ }
+ term SNMP-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-SNMP-SOURCES;
+ }
+ protocol udp;
+ destination-port snmp;
+ }
+ then accept;
+ }
+ term SNMP-DENY {
+ from {
+ protocol udp;
+ destination-port snmp;
+ }
+ then {
+ discard;
+ }
+ }
+ term ALL-TRAFFIC {
+ then accept;
+ }
+ }
+ }
+ filter DOH-COS {
+ term expedited-forwarding {
+ from {
+ source-address {
+ 164.58.0.0/16;
+ 156.110.0.0/16;
+ }
+ }
+ then {
+ forwarding-class expedited-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-low {
+ from {
+ prefix-list {
+ DOH-TIME-SEN-LOW-BW;
+ }
+ destination-port [ 1433 80 139 445 9100 443 ];
+ }
+ then {
+ loss-priority low;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-high {
+ from {
+ prefix-list {
+ TIME-SEN-TRANS;
+ }
+ destination-port [ 80 135 139 445 1433 5088 5089 6087 ];
+ }
+ then {
+ loss-priority high;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term accept-all {
+ then {
+ forwarding-class best-effort;
+ accept;
+ }
+ }
+ }
+}
+routing-instances {
+ DOH-DATA {
+ instance-type virtual-router;
+ interface ge-0/0/0.0;
+ interface lsq-0/0/0:0.17;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.76.34;
+ }
+ }
+ }
+ DOH-PUBLIC {
+ instance-type virtual-router;
+ interface lsq-0/0/0:0.18;
+ interface ge-0/0/1.0;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 172.23.3.193;
+ }
+ }
+ }
+}
+# grnoc-mon at DOH-SHAWNEE-SRX220> show ospf neighbor
+# OSPF instance is not running
+#
+# grnoc-mon at DOH-SHAWNEE-SRX220> show bfd session
+
+0 sessions, 0 clients
+Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
+
Index: configs/hub.woo.onenet.net
===================================================================
--- configs/hub.woo.onenet.net (revision 145057)
+++ configs/hub.woo.onenet.net (working copy)
@@ -1,13 +1,13 @@
# RANCID-CONTENT-TYPE: juniper
#
# grnoc-mon at WOODWARD-M120-RE0> show system commit
+# 2016-07-27 18:34:56 CDT by andrew via cli commit synchronize
# 2016-07-27 15:31:50 CDT by sky via cli commit synchronize
# 2016-07-20 18:46:53 CDT by andrew via cli commit synchronize
# 2016-07-20 10:20:04 CDT by andrew via cli commit synchronize
# 2016-03-22 01:07:09 CDT by joel via synchronize
# 2016-03-22 01:04:33 CDT by root via other
# Synchronization with remote Routing Engine
-# 2016-03-22 01:03:45 CDT by root via other
# grnoc-mon at WOODWARD-M120-RE0> show chassis environment
# Class Item Status Measurement
# Temp PEM 0 OK
@@ -264,7 +264,7 @@
# grnoc-mon at WOODWARD-M120-RE0> show system uptime
# System booted: 2016-03-22 01:01 CDT
# Protocols started: 2016-03-22 01:07 CDT
-# Last configured: 2016-07-27 15:31 CDT by sky
+# Last configured: 2016-07-27 18:34 CDT by andrew
#
# {master}
# grnoc-mon at WOODWARD-M120-RE0> show interface terse
@@ -286,7 +286,9 @@
#t1-2/0/2:4 up down
#t1-2/0/2:5 down down
#t1-2/0/2:6 up up
-#t1-2/0/2:6.0 up up
+#t1-2/0/2:6.16 up up
+#t1-2/0/2:6.17 up up
+#t1-2/0/2:6.18 up up
#t1-2/0/2:7 up up
#t1-2/0/2:7.0 up up
#t1-2/0/2:8 down down
@@ -446,7 +448,7 @@
#pp0 up up
#tap up up
# grnoc-mon at WOODWARD-M120-RE0> show configuration
-## Last commit: 2016-07-27 15:31:50 CDT by sky
+## Last commit: 2016-07-27 18:34:56 CDT by andrew
version 13.3R8.7;
groups {
re0 {
@@ -781,23 +783,38 @@
disable;
}
t1-2/0/2:6 {
- description "DOH-WOODWARD-T1-CIR0000709-OCS [DECOM]";
- mtu 1518;
- encapsulation cisco-hdlc;
- unit 0 {
+ description DOH-WOODWARD-T1-CIR0000709-OCS;
+ dce;
+ encapsulation frame-relay;
+ unit 16 {
+ dlci 16;
family inet {
- mtu 1512;
sampling {
input;
+ output;
}
- address 172.23.1.17/30;
+ address 10.119.78.212/31;
}
- family mpls {
- filter {
- input FLOW-MPLS;
+ }
+ unit 17 {
+ dlci 17;
+ family inet {
+ sampling {
+ input;
+ output;
}
+ address 10.119.76.212/31;
}
}
+ unit 18 {
+ dlci 18;
+ family inet {
+ sampling {
+ input;
+ }
+ address 172.23.1.17/30;
+ }
+ }
}
t1-2/0/2:7 {
description OESC-WOODWARD-T1-CIR0000716;
@@ -1521,6 +1538,7 @@
discard;
no-readvertise;
}
+ route 156.110.143.0/29 next-hop 172.23.1.18;
}
router-id 164.58.199.58;
autonomous-system 5078;
@@ -1530,7 +1548,6 @@
icmp-tunneling;
interface lo0.0;
interface ge-3/2/3.0;
- interface t1-2/0/2:6.0;
}
bgp {
group CORE-RR {
@@ -1613,21 +1630,6 @@
}
}
}
- area 0.0.0.3 {
- nssa {
- default-lsa {
- default-metric 10;
- metric-type 1;
- type-7;
- }
- summaries;
- }
- interface t1-2/0/2:6.0 {
- authentication {
- md5 7# key <removed>;
- }
- }
- }
}
ospf3 {
reference-bandwidth 100g;
@@ -1646,7 +1648,6 @@
ldp {
preference 255;
track-igp-metric;
- interface t1-2/0/2:6.0;
interface ge-3/2/3.0;
interface lo0.0;
}
@@ -2271,11 +2272,17 @@
DOH-L3VPN {
description DOH-L3VPN;
instance-type vrf;
+ interface t1-2/0/2:6.17;
route-distinguisher 164.58.199.58:3000;
vrf-import DOH-VRF-IMPORT;
vrf-export DOH-VRF-EXPORT;
vrf-target target:5078:3000;
vrf-table-label;
+ routing-options {
+ static {
+ route 172.23.15.0/26 next-hop 10.119.76.213;
+ }
+ }
}
DPS-L3VPN {
description DPS-L3VPN;
@@ -2296,6 +2303,7 @@
OMES-MGMT-L3VPN {
description OMES-MGMT-L3VPN;
instance-type vrf;
+ interface t1-2/0/2:6.16;
route-distinguisher 164.58.199.58:2550;
vrf-import OMES-MGMT-VRF-IMPORT;
vrf-export OMES-MGMT-VRF-EXPORT;
@@ -2316,7 +2324,6 @@
# grnoc-mon at WOODWARD-M120-RE0> show ospf neighbor
# Address Interface State ID Pri Dead
# 164.58.245.65 ge-3/2/3.0 Full 164.58.199.59
-# 172.23.1.18 t1-2/0/2:6.0 Full 10.199.2.114
#
# {master}
# grnoc-mon at WOODWARD-M120-RE0> show bfd session
Index: configs/doh-weatherford.client.onenet.net
===================================================================
--- configs/doh-weatherford.client.onenet.net (revision 145068)
+++ configs/doh-weatherford.client.onenet.net (working copy)
@@ -0,0 +1,718 @@
+# RANCID-CONTENT-TYPE: juniper
+#
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show system commit
+# 2016-07-27 18:17:14 CDT by andrew via cli commit confirmed, rollback in 5mins
+# 2016-07-27 18:11:50 CDT by andrew via cli
+# 2014-11-07 15:47:03 CST by admin via netconf
+# 2014-09-03 21:27:10 CDT by root via other
+# 2014-09-02 20:51:03 CDT by andrew via cli
+# 2014-09-01 23:30:19 CDT by rnordmark via cli
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show chassis environment
+# Class Item Status Measurement
+# Temp Routing Engine OK
+# Routing Engine CPU Absent
+# Fans SRX220 Chassis fan 0 OK
+# SRX220 Chassis fan 1 OK
+# Power Power Supply 0 OK
+#
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show chassis firmware
+# Part Type Version
+# FPC 0 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FPC 1 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FWDD O/S Version 12.1X46-D20.5 by builder on 2014-05
+#
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show chassis fpc detail
+# Slot 0 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+# Slot 1 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+#
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show chassis hardware
+# Hardware inventory:
+# Item Version Part number Serial number Description
+# Chassis AR4012AA0001 SRX220H-POE
+# Routing Engine REV 20 750-031177 AAFB0525 RE-SRX220H-POE
+# FPC 0 FPC
+# PIC 0 8x GE Base PIC
+# FPC 1 REV 07 750-023367 AAEY8927 FPC
+# PIC 0 1x T1E1 mPIM
+# Power Supply 0
+#
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show chassis hardware models
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show chassis routing-engine
+# Routing Engine status:
+# Serial ID AAFB0525
+#
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show chassis scb
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show chassis sfm detail
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show chassis ssb
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show system boot-messages
+# kld_map_v: 0x8ff80000, kld_map_p: 0x0
+# Copyright (c) 1996-2014, Juniper Networks, Inc.
+# All rights reserved.
+# Copyright (c) 1992-2006 The FreeBSD Project.
+# Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
+# The Regents of the University of California. All rights reserved.
+# FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
+# Security policy loaded: JUNOS MAC/pcap (mac_pcap)
+# Security policy loaded: JUNOS MAC/runasnonroot (mac_runasnonroot)
+# netisr_init: !debug_mpsafenet, forcing maxthreads from 2 to 1
+# cpu0 on motherboard
+# : CAVIUM's OCTEON 5020 CPU Rev. 0.1 with no FPU implemented
+# L1 Cache: I size 32kb(128 line), D size 8kb(128 line), sixty four way.
+# L2 Cache: Size 128kb, 8 way
+# obio0 on motherboard
+# uart0: <Octeon-16550 channel 0> on obio0
+# uart0: console (9600,n,8,1)
+# twsi0 on obio0
+# dwc0: <Synopsis DWC OTG Controller Driver> on obio0
+# usb0: <USB Bus for DWC OTG Controller> on dwc0
+# usb0: USB revision 2.0
+# uhub0: vendor 0x0000 DWC OTG root hub, class 9/0, rev 2.00/1.00, addr 1
+# uhub0: 1 port with 1 removable, self powered
+# uhub1: vendor 0x0409 product 0x005a, class 9/0, rev 2.00/1.00, addr 2
+# uhub1: single transaction translator
+# uhub1: 3 ports with 2 removable, self powered
+# cpld0 on obio0
+# pcib0: <Cavium on-chip PCI bridge> on obio0
+# Disabling Octeon big bar support
+# PCI Status: PCI 32-bit: 0xc041b
+# pcib0: Initialized controller
+# pci0: <PCI bus> on pcib0
+# pci0: <simple comms> at device 1.0 (no driver attached)
+# atapci0: <SiI 0680 UDMA133 controller> port 0x8-0xb,0x10-0x17,0x18-0x1b,0x20-0x2f mem 0x8020000-0x80200ff irq 0 at device 2.0 on pci0
+# ata2: <ATA channel 0> on atapci0
+# ata3: <ATA channel 1> on atapci0
+# gblmem0 on obio0
+# octpkt0: <Octeon RGMII> on obio0
+# cfi0: <AMD/Fujitsu - 8MB> on obio0
+# Timecounter "mips" frequency 700000000 Hz quality 0
+# ###PCB Group initialized for udppcbgroup
+# ###PCB Group initialized for tcppcbgroup
+# ad0: Device does not support APM
+# ad0: 1006MB <CF 1GB 20080112> at ata2-master WDMA2
+# Trying to mount root from ufs:/dev/ad0s1a
+# WARNING: / was not properly dismounted
+# WARNING: / was not properly dismounted
+#
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show version
+# Hostname: DOH-WEATHERFORD-SRX220 # Model: srx220h-poe # JUNOS Software Release [12.1X46-D20.5] # # grnoc-mon at DOH-WEATHERFORD-SRX220> file list /var/tmp detail # lrw-r--r-- 1 root wheel 11 May 14 2014 /var/tmp@ -> /cf/var/tmp
+# total files: 1
+#
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show system uptime
+# System booted: 2016-07-27 18:19 CDT
+# Protocols started: 2016-07-27 18:21 CDT
+# Last configured: 2016-07-27 18:17 CDT by andrew
+#
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show interface terse
+#Interface Admin Link
+#ge-0/0/0 up up
+#ge-0/0/0.0 up up
+#gr-0/0/0 up up
+#ip-0/0/0 up up
+#lsq-0/0/0 up up
+#lt-0/0/0 up up
+#mt-0/0/0 up up
+#sp-0/0/0 up up
+#sp-0/0/0.0 up up
+#sp-0/0/0.16383 up up
+#ge-0/0/1 down down
+#ge-0/0/2 down down
+#ge-0/0/3 down down
+#ge-0/0/4 down down
+#ge-0/0/5 down down
+#ge-0/0/6 down down
+#ge-0/0/7 down down
+#t1-1/0/0 up up
+#t1-1/0/0.16 up up
+#t1-1/0/0.17 up up
+#fxp2 up up
+#fxp2.0 up up
+#gre up up
+#ipip up up
+#irb up up
+#lo0 up up
+#lo0.0 up up
+#lo0.16384 up up
+#lo0.16385 up up
+#lo0.32768 up up
+#lsi up up
+#mtun up up
+#pimd up up
+#pime up up
+#pp0 up up
+#ppd0 up up
+#ppe0 up up
+#st0 up up
+#tap up up
+#vlan up up
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show configuration
+## Last commit: 2016-07-27 18:17:14 CDT by andrew
+version 12.1X46-D20.5;
+system {
+ host-name DOH-WEATHERFORD-SRX220;
+ domain-name onenet.net;
+ time-zone America/Chicago;
+ authentication-order [ password radius ];
+ ports {
+ console log-out-on-disconnect;
+ }
+ root-authentication {
+# encrypted-password <removed>;
+ }
+ name-server {
+ 10.119.255.3;
+ 10.119.255.4;
+ }
+ radius-server {
+ 10.119.255.7 {
+ port 1812;
+ accounting-port 1813;
+# secret "<removed>"; ## SECRET-DATA
+ source-address 10.119.78.135;
+ }
+ }
+ radius-options {
+ attributes {
+ nas-ip-address 10.119.78.135;
+ }
+ }
+ login {
+ message "\n+----------------------------------------------------------------------------+\n| |\n| Managed by Oklahoma State Regents for Higher Education |\n| Oklahoma Network for Education Enrichment (ONENET) |\n| |\n| *** Unauthorized Use or Access Prohibited *** |\n| |\n| For more information, contact: |\n| |\n| Oklahoma State Regents for Higher Education |\n| Educational Telecommunications Network -- ONENET |\n| (888) 566-3638 |\n| !
info at onenet.net |\n| |\n+----------------------------------------------------------------------------+\n";
+ class admin {
+ idle-timeout 30;
+ permissions all;
+ }
+ class lockdown {
+ idle-timeout 2;
+ permissions view;
+ deny-commands .*;
+ deny-configuration .*;
+ }
+ class operator-local {
+ idle-timeout 15;
+ permissions [ access admin configure firewall interface network routing snmp system trace view ];
+ allow-commands "show log messages";
+ }
+ class robot {
+ idle-timeout 10;
+ permissions [ admin configure firewall interface routing secret security snmp system trace view ];
+ }
+ user admin {
+ uid 1000;
+ class super-user;
+ authentication {
+# encrypted-password <removed>;
+ }
+ }
+ user client {
+ uid 2000;
+ class admin;
+ }
+ user eng {
+ uid 2018;
+ class admin;
+ }
+ user rancid {
+ uid 2001;
+ class robot;
+ }
+ user remote {
+ uid 2002;
+ class operator-local;
+ }
+ user upgrades {
+ uid 2003;
+ class operator;
+ authentication {
+# ssh-rsa <removed>;
+ }
+ }
+ }
+ services {
+ ssh {
+ root-login deny;
+ protocol-version v2;
+ }
+ }
+ syslog {
+ archive size 10m files 5;
+ user * {
+ any emergency;
+ }
+ file messages {
+ any critical;
+ authorization info;
+ }
+ file interactive-commands {
+ interactive-commands any;
+ }
+ file PROTECT-RE {
+ firewall any;
+ archive no-world-readable;
+ }
+ file updown {
+ any any;
+ match "SNMP_TRAP_LINK_|(TRAP_LINK)|bgp_rt_maxprefixes_check|RPD_BGP_NEIGHBOR_STATE";
+ }
+ }
+ max-configurations-on-flash 20;
+ max-configuration-rollbacks 20;
+ license {
+ autoupdate {
+ url https://ae1.juniper.net/junos/key_retrieval;
+ }
+ }
+ ntp {
+ server 10.119.255.5 prefer;
+ server 10.119.255.6;
+ }
+}
+interfaces {
+ ge-0/0/0 {
+ description DOH-DATA;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 172.23.18.1/26;
+ }
+ }
+ }
+ ge-0/0/1 {
+ disable;
+ }
+ ge-0/0/2 {
+ disable;
+ }
+ ge-0/0/3 {
+ disable;
+ }
+ ge-0/0/4 {
+ disable;
+ }
+ ge-0/0/5 {
+ disable;
+ }
+ ge-0/0/6 {
+ disable;
+ }
+ ge-0/0/7 {
+ disable;
+ }
+ t1-1/0/0 {
+ description "Link to OneNet";
+ per-unit-scheduler;
+ clocking external;
+ encapsulation frame-relay;
+ t1-options {
+ remote-loopback-respond;
+ }
+ unit 16 {
+ description "DATACOMM-MGMT to OneNet";
+ dlci 16;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.78.135/31;
+ }
+ }
+ unit 17 {
+ description "DOH-DATA to OneNet";
+ dlci 17;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.76.135/31;
+ }
+ }
+ }
+ t1-2/0/0 {
+ disable;
+ }
+ lo0 {
+ unit 0 {
+ family inet {
+ filter {
+ input PROTECT-RE;
+ }
+ }
+ }
+ }
+}
+snmp {
+ client-list snmp-management {
+ 10.119.255.0/24;
+ 204.61.5.128/27;
+ 0.0.0.0/0 {
+ restrict;
+ }
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+}
+routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.78.134;
+ }
+}
+protocols {
+ lldp {
+ interface all;
+ }
+ lldp-med {
+ interface all;
+ }
+}
+policy-options {
+ prefix-list PRE-MGMT-SOURCES {
+ 10.119.255.0/24;
+ 164.58.253.0/24;
+ }
+ prefix-list PRE-LOCALIPv4-SOURCES {
+ apply-path "interfaces <*> unit <*> family inet address <*>";
+ }
+ prefix-list PRE-SNMP-SOURCES {
+ 10.119.255.0/24;
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ 204.61.5.128/27;
+ }
+ prefix-list DOH-TIME-SEN-LOW-BW {
+ 172.23.32.70/32;
+ 172.23.32.72/32;
+ 172.23.32.73/32;
+ 172.23.48.10/32;
+ 172.23.48.49/32;
+ 172.23.48.210/32;
+ 172.23.49.158/32;
+ 172.23.49.160/32;
+ 172.23.49.167/32;
+ 172.23.49.208/32;
+ 204.87.86.20/32;
+ }
+ prefix-list TIME-SEN-TRANS {
+ 172.23.48.13/32;
+ 172.23.48.20/32;
+ 172.23.48.72/32;
+ 172.23.48.105/32;
+ 172.23.48.156/32;
+ 172.23.48.193/32;
+ 172.23.49.4/32;
+ 172.23.49.9/32;
+ 172.23.49.39/32;
+ 172.23.49.70/32;
+ 172.23.49.72/32;
+ }
+}
+class-of-service {
+ classifiers {
+ dscp dscp-default {
+ import default;
+ forwarding-class scavenger-service {
+ loss-priority high code-points ss;
+ }
+ }
+ }
+ code-point-aliases {
+ dscp {
+ ss 001000;
+ }
+ exp {
+ ss 001;
+ }
+ }
+ forwarding-classes {
+ queue 0 best-effort;
+ queue 1 assured-forwarding;
+ queue 2 expedited-forwarding;
+ queue 3 network-control;
+ queue 4 scavenger-service;
+ }
+ interfaces {
+ ge-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ t1-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ }
+ rewrite-rules {
+ exp exp-inet-table {
+ forwarding-class best-effort {
+ loss-priority low code-point 000;
+ loss-priority high code-point 001;
+ }
+ forwarding-class assured-forwarding {
+ loss-priority low code-point 010;
+ loss-priority high code-point 011;
+ }
+ forwarding-class expedited-forwarding {
+ loss-priority low code-point 111;
+ loss-priority high code-point 110;
+ }
+ forwarding-class network-control {
+ loss-priority low code-point 100;
+ loss-priority high code-point 101;
+ }
+ }
+ }
+ scheduler-maps {
+ t1-sch-map {
+ forwarding-class best-effort scheduler best-effort-sch;
+ forwarding-class expedited-forwarding scheduler t1-expedited-forwarding-sch;
+ forwarding-class network-control scheduler network-control-sch;
+ forwarding-class assured-forwarding scheduler t1-assured-forwarding-sch;
+ forwarding-class scavenger-service scheduler scavenger-service-sch;
+ }
+ }
+ schedulers {
+ best-effort-sch {
+ transmit-rate {
+ remainder;
+ }
+ buffer-size {
+ remainder;
+ }
+ priority low;
+ }
+ network-control-sch {
+ transmit-rate percent 5;
+ buffer-size percent 5;
+ priority high;
+ }
+ scavenger-service-sch {
+ transmit-rate percent 0;
+ buffer-size percent 0;
+ priority low;
+ }
+ t1-assured-forwarding-sch {
+ transmit-rate percent 45;
+ buffer-size percent 5;
+ priority high;
+ }
+ t1-expedited-forwarding-sch {
+ transmit-rate percent 35;
+ buffer-size percent 5;
+ priority high;
+ }
+ }
+}
+security {
+ policies {
+ from-zone DOH-DATA to-zone DOH-DATA {
+ policy DOH-DATA {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DATACOMM-MGMT to-zone DATACOMM-MGMT {
+ policy DATACOMM-MGMT {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ }
+ zones {
+ security-zone DOH-DATA {
+ interfaces {
+ t1-1/0/0.17 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/0.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DATACOMM-MGMT {
+ interfaces {
+ t1-1/0/0.16 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ }
+}
+firewall {
+ family inet {
+ filter PROTECT-RE {
+ term SSH-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-MGMT-SOURCES;
+ PRE-LOCALIPv4-SOURCES;
+ }
+ protocol tcp;
+ destination-port ssh;
+ }
+ then accept;
+ }
+ term SSH-DENY {
+ from {
+ protocol tcp;
+ destination-port ssh;
+ }
+ then {
+ discard;
+ }
+ }
+ term SNMP-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-SNMP-SOURCES;
+ }
+ protocol udp;
+ destination-port snmp;
+ }
+ then accept;
+ }
+ term SNMP-DENY {
+ from {
+ protocol udp;
+ destination-port snmp;
+ }
+ then {
+ discard;
+ }
+ }
+ term ALL-TRAFFIC {
+ then accept;
+ }
+ }
+ }
+ filter DOH-COS {
+ term expedited-forwarding {
+ from {
+ source-address {
+ 164.58.0.0/16;
+ 156.110.0.0/16;
+ }
+ }
+ then {
+ forwarding-class expedited-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-low {
+ from {
+ prefix-list {
+ DOH-TIME-SEN-LOW-BW;
+ }
+ destination-port [ 1433 80 139 445 9100 443 ];
+ }
+ then {
+ loss-priority low;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-high {
+ from {
+ prefix-list {
+ TIME-SEN-TRANS;
+ }
+ destination-port [ 80 135 139 445 1433 5088 5089 6087 ];
+ }
+ then {
+ loss-priority high;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term accept-all {
+ then {
+ forwarding-class best-effort;
+ accept;
+ }
+ }
+ }
+}
+routing-instances {
+ DOH-DATA {
+ instance-type virtual-router;
+ interface ge-0/0/0.0;
+ interface t1-1/0/0.17;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.76.134;
+ }
+ }
+ }
+}
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show ospf neighbor
+# OSPF instance is not running
+#
+# grnoc-mon at DOH-WEATHERFORD-SRX220> show bfd session
+
+0 sessions, 0 clients
+Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
+
Index: configs/doh-wilburton.client.onenet.net
===================================================================
--- configs/doh-wilburton.client.onenet.net (revision 145069)
+++ configs/doh-wilburton.client.onenet.net (working copy)
@@ -0,0 +1,785 @@
+# RANCID-CONTENT-TYPE: juniper
+#
+# grnoc-mon at DOH-WILBURTON-SRX220> show system commit
+# 2016-07-27 18:12:53 CDT by admin via cli commit confirmed, rollback in 5mins
+# 2014-11-07 15:47:06 CST by admin via netconf
+# 2014-09-04 22:11:51 CDT by root via other
+# 2014-09-02 21:00:04 CDT by andrew via cli
+# 2014-09-01 23:27:48 CDT by rnordmark via cli
+# 2014-09-01 12:18:36 CDT by rnordmark via cli
+# grnoc-mon at DOH-WILBURTON-SRX220> show chassis environment
+# Class Item Status Measurement
+# Temp Routing Engine OK
+# Routing Engine CPU Absent
+# Fans SRX220 Chassis fan 0 OK
+# SRX220 Chassis fan 1 OK
+# Power Power Supply 0 OK
+#
+# grnoc-mon at DOH-WILBURTON-SRX220> show chassis firmware
+# Part Type Version
+# FPC 0 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FPC 1 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FWDD O/S Version 12.1X46-D20.5 by builder on 2014-05
+#
+# grnoc-mon at DOH-WILBURTON-SRX220> show chassis fpc detail
+# Slot 0 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+# Slot 1 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+#
+# grnoc-mon at DOH-WILBURTON-SRX220> show chassis hardware
+# Hardware inventory:
+# Item Version Part number Serial number Description
+# Chassis AR3612AA0044 SRX220H-POE
+# Routing Engine REV 20 750-031177 AAEY9212 RE-SRX220H-POE
+# FPC 0 FPC
+# PIC 0 8x GE Base PIC
+# FPC 1 REV 07 750-023367 AAEY2979 FPC
+# PIC 0 1x T1E1 mPIM
+# Power Supply 0
+#
+# grnoc-mon at DOH-WILBURTON-SRX220> show chassis hardware models
+# grnoc-mon at DOH-WILBURTON-SRX220> show chassis routing-engine
+# Routing Engine status:
+# Serial ID AAEY9212
+#
+# grnoc-mon at DOH-WILBURTON-SRX220> show chassis scb
+# grnoc-mon at DOH-WILBURTON-SRX220> show chassis sfm detail
+# grnoc-mon at DOH-WILBURTON-SRX220> show chassis ssb
+# grnoc-mon at DOH-WILBURTON-SRX220> show system boot-messages
+# kld_map_v: 0x8ff80000, kld_map_p: 0x0
+# Copyright (c) 1996-2014, Juniper Networks, Inc.
+# All rights reserved.
+# Copyright (c) 1992-2006 The FreeBSD Project.
+# Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
+# The Regents of the University of California. All rights reserved.
+# FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
+# Security policy loaded: JUNOS MAC/pcap (mac_pcap)
+# Security policy loaded: JUNOS MAC/runasnonroot (mac_runasnonroot)
+# netisr_init: !debug_mpsafenet, forcing maxthreads from 2 to 1
+# cpu0 on motherboard
+# : CAVIUM's OCTEON 5020 CPU Rev. 0.1 with no FPU implemented
+# L1 Cache: I size 32kb(128 line), D size 8kb(128 line), sixty four way.
+# L2 Cache: Size 128kb, 8 way
+# obio0 on motherboard
+# uart0: <Octeon-16550 channel 0> on obio0
+# uart0: console (9600,n,8,1)
+# twsi0 on obio0
+# dwc0: <Synopsis DWC OTG Controller Driver> on obio0
+# usb0: <USB Bus for DWC OTG Controller> on dwc0
+# usb0: USB revision 2.0
+# uhub0: vendor 0x0000 DWC OTG root hub, class 9/0, rev 2.00/1.00, addr 1
+# uhub0: 1 port with 1 removable, self powered
+# uhub1: vendor 0x0409 product 0x005a, class 9/0, rev 2.00/1.00, addr 2
+# uhub1: single transaction translator
+# uhub1: 3 ports with 2 removable, self powered
+# cpld0 on obio0
+# pcib0: <Cavium on-chip PCI bridge> on obio0
+# Disabling Octeon big bar support
+# PCI Status: PCI 32-bit: 0xc041b
+# pcib0: Initialized controller
+# pci0: <PCI bus> on pcib0
+# pci0: <simple comms> at device 1.0 (no driver attached)
+# atapci0: <SiI 0680 UDMA133 controller> port 0x8-0xb,0x10-0x17,0x18-0x1b,0x20-0x2f mem 0x8020000-0x80200ff irq 0 at device 2.0 on pci0
+# ata2: <ATA channel 0> on atapci0
+# ata3: <ATA channel 1> on atapci0
+# gblmem0 on obio0
+# octpkt0: <Octeon RGMII> on obio0
+# cfi0: <AMD/Fujitsu - 8MB> on obio0
+# Timecounter "mips" frequency 700000000 Hz quality 0
+# ###PCB Group initialized for udppcbgroup
+# ###PCB Group initialized for tcppcbgroup
+# ad0: Device does not support APM
+# ad0: 1006MB <CF 1GB 20080112> at ata2-master WDMA2
+# Trying to mount root from ufs:/dev/ad0s1a
+# WARNING: / was not properly dismounted
+# WARNING: / was not properly dismounted
+#
+# grnoc-mon at DOH-WILBURTON-SRX220> show version
+# Hostname: DOH-WILBURTON-SRX220 # Model: srx220h-poe # JUNOS Software Release [12.1X46-D20.5] # # grnoc-mon at DOH-WILBURTON-SRX220> file list /var/tmp detail # lrw-r--r-- 1 root wheel 11 May 14 2014 /var/tmp@ -> /cf/var/tmp
+# total files: 1
+#
+# grnoc-mon at DOH-WILBURTON-SRX220> show system uptime
+# System booted: 2016-07-27 18:20 CDT
+# Protocols started: 2016-07-27 18:22 CDT
+# Last configured: 2016-07-27 18:12 CDT by admin
+#
+# grnoc-mon at DOH-WILBURTON-SRX220> show interface terse
+#Interface Admin Link
+#ge-0/0/0 up up
+#ge-0/0/0.0 up up
+#gr-0/0/0 up up
+#ip-0/0/0 up up
+#lsq-0/0/0 up up
+#lt-0/0/0 up up
+#mt-0/0/0 up up
+#sp-0/0/0 up up
+#sp-0/0/0.0 up up
+#sp-0/0/0.16383 up up
+#ge-0/0/1 up up
+#ge-0/0/1.0 up up
+#ge-0/0/2 down down
+#ge-0/0/3 down down
+#ge-0/0/4 down down
+#ge-0/0/5 down down
+#ge-0/0/6 down down
+#ge-0/0/7 down down
+#t1-1/0/0 up up
+#t1-1/0/0.16 up up
+#t1-1/0/0.17 up up
+#t1-1/0/0.18 up up
+#fxp2 up up
+#fxp2.0 up up
+#gre up up
+#ipip up up
+#irb up up
+#lo0 up up
+#lo0.0 up up
+#lo0.16384 up up
+#lo0.16385 up up
+#lo0.32768 up up
+#lsi up up
+#mtun up up
+#pimd up up
+#pime up up
+#pp0 up up
+#ppd0 up up
+#ppe0 up up
+#st0 up up
+#tap up up
+#vlan up up
+# grnoc-mon at DOH-WILBURTON-SRX220> show configuration
+## Last commit: 2016-07-27 18:12:53 CDT by admin
+version 12.1X46-D20.5;
+system {
+ host-name DOH-WILBURTON-SRX220;
+ domain-name onenet.net;
+ time-zone America/Chicago;
+ authentication-order [ password radius ];
+ ports {
+ console log-out-on-disconnect;
+ }
+ root-authentication {
+# encrypted-password <removed>;
+ }
+ name-server {
+ 10.119.255.3;
+ 10.119.255.4;
+ }
+ radius-server {
+ 10.119.255.7 {
+ port 1812;
+ accounting-port 1813;
+# secret "<removed>"; ## SECRET-DATA
+ source-address 10.119.78.99;
+ }
+ }
+ radius-options {
+ attributes {
+ nas-ip-address 10.119.78.99;
+ }
+ }
+ login {
+ message "\n+----------------------------------------------------------------------------+\n| |\n| Managed by Oklahoma State Regents for Higher Education |\n| Oklahoma Network for Education Enrichment (ONENET) |\n| |\n| *** Unauthorized Use or Access Prohibited *** |\n| |\n| For more information, contact: |\n| |\n| Oklahoma State Regents for Higher Education |\n| Educational Telecommunications Network -- ONENET |\n| (888) 566-3638 |\n| !
info at onenet.net |\n| |\n+----------------------------------------------------------------------------+\n";
+ class admin {
+ idle-timeout 30;
+ permissions all;
+ }
+ class lockdown {
+ idle-timeout 2;
+ permissions view;
+ deny-commands .*;
+ deny-configuration .*;
+ }
+ class operator-local {
+ idle-timeout 15;
+ permissions [ access admin configure firewall interface network routing snmp system trace view ];
+ allow-commands "show log messages";
+ }
+ class robot {
+ idle-timeout 10;
+ permissions [ admin configure firewall interface routing secret security snmp system trace view ];
+ }
+ user admin {
+ uid 1000;
+ class super-user;
+ authentication {
+# encrypted-password <removed>;
+ }
+ }
+ user client {
+ uid 2000;
+ class admin;
+ }
+ user eng {
+ uid 2018;
+ class admin;
+ }
+ user rancid {
+ uid 2001;
+ class robot;
+ }
+ user remote {
+ uid 2002;
+ class operator-local;
+ }
+ user upgrades {
+ uid 2003;
+ class operator;
+ authentication {
+# ssh-rsa <removed>;
+ }
+ }
+ }
+ services {
+ ssh {
+ root-login deny;
+ protocol-version v2;
+ }
+ }
+ syslog {
+ archive size 10m files 5;
+ user * {
+ any emergency;
+ }
+ file messages {
+ any critical;
+ authorization info;
+ }
+ file interactive-commands {
+ interactive-commands any;
+ }
+ file PROTECT-RE {
+ firewall any;
+ archive no-world-readable;
+ }
+ file updown {
+ any any;
+ match "SNMP_TRAP_LINK_|(TRAP_LINK)|bgp_rt_maxprefixes_check|RPD_BGP_NEIGHBOR_STATE";
+ }
+ }
+ max-configurations-on-flash 20;
+ max-configuration-rollbacks 20;
+ license {
+ autoupdate {
+ url https://ae1.juniper.net/junos/key_retrieval;
+ }
+ }
+ ntp {
+ server 10.119.255.5 prefer;
+ server 10.119.255.6;
+ }
+}
+interfaces {
+ ge-0/0/0 {
+ description DOH-DATA;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 172.23.28.1/26;
+ }
+ }
+ }
+ ge-0/0/1 {
+ description DOH-PUBLIC;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 156.110.142.109/30;
+ }
+ }
+ }
+ ge-0/0/2 {
+ disable;
+ }
+ ge-0/0/3 {
+ disable;
+ }
+ ge-0/0/4 {
+ disable;
+ }
+ ge-0/0/5 {
+ disable;
+ }
+ ge-0/0/6 {
+ disable;
+ }
+ ge-0/0/7 {
+ disable;
+ }
+ t1-1/0/0 {
+ description "Link to OneNet";
+ per-unit-scheduler;
+ clocking external;
+ encapsulation frame-relay;
+ t1-options {
+ remote-loopback-respond;
+ }
+ unit 16 {
+ description "DATACOMM-MGMT to OneNet";
+ dlci 16;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.78.99/31;
+ }
+ }
+ unit 17 {
+ description "DOH-DATA to OneNet";
+ dlci 17;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.76.99/31;
+ }
+ }
+ unit 18 {
+ description "DOH-PUBLIC to OneNet";
+ dlci 18;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 172.23.0.194/30;
+ }
+ }
+ }
+ t1-2/0/0 {
+ disable;
+ }
+ lo0 {
+ unit 0 {
+ family inet {
+ filter {
+ input PROTECT-RE;
+ }
+ }
+ }
+ }
+}
+snmp {
+ client-list snmp-management {
+ 10.119.255.0/24;
+ 204.61.5.128/27;
+ 0.0.0.0/0 {
+ restrict;
+ }
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+}
+routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.78.98;
+ }
+}
+protocols {
+ lldp {
+ interface all;
+ }
+ lldp-med {
+ interface all;
+ }
+}
+policy-options {
+ prefix-list PRE-MGMT-SOURCES {
+ 10.119.255.0/24;
+ 164.58.253.0/24;
+ }
+ prefix-list PRE-LOCALIPv4-SOURCES {
+ apply-path "interfaces <*> unit <*> family inet address <*>";
+ }
+ prefix-list PRE-SNMP-SOURCES {
+ 10.119.255.0/24;
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ 204.61.5.128/27;
+ }
+ prefix-list DOH-TIME-SEN-LOW-BW {
+ 172.23.32.70/32;
+ 172.23.32.72/32;
+ 172.23.32.73/32;
+ 172.23.48.10/32;
+ 172.23.48.49/32;
+ 172.23.48.210/32;
+ 172.23.49.158/32;
+ 172.23.49.160/32;
+ 172.23.49.167/32;
+ 172.23.49.208/32;
+ 204.87.86.20/32;
+ }
+ prefix-list TIME-SEN-TRANS {
+ 172.23.48.13/32;
+ 172.23.48.20/32;
+ 172.23.48.72/32;
+ 172.23.48.105/32;
+ 172.23.48.156/32;
+ 172.23.48.193/32;
+ 172.23.49.4/32;
+ 172.23.49.9/32;
+ 172.23.49.39/32;
+ 172.23.49.70/32;
+ 172.23.49.72/32;
+ }
+}
+class-of-service {
+ classifiers {
+ dscp dscp-default {
+ import default;
+ forwarding-class scavenger-service {
+ loss-priority high code-points ss;
+ }
+ }
+ }
+ code-point-aliases {
+ dscp {
+ ss 001000;
+ }
+ exp {
+ ss 001;
+ }
+ }
+ forwarding-classes {
+ queue 0 best-effort;
+ queue 1 assured-forwarding;
+ queue 2 expedited-forwarding;
+ queue 3 network-control;
+ queue 4 scavenger-service;
+ }
+ interfaces {
+ ge-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ t1-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ }
+ rewrite-rules {
+ exp exp-inet-table {
+ forwarding-class best-effort {
+ loss-priority low code-point 000;
+ loss-priority high code-point 001;
+ }
+ forwarding-class assured-forwarding {
+ loss-priority low code-point 010;
+ loss-priority high code-point 011;
+ }
+ forwarding-class expedited-forwarding {
+ loss-priority low code-point 111;
+ loss-priority high code-point 110;
+ }
+ forwarding-class network-control {
+ loss-priority low code-point 100;
+ loss-priority high code-point 101;
+ }
+ }
+ }
+ scheduler-maps {
+ t1-sch-map {
+ forwarding-class best-effort scheduler best-effort-sch;
+ forwarding-class expedited-forwarding scheduler t1-expedited-forwarding-sch;
+ forwarding-class network-control scheduler network-control-sch;
+ forwarding-class assured-forwarding scheduler t1-assured-forwarding-sch;
+ forwarding-class scavenger-service scheduler scavenger-service-sch;
+ }
+ }
+ schedulers {
+ best-effort-sch {
+ transmit-rate {
+ remainder;
+ }
+ buffer-size {
+ remainder;
+ }
+ priority low;
+ }
+ network-control-sch {
+ transmit-rate percent 5;
+ buffer-size percent 5;
+ priority high;
+ }
+ scavenger-service-sch {
+ transmit-rate percent 0;
+ buffer-size percent 0;
+ priority low;
+ }
+ t1-assured-forwarding-sch {
+ transmit-rate percent 45;
+ buffer-size percent 5;
+ priority high;
+ }
+ t1-expedited-forwarding-sch {
+ transmit-rate percent 35;
+ buffer-size percent 5;
+ priority high;
+ }
+ }
+}
+security {
+ policies {
+ from-zone DOH-DATA to-zone DOH-DATA {
+ policy DOH-DATA {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DOH-PUBLIC to-zone DOH-PUBLIC {
+ policy DOH-PUBLIC {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DATACOMM-MGMT to-zone DATACOMM-MGMT {
+ policy DATACOMM-MGMT {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ }
+ zones {
+ security-zone DOH-DATA {
+ interfaces {
+ t1-1/0/0.17 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/0.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DOH-PUBLIC {
+ interfaces {
+ t1-1/0/0.18 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/1.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DATACOMM-MGMT {
+ interfaces {
+ t1-1/0/0.16 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ }
+}
+firewall {
+ family inet {
+ filter PROTECT-RE {
+ term SSH-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-MGMT-SOURCES;
+ PRE-LOCALIPv4-SOURCES;
+ }
+ protocol tcp;
+ destination-port ssh;
+ }
+ then accept;
+ }
+ term SSH-DENY {
+ from {
+ protocol tcp;
+ destination-port ssh;
+ }
+ then {
+ discard;
+ }
+ }
+ term SNMP-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-SNMP-SOURCES;
+ }
+ protocol udp;
+ destination-port snmp;
+ }
+ then accept;
+ }
+ term SNMP-DENY {
+ from {
+ protocol udp;
+ destination-port snmp;
+ }
+ then {
+ discard;
+ }
+ }
+ term ALL-TRAFFIC {
+ then accept;
+ }
+ }
+ }
+ filter DOH-COS {
+ term expedited-forwarding {
+ from {
+ source-address {
+ 164.58.0.0/16;
+ 156.110.0.0/16;
+ }
+ }
+ then {
+ forwarding-class expedited-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-low {
+ from {
+ prefix-list {
+ DOH-TIME-SEN-LOW-BW;
+ }
+ destination-port [ 1433 80 139 445 9100 443 ];
+ }
+ then {
+ loss-priority low;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-high {
+ from {
+ prefix-list {
+ TIME-SEN-TRANS;
+ }
+ destination-port [ 80 135 139 445 1433 5088 5089 6087 ];
+ }
+ then {
+ loss-priority high;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term accept-all {
+ then {
+ forwarding-class best-effort;
+ accept;
+ }
+ }
+ }
+}
+routing-instances {
+ DOH-DATA {
+ instance-type virtual-router;
+ interface ge-0/0/0.0;
+ interface t1-1/0/0.17;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.76.98;
+ }
+ }
+ }
+ DOH-PUBLIC {
+ instance-type virtual-router;
+ interface ge-0/0/1.0;
+ interface t1-1/0/0.18;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 172.23.0.193;
+ }
+ }
+ }
+}
+# grnoc-mon at DOH-WILBURTON-SRX220> show ospf neighbor
+# OSPF instance is not running
+#
+# grnoc-mon at DOH-WILBURTON-SRX220> show bfd session
+
+0 sessions, 0 clients
+Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
+
Index: configs/doh-pawnee.client.onenet.net
===================================================================
--- configs/doh-pawnee.client.onenet.net (revision 145062)
+++ configs/doh-pawnee.client.onenet.net (working copy)
@@ -0,0 +1,785 @@
+# RANCID-CONTENT-TYPE: juniper
+#
+# grnoc-mon at DOH-PAWNEE-SRX220> show system commit
+# 2016-07-27 18:39:54 CDT by admin via cli commit confirmed, rollback in 5mins
+# 2014-11-07 15:47:06 CST by admin via netconf
+# 2014-09-03 21:43:31 CDT by root via other
+# 2014-09-02 22:05:11 CDT by andrew via cli
+# 2014-09-02 18:08:00 CDT by rnordmark via cli
+# 2014-09-01 23:37:07 CDT by rnordmark via cli
+# grnoc-mon at DOH-PAWNEE-SRX220> show chassis environment
+# Class Item Status Measurement
+# Temp Routing Engine OK
+# Routing Engine CPU Absent
+# Fans SRX220 Chassis fan 0 OK
+# SRX220 Chassis fan 1 OK
+# Power Power Supply 0 OK
+#
+# grnoc-mon at DOH-PAWNEE-SRX220> show chassis firmware
+# Part Type Version
+# FPC 0 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FPC 1 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FWDD O/S Version 12.1X46-D20.5 by builder on 2014-05
+#
+# grnoc-mon at DOH-PAWNEE-SRX220> show chassis fpc detail
+# Slot 0 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+# Slot 1 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+#
+# grnoc-mon at DOH-PAWNEE-SRX220> show chassis hardware
+# Hardware inventory:
+# Item Version Part number Serial number Description
+# Chassis AR3212AA0017 SRX220H-POE
+# Routing Engine REV 20 750-031177 AAEY4132 RE-SRX220H-POE
+# FPC 0 FPC
+# PIC 0 8x GE Base PIC
+# FPC 1 REV 07 750-023367 AAEW9193 FPC
+# PIC 0 1x T1E1 mPIM
+# Power Supply 0
+#
+# grnoc-mon at DOH-PAWNEE-SRX220> show chassis hardware models
+# grnoc-mon at DOH-PAWNEE-SRX220> show chassis routing-engine
+# Routing Engine status:
+# Serial ID AAEY4132
+#
+# grnoc-mon at DOH-PAWNEE-SRX220> show chassis scb
+# grnoc-mon at DOH-PAWNEE-SRX220> show chassis sfm detail
+# grnoc-mon at DOH-PAWNEE-SRX220> show chassis ssb
+# grnoc-mon at DOH-PAWNEE-SRX220> show system boot-messages
+# kld_map_v: 0x8ff80000, kld_map_p: 0x0
+# Copyright (c) 1996-2014, Juniper Networks, Inc.
+# All rights reserved.
+# Copyright (c) 1992-2006 The FreeBSD Project.
+# Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
+# The Regents of the University of California. All rights reserved.
+# FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
+# Security policy loaded: JUNOS MAC/pcap (mac_pcap)
+# Security policy loaded: JUNOS MAC/runasnonroot (mac_runasnonroot)
+# netisr_init: !debug_mpsafenet, forcing maxthreads from 2 to 1
+# cpu0 on motherboard
+# : CAVIUM's OCTEON 5020 CPU Rev. 0.1 with no FPU implemented
+# L1 Cache: I size 32kb(128 line), D size 8kb(128 line), sixty four way.
+# L2 Cache: Size 128kb, 8 way
+# obio0 on motherboard
+# uart0: <Octeon-16550 channel 0> on obio0
+# uart0: console (9600,n,8,1)
+# twsi0 on obio0
+# dwc0: <Synopsis DWC OTG Controller Driver> on obio0
+# usb0: <USB Bus for DWC OTG Controller> on dwc0
+# usb0: USB revision 2.0
+# uhub0: vendor 0x0000 DWC OTG root hub, class 9/0, rev 2.00/1.00, addr 1
+# uhub0: 1 port with 1 removable, self powered
+# uhub1: vendor 0x0409 product 0x005a, class 9/0, rev 2.00/1.00, addr 2
+# uhub1: single transaction translator
+# uhub1: 3 ports with 2 removable, self powered
+# cpld0 on obio0
+# pcib0: <Cavium on-chip PCI bridge> on obio0
+# Disabling Octeon big bar support
+# PCI Status: PCI 32-bit: 0xc041b
+# pcib0: Initialized controller
+# pci0: <PCI bus> on pcib0
+# pci0: <simple comms> at device 1.0 (no driver attached)
+# atapci0: <SiI 0680 UDMA133 controller> port 0x8-0xb,0x10-0x17,0x18-0x1b,0x20-0x2f mem 0x8020000-0x80200ff irq 0 at device 2.0 on pci0
+# ata2: <ATA channel 0> on atapci0
+# ata3: <ATA channel 1> on atapci0
+# gblmem0 on obio0
+# octpkt0: <Octeon RGMII> on obio0
+# cfi0: <AMD/Fujitsu - 8MB> on obio0
+# Timecounter "mips" frequency 700000000 Hz quality 0
+# ###PCB Group initialized for udppcbgroup
+# ###PCB Group initialized for tcppcbgroup
+# ad0: Device does not support APM
+# ad0: 1006MB <CF 1GB 20080112> at ata2-master WDMA2
+# Trying to mount root from ufs:/dev/ad0s1a
+# WARNING: / was not properly dismounted
+# WARNING: / was not properly dismounted
+#
+# grnoc-mon at DOH-PAWNEE-SRX220> show version
+# Hostname: DOH-PAWNEE-SRX220 # Model: srx220h-poe # JUNOS Software Release [12.1X46-D20.5] # # grnoc-mon at DOH-PAWNEE-SRX220> file list /var/tmp detail # lrw-r--r-- 1 root wheel 11 May 14 2014 /var/tmp@ -> /cf/var/tmp
+# total files: 1
+#
+# grnoc-mon at DOH-PAWNEE-SRX220> show system uptime
+# System booted: 2016-07-27 18:43 CDT
+# Protocols started: 2016-07-27 18:45 CDT
+# Last configured: 2016-07-27 18:39 CDT by admin
+#
+# grnoc-mon at DOH-PAWNEE-SRX220> show interface terse
+#Interface Admin Link
+#ge-0/0/0 up up
+#ge-0/0/0.0 up up
+#gr-0/0/0 up up
+#ip-0/0/0 up up
+#lsq-0/0/0 up up
+#lt-0/0/0 up up
+#mt-0/0/0 up up
+#sp-0/0/0 up up
+#sp-0/0/0.0 up up
+#sp-0/0/0.16383 up up
+#ge-0/0/1 up up
+#ge-0/0/1.0 up up
+#ge-0/0/2 down down
+#ge-0/0/3 down down
+#ge-0/0/4 down down
+#ge-0/0/5 down down
+#ge-0/0/6 down down
+#ge-0/0/7 down down
+#t1-1/0/0 up up
+#t1-1/0/0.16 up up
+#t1-1/0/0.17 up up
+#t1-1/0/0.18 up up
+#fxp2 up up
+#fxp2.0 up up
+#gre up up
+#ipip up up
+#irb up up
+#lo0 up up
+#lo0.0 up up
+#lo0.16384 up up
+#lo0.16385 up up
+#lo0.32768 up up
+#lsi up up
+#mtun up up
+#pimd up up
+#pime up up
+#pp0 up up
+#ppd0 up up
+#ppe0 up up
+#st0 up up
+#tap up up
+#vlan up up
+# grnoc-mon at DOH-PAWNEE-SRX220> show configuration
+## Last commit: 2016-07-27 18:39:54 CDT by admin
+version 12.1X46-D20.5;
+system {
+ host-name DOH-PAWNEE-SRX220;
+ domain-name onenet.net;
+ time-zone America/Chicago;
+ authentication-order [ password radius ];
+ ports {
+ console log-out-on-disconnect;
+ }
+ root-authentication {
+# encrypted-password <removed>;
+ }
+ name-server {
+ 10.119.255.3;
+ 10.119.255.4;
+ }
+ radius-server {
+ 10.119.255.7 {
+ port 1812;
+ accounting-port 1813;
+# secret "<removed>"; ## SECRET-DATA
+ source-address 10.119.78.191;
+ }
+ }
+ radius-options {
+ attributes {
+ nas-ip-address 10.119.78.191;
+ }
+ }
+ login {
+ message "\n+----------------------------------------------------------------------------+\n| |\n| Managed by Oklahoma State Regents for Higher Education |\n| Oklahoma Network for Education Enrichment (ONENET) |\n| |\n| *** Unauthorized Use or Access Prohibited *** |\n| |\n| For more information, contact: |\n| |\n| Oklahoma State Regents for Higher Education |\n| Educational Telecommunications Network -- ONENET |\n| (888) 566-3638 |\n| !
info at onenet.net |\n| |\n+----------------------------------------------------------------------------+\n";
+ class admin {
+ idle-timeout 30;
+ permissions all;
+ }
+ class lockdown {
+ idle-timeout 2;
+ permissions view;
+ deny-commands .*;
+ deny-configuration .*;
+ }
+ class operator-local {
+ idle-timeout 15;
+ permissions [ access admin configure firewall interface network routing snmp system trace view ];
+ allow-commands "show log messages";
+ }
+ class robot {
+ idle-timeout 10;
+ permissions [ admin configure firewall interface routing secret security snmp system trace view ];
+ }
+ user admin {
+ uid 1000;
+ class super-user;
+ authentication {
+# encrypted-password <removed>;
+ }
+ }
+ user client {
+ uid 2000;
+ class admin;
+ }
+ user eng {
+ uid 2018;
+ class admin;
+ }
+ user rancid {
+ uid 2001;
+ class robot;
+ }
+ user remote {
+ uid 2002;
+ class operator-local;
+ }
+ user upgrades {
+ uid 2003;
+ class operator;
+ authentication {
+# ssh-rsa <removed>;
+ }
+ }
+ }
+ services {
+ ssh {
+ root-login deny;
+ protocol-version v2;
+ }
+ }
+ syslog {
+ archive size 10m files 5;
+ user * {
+ any emergency;
+ }
+ file messages {
+ any critical;
+ authorization info;
+ }
+ file interactive-commands {
+ interactive-commands any;
+ }
+ file PROTECT-RE {
+ firewall any;
+ archive no-world-readable;
+ }
+ file updown {
+ any any;
+ match "SNMP_TRAP_LINK_|(TRAP_LINK)|bgp_rt_maxprefixes_check|RPD_BGP_NEIGHBOR_STATE";
+ }
+ }
+ max-configurations-on-flash 20;
+ max-configuration-rollbacks 20;
+ license {
+ autoupdate {
+ url https://ae1.juniper.net/junos/key_retrieval;
+ }
+ }
+ ntp {
+ server 10.119.255.5 prefer;
+ server 10.119.255.6;
+ }
+}
+interfaces {
+ ge-0/0/0 {
+ description DOH-DATA;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 172.23.67.193/26;
+ }
+ }
+ }
+ ge-0/0/1 {
+ description DOH-PUBLIC;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 156.110.202.117/30;
+ }
+ }
+ }
+ ge-0/0/2 {
+ disable;
+ }
+ ge-0/0/3 {
+ disable;
+ }
+ ge-0/0/4 {
+ disable;
+ }
+ ge-0/0/5 {
+ disable;
+ }
+ ge-0/0/6 {
+ disable;
+ }
+ ge-0/0/7 {
+ disable;
+ }
+ t1-1/0/0 {
+ description "Link to OneNet";
+ per-unit-scheduler;
+ clocking external;
+ encapsulation frame-relay;
+ t1-options {
+ remote-loopback-respond;
+ }
+ unit 16 {
+ description "DATACOMM-MGMT to OneNet";
+ dlci 16;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.78.191/31;
+ }
+ }
+ unit 17 {
+ description "DOH-DATA to OneNet";
+ dlci 17;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.76.191/31;
+ }
+ }
+ unit 18 {
+ description "DOH-PUBLIC to OneNet";
+ dlci 18;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 172.23.2.38/30;
+ }
+ }
+ }
+ t1-2/0/0 {
+ disable;
+ }
+ lo0 {
+ unit 0 {
+ family inet {
+ filter {
+ input PROTECT-RE;
+ }
+ }
+ }
+ }
+}
+snmp {
+ client-list snmp-management {
+ 10.119.255.0/24;
+ 204.61.5.128/27;
+ 0.0.0.0/0 {
+ restrict;
+ }
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+}
+routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.78.190;
+ }
+}
+protocols {
+ lldp {
+ interface all;
+ }
+ lldp-med {
+ interface all;
+ }
+}
+policy-options {
+ prefix-list PRE-MGMT-SOURCES {
+ 10.119.255.0/24;
+ 164.58.253.0/24;
+ }
+ prefix-list PRE-LOCALIPv4-SOURCES {
+ apply-path "interfaces <*> unit <*> family inet address <*>";
+ }
+ prefix-list PRE-SNMP-SOURCES {
+ 10.119.255.0/24;
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ 204.61.5.128/27;
+ }
+ prefix-list DOH-TIME-SEN-LOW-BW {
+ 172.23.32.70/32;
+ 172.23.32.72/32;
+ 172.23.32.73/32;
+ 172.23.48.10/32;
+ 172.23.48.49/32;
+ 172.23.48.210/32;
+ 172.23.49.158/32;
+ 172.23.49.160/32;
+ 172.23.49.167/32;
+ 172.23.49.208/32;
+ 204.87.86.20/32;
+ }
+ prefix-list TIME-SEN-TRANS {
+ 172.23.48.13/32;
+ 172.23.48.20/32;
+ 172.23.48.72/32;
+ 172.23.48.105/32;
+ 172.23.48.156/32;
+ 172.23.48.193/32;
+ 172.23.49.4/32;
+ 172.23.49.9/32;
+ 172.23.49.39/32;
+ 172.23.49.70/32;
+ 172.23.49.72/32;
+ }
+}
+class-of-service {
+ classifiers {
+ dscp dscp-default {
+ import default;
+ forwarding-class scavenger-service {
+ loss-priority high code-points ss;
+ }
+ }
+ }
+ code-point-aliases {
+ dscp {
+ ss 001000;
+ }
+ exp {
+ ss 001;
+ }
+ }
+ forwarding-classes {
+ queue 0 best-effort;
+ queue 1 assured-forwarding;
+ queue 2 expedited-forwarding;
+ queue 3 network-control;
+ queue 4 scavenger-service;
+ }
+ interfaces {
+ ge-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ t1-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ }
+ rewrite-rules {
+ exp exp-inet-table {
+ forwarding-class best-effort {
+ loss-priority low code-point 000;
+ loss-priority high code-point 001;
+ }
+ forwarding-class assured-forwarding {
+ loss-priority low code-point 010;
+ loss-priority high code-point 011;
+ }
+ forwarding-class expedited-forwarding {
+ loss-priority low code-point 111;
+ loss-priority high code-point 110;
+ }
+ forwarding-class network-control {
+ loss-priority low code-point 100;
+ loss-priority high code-point 101;
+ }
+ }
+ }
+ scheduler-maps {
+ t1-sch-map {
+ forwarding-class best-effort scheduler best-effort-sch;
+ forwarding-class expedited-forwarding scheduler t1-expedited-forwarding-sch;
+ forwarding-class network-control scheduler network-control-sch;
+ forwarding-class assured-forwarding scheduler t1-assured-forwarding-sch;
+ forwarding-class scavenger-service scheduler scavenger-service-sch;
+ }
+ }
+ schedulers {
+ best-effort-sch {
+ transmit-rate {
+ remainder;
+ }
+ buffer-size {
+ remainder;
+ }
+ priority low;
+ }
+ network-control-sch {
+ transmit-rate percent 5;
+ buffer-size percent 5;
+ priority high;
+ }
+ scavenger-service-sch {
+ transmit-rate percent 0;
+ buffer-size percent 0;
+ priority low;
+ }
+ t1-assured-forwarding-sch {
+ transmit-rate percent 45;
+ buffer-size percent 5;
+ priority high;
+ }
+ t1-expedited-forwarding-sch {
+ transmit-rate percent 35;
+ buffer-size percent 5;
+ priority high;
+ }
+ }
+}
+security {
+ policies {
+ from-zone DOH-DATA to-zone DOH-DATA {
+ policy DOH-DATA {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DOH-PUBLIC to-zone DOH-PUBLIC {
+ policy DOH-PUBLIC {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DATACOMM-MGMT to-zone DATACOMM-MGMT {
+ policy DATACOMM-MGMT {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ }
+ zones {
+ security-zone DOH-DATA {
+ interfaces {
+ t1-1/0/0.17 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/0.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DOH-PUBLIC {
+ interfaces {
+ t1-1/0/0.18 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/1.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DATACOMM-MGMT {
+ interfaces {
+ t1-1/0/0.16 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ }
+}
+firewall {
+ family inet {
+ filter PROTECT-RE {
+ term SSH-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-MGMT-SOURCES;
+ PRE-LOCALIPv4-SOURCES;
+ }
+ protocol tcp;
+ destination-port ssh;
+ }
+ then accept;
+ }
+ term SSH-DENY {
+ from {
+ protocol tcp;
+ destination-port ssh;
+ }
+ then {
+ discard;
+ }
+ }
+ term SNMP-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-SNMP-SOURCES;
+ }
+ protocol udp;
+ destination-port snmp;
+ }
+ then accept;
+ }
+ term SNMP-DENY {
+ from {
+ protocol udp;
+ destination-port snmp;
+ }
+ then {
+ discard;
+ }
+ }
+ term ALL-TRAFFIC {
+ then accept;
+ }
+ }
+ }
+ filter DOH-COS {
+ term expedited-forwarding {
+ from {
+ source-address {
+ 164.58.0.0/16;
+ 156.110.0.0/16;
+ }
+ }
+ then {
+ forwarding-class expedited-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-low {
+ from {
+ prefix-list {
+ DOH-TIME-SEN-LOW-BW;
+ }
+ destination-port [ 1433 80 139 445 9100 443 ];
+ }
+ then {
+ loss-priority low;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-high {
+ from {
+ prefix-list {
+ TIME-SEN-TRANS;
+ }
+ destination-port [ 80 135 139 445 1433 5088 5089 6087 ];
+ }
+ then {
+ loss-priority high;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term accept-all {
+ then {
+ forwarding-class best-effort;
+ accept;
+ }
+ }
+ }
+}
+routing-instances {
+ DOH-DATA {
+ instance-type virtual-router;
+ interface ge-0/0/0.0;
+ interface t1-1/0/0.17;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.76.190;
+ }
+ }
+ }
+ DOH-PUBLIC {
+ instance-type virtual-router;
+ interface ge-0/0/1.0;
+ interface t1-1/0/0.18;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 172.23.2.37;
+ }
+ }
+ }
+}
+# grnoc-mon at DOH-PAWNEE-SRX220> show ospf neighbor
+# OSPF instance is not running
+#
+# grnoc-mon at DOH-PAWNEE-SRX220> show bfd session
+
+0 sessions, 0 clients
+Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
+
Index: configs/core3.okc-m120.onenet.net
===================================================================
--- configs/core3.okc-m120.onenet.net (revision 145071)
+++ configs/core3.okc-m120.onenet.net (working copy)
@@ -1,12 +1,12 @@
# RANCID-CONTENT-TYPE: juniper
#
# grnoc-mon at OKC-CORE3-M120-RE0> show system commit
-# 2016-07-27 16:53:01 CDT by andrew via cli commit synchronize
-# 2016-07-27 15:24:18 CDT by sky via cli commit synchronize
-# 2016-07-26 19:58:29 CDT by sky via cli commit synchronize
-# 2016-07-26 19:33:18 CDT by sky via cli commit synchronize
-# 2016-07-26 19:27:21 CDT by sky via cli commit synchronize
-# 2016-07-26 19:18:31 CDT by sky via cli commit synchronize
+# 2016-07-27 18:55:20 CDT by sky via cli commit synchronize
+# 2016-07-27 18:47:22 CDT by sky via cli commit synchronize
+# 2016-07-27 18:39:46 CDT by sky via cli commit synchronize
+# 2016-07-27 18:33:07 CDT by sky via cli commit synchronize
+# 2016-07-27 18:26:58 CDT by sky via cli commit synchronize
+# 2016-07-27 18:19:50 CDT by sky via cli commit synchronize
# grnoc-mon at OKC-CORE3-M120-RE0> show chassis environment
# Class Item Status Measurement
# Temp PEM 0 OK
@@ -367,7 +367,7 @@
# grnoc-mon at OKC-CORE3-M120-RE0> show system uptime
# System booted: 2015-05-06 01:06 CDT
# Protocols started: 2015-05-06 01:08 CDT
-# Last configured: 2016-07-27 16:53 CDT by andrew
+# Last configured: 2016-07-27 18:55 CDT by sky
#
# {master}
# grnoc-mon at OKC-CORE3-M120-RE0> show interface terse
@@ -703,7 +703,9 @@
#t1-2/3/0:7:1.17 up up
#t1-2/3/0:7:1.18 up up
#t1-2/3/0:7:2 up up
-#t1-2/3/0:7:2.0 up up
+#t1-2/3/0:7:2.16 up up
+#t1-2/3/0:7:2.17 up up
+#t1-2/3/0:7:2.18 up up
#t1-2/3/0:7:3 up up
#t1-2/3/0:7:3.0 up up
#t1-2/3/0:7:4 up up
@@ -713,8 +715,10 @@
#t1-2/3/0:7:7 up up
#t1-2/3/0:7:7.0 up up
#t1-2/3/0:7:8 down down
-#t1-2/3/0:7:9 up up
-#t1-2/3/0:7:9.0 up up
+#t1-2/3/0:7:9 up down
+#t1-2/3/0:7:9.16 up down
+#t1-2/3/0:7:9.17 up down
+#t1-2/3/0:7:9.18 up down
#t1-2/3/0:7:10 up up
#t1-2/3/0:7:10.0 up up
#t1-2/3/0:7:11 down down
@@ -1024,7 +1028,9 @@
#t1-3/3/0:1:9 up up
#t1-3/3/0:1:9.0 up up
#t1-3/3/0:1:10 up up
-#t1-3/3/0:1:10.0 up up
+#t1-3/3/0:1:10.16 up up
+#t1-3/3/0:1:10.17 up up
+#t1-3/3/0:1:10.18 up up
#t1-3/3/0:1:11 down down
#t1-3/3/0:1:12 up up
#t1-3/3/0:1:12.0 up up
@@ -1076,7 +1082,9 @@
#t1-3/3/0:2:10.16 up up
#t1-3/3/0:2:10.17 up up
#t1-3/3/0:2:11 up up
-#t1-3/3/0:2:11.0 up up
+#t1-3/3/0:2:11.16 up up
+#t1-3/3/0:2:11.17 up up
+#t1-3/3/0:2:11.18 up up
#t1-3/3/0:2:12 down down
#t1-3/3/0:2:13 down down
#t1-3/3/0:2:14 down down
@@ -1162,8 +1170,8 @@
#t1-3/3/0:4:6.0 up up
#t1-3/3/0:4:7 down down
#t1-3/3/0:4:8 down down
-#t1-3/3/0:4:9 up down
-#t1-3/3/0:4:9.0 up down
+#t1-3/3/0:4:9 up up
+#t1-3/3/0:4:9.0 up up
#t1-3/3/0:4:10 down down
#t1-3/3/0:4:11 down down
#t1-3/3/0:4:12 down down
@@ -1232,7 +1240,9 @@
#t1-3/3/0:6:1.0 up up
#t1-3/3/0:6:2 down down
#t1-3/3/0:6:3 up up
-#t1-3/3/0:6:3.0 up up
+#t1-3/3/0:6:3.16 up up
+#t1-3/3/0:6:3.17 up up
+#t1-3/3/0:6:3.18 up up
#t1-3/3/0:6:4 down down
#t1-3/3/0:6:5 down down
#t1-3/3/0:6:6 down down
@@ -1589,7 +1599,9 @@
#t1-4/0/2:20 up down
#t1-4/0/2:20.0 up down
#t1-4/0/2:21 up up
-#t1-4/0/2:21.0 up up
+#t1-4/0/2:21.16 up up
+#t1-4/0/2:21.17 up up
+#t1-4/0/2:21.18 up up
#t1-4/0/2:22 down down
#t1-4/0/2:23 up down
#t1-4/0/2:23.0 up down
@@ -1778,10 +1790,9 @@
#lsq-5/1/0.84 up up
#lsq-5/1/0.109 up up
#lsq-5/1/0.116 up up
-#lsq-5/1/0.125 up down
+#lsq-5/1/0.125 up up
#lsq-5/1/0.129 up up
#lsq-5/1/0.131 up up
-#lsq-5/1/0.137 up up
#lsq-5/1/0.148 up up
#lsq-5/1/0.149 up up
#lsq-5/1/0.150 up up
@@ -1818,6 +1829,10 @@
#lsq-5/1/0:6.16 up up
#lsq-5/1/0:6.17 up up
#lsq-5/1/0:6.18 up up
+#lsq-5/1/0:7 up up
+#lsq-5/1/0:7.16 up up
+#lsq-5/1/0:7.17 up up
+#lsq-5/1/0:7.18 up up
#gr-5/3/0 up up
#ip-5/3/0 up up
#mt-5/3/0 up up
@@ -1860,7 +1875,7 @@
#pp0 up up
#tap up up
# grnoc-mon at OKC-CORE3-M120-RE0> show configuration
-## Last commit: 2016-07-27 16:53:01 CDT by andrew
+## Last commit: 2016-07-27 18:55:20 CDT by sky
version 12.3R7.7;
groups {
re0 {
@@ -2065,7 +2080,7 @@
adaptive-services {
service-package layer-2;
}
- mlfr-uni-nni-bundles 7;
+ mlfr-uni-nni-bundles 8;
}
pic 3 {
adaptive-services {
@@ -3697,21 +3712,38 @@
}
}
t1-2/3/0:7:2 {
- description "DOH-Walters-T1-CIR0002619-OCS [DECOM]";
- mtu 1518;
- encapsulation cisco-hdlc;
- unit 0 {
+ description DOH-WALTERS-T1-CIR0002619-OCS;
+ dce;
+ encapsulation frame-relay;
+ unit 16 {
+ dlci 16;
family inet {
- mtu 1512;
- address 172.23.5.197/30;
+ sampling {
+ input;
+ output;
+ }
+ address 10.119.78.120/31;
}
- family mpls {
- filter {
- input FLOW-MPLS;
- output FLOW-MPLS;
+ }
+ unit 17 {
+ dlci 17;
+ family inet {
+ sampling {
+ input;
+ output;
}
+ address 10.119.76.120/31;
}
}
+ unit 18 {
+ dlci 18;
+ family inet {
+ sampling {
+ input;
+ }
+ address 172.23.5.197/30;
+ }
+ }
}
t1-2/3/0:7:3 {
description TAGNET-3423-RINGLING-T1-CIR0006231;
@@ -3750,21 +3782,38 @@
disable;
}
t1-2/3/0:7:9 {
- description "DOH-Kingfisher-T1-CIR0002930-OCS [DECOM]";
- mtu 1518;
- encapsulation cisco-hdlc;
- unit 0 {
+ description DOH-KINGFISHER-T1-CIR0002930-OCS;
+ dce;
+ encapsulation frame-relay;
+ unit 16 {
+ dlci 16;
family inet {
- mtu 1512;
- address 172.23.5.5/30;
+ sampling {
+ input;
+ output;
+ }
+ address 10.119.78.232/31;
}
- family mpls {
- filter {
- input FLOW-MPLS;
- output FLOW-MPLS;
+ }
+ unit 17 {
+ dlci 17;
+ family inet {
+ sampling {
+ input;
+ output;
}
+ address 10.119.76.232/31;
}
}
+ unit 18 {
+ dlci 18;
+ family inet {
+ sampling {
+ input;
+ }
+ address 172.23.5.5/30;
+ }
+ }
}
t1-2/3/0:7:10 {
description TAGNET-7313-BROKENARROW-T1-CIR0005736;
@@ -5187,21 +5236,38 @@
}
}
t1-3/3/0:1:10 {
- description "DOH-Pawnee-T1-CIR0002975-OCS [DECOM]";
- mtu 1518;
- encapsulation cisco-hdlc;
- unit 0 {
+ description DOH-PAWNEE-T1-CIR0002975-OCS;
+ dce;
+ encapsulation frame-relay;
+ unit 16 {
+ dlci 16;
family inet {
- mtu 1512;
- address 172.23.2.37/30;
+ sampling {
+ input;
+ output;
+ }
+ address 10.119.78.190/31;
}
- family mpls {
- filter {
- input FLOW-MPLS;
- output FLOW-MPLS;
+ }
+ unit 17 {
+ dlci 17;
+ family inet {
+ sampling {
+ input;
+ output;
}
+ address 10.119.76.190/31;
}
}
+ unit 18 {
+ dlci 18;
+ family inet {
+ sampling {
+ input;
+ }
+ address 172.23.2.37/30;
+ }
+ }
}
t1-3/3/0:1:11 {
disable;
@@ -5436,21 +5502,38 @@
}
}
t1-3/3/0:2:11 {
- description "DOH-Stilwell-T1-CIR0003035-OCS [DECOM]";
- mtu 1518;
- encapsulation cisco-hdlc;
- unit 0 {
+ description DOH-STILWELL-T1-CIR0003035-OCS;
+ dce;
+ encapsulation frame-relay;
+ unit 16 {
+ dlci 16;
family inet {
- mtu 1512;
- address 172.23.2.181/30;
+ sampling {
+ input;
+ output;
+ }
+ address 10.119.78.154/31;
}
- family mpls {
- filter {
- input FLOW-MPLS;
- output FLOW-MPLS;
+ }
+ unit 17 {
+ dlci 17;
+ family inet {
+ sampling {
+ input;
+ output;
}
+ address 10.119.76.154/31;
}
}
+ unit 18 {
+ dlci 18;
+ family inet {
+ sampling {
+ input;
+ }
+ address 172.23.2.181/30;
+ }
+ }
}
t1-3/3/0:2:12 {
disable;
@@ -6121,21 +6204,38 @@
disable;
}
t1-3/3/0:6:3 {
- description "DOH-Watonga-T1-CIR0003146-OCS [DECOM]";
- mtu 1518;
- encapsulation cisco-hdlc;
- unit 0 {
+ description DOH-WATONGA-T1-CIR0003146-OCS;
+ dce;
+ encapsulation frame-relay;
+ unit 16 {
+ dlci 16;
family inet {
- mtu 1512;
- address 172.23.5.9/30;
+ sampling {
+ input;
+ output;
+ }
+ address 10.119.78.210/31;
}
- family mpls {
- filter {
- input FLOW-MPLS;
- output FLOW-MPLS;
+ }
+ unit 17 {
+ dlci 17;
+ family inet {
+ sampling {
+ input;
+ output;
}
+ address 10.119.76.210/31;
}
}
+ unit 18 {
+ dlci 18;
+ family inet {
+ sampling {
+ input;
+ }
+ address 172.23.5.9/30;
+ }
+ }
}
t1-3/3/0:6:4 {
disable;
@@ -6608,20 +6708,20 @@
disable;
}
t1-3/3/0:8:22 {
- description "DOH-Shawnee-T1-CIR0003350-lsq-5/1/0.137 [DECOM]";
- mtu 2000;
+ description DOH-SHAWNEE-T1-CIR0003350-LSQ-5/1/0:7;
+ encapsulation multilink-frame-relay-uni-nni;
unit 0 {
- family mlppp {
- bundle lsq-5/1/0.137;
+ family mlfr-uni-nni {
+ bundle lsq-5/1/0:7;
}
}
}
t1-3/3/0:8:23 {
- description "DOH-Shawnee-T1-CIR0004959-lsq-5/1/0.137 [DECOM]";
- mtu 2000;
+ description DOH-SHAWNEE-T1-CIR0004959-LSQ-5/1/0:7;
+ encapsulation multilink-frame-relay-uni-nni;
unit 0 {
- family mlppp {
- bundle lsq-5/1/0.137;
+ family mlfr-uni-nni {
+ bundle lsq-5/1/0:7;
}
}
}
@@ -7663,22 +7763,38 @@
}
}
t1-4/0/2:21 {
- description "DOH-STIGLER-T1-CIR0002806-OCS [DECOM]";
- mtu 1518;
- clocking internal;
- encapsulation cisco-hdlc;
- unit 0 {
+ description DOH-STIGLER-T1-CIR0002806-OCS;
+ dce;
+ encapsulation frame-relay;
+ unit 16 {
+ dlci 16;
family inet {
- mtu 1512;
- address 172.23.0.165/30;
+ sampling {
+ input;
+ output;
+ }
+ address 10.119.78.158/31;
}
- family mpls {
- filter {
- input FLOW-MPLS;
- output FLOW-MPLS;
+ }
+ unit 17 {
+ dlci 17;
+ family inet {
+ sampling {
+ input;
+ output;
}
+ address 10.119.76.158/31;
}
}
+ unit 18 {
+ dlci 18;
+ family inet {
+ sampling {
+ input;
+ }
+ address 172.23.0.165/30;
+ }
+ }
}
t1-4/0/2:22 {
disable;
@@ -8533,25 +8649,6 @@
address 156.110.26.165/30;
}
}
- unit 137 {
- description "DOH-Shawnee-OCS [DECOM]";
- encapsulation multilink-ppp;
- mrru 2000;
- family inet {
- mtu 2000;
- filter {
- output DOH-COS;
- }
- address 172.23.3.193/30;
- }
- family mpls {
- mtu 1984;
- filter {
- input FLOW-MPLS;
- output FLOW-MPLS;
- }
- }
- }
unit 148 {
description TAGNET-6323-EARLSBORO;
encapsulation multilink-ppp;
@@ -8754,6 +8851,41 @@
}
}
}
+ lsq-5/1/0:7 {
+ description DOH-SHAWNEE-OCS;
+ per-unit-scheduler;
+ dce;
+ encapsulation multilink-frame-relay-uni-nni;
+ unit 16 {
+ dlci 16;
+ family inet {
+ sampling {
+ input;
+ output;
+ }
+ address 10.119.78.34/31;
+ }
+ }
+ unit 17 {
+ dlci 17;
+ family inet {
+ sampling {
+ input;
+ output;
+ }
+ address 10.119.76.34/31;
+ }
+ }
+ unit 18 {
+ dlci 18;
+ family inet {
+ sampling {
+ input;
+ }
+ address 172.23.3.193/30;
+ }
+ }
+ }
sp-5/3/0 {
unit 0 {
family inet;
@@ -8970,6 +9102,13 @@
route 156.110.72.16/30 next-hop 172.23.0.230;
route 156.110.218.112/30 next-hop 172.23.2.134;
route 156.110.222.104/30 next-hop 172.23.0.230;
+ route 156.110.115.72/29 next-hop 172.23.3.194;
+ route 164.58.22.136/30 next-hop 172.23.5.198;
+ route 156.110.235.104/30 next-hop 172.23.2.182;
+ route 156.110.134.100/30 next-hop 172.23.0.166;
+ route 156.110.202.116/30 next-hop 172.23.2.38;
+ route 156.110.66.108/30 next-hop 172.23.5.10;
+ route 156.110.66.112/30 next-hop 172.23.5.6;
}
router-id 164.58.199.213;
autonomous-system 5078;
@@ -8984,15 +9123,8 @@
interface xe-1/0/0.52;
interface lo0.0;
interface lsq-5/1/0.37;
- interface lsq-5/1/0.137;
interface t1-4/1/3:6.0;
interface t1-3/3/0:7:19.0;
- interface t1-3/3/0:2:11.0;
- interface t1-2/3/0:7:2.0;
- interface t1-3/3/0:1:10.0;
- interface t1-3/3/0:6:3.0;
- interface t1-2/3/0:7:9.0;
- interface t1-4/0/2:21.0;
}
bgp {
family inet {
@@ -9124,11 +9256,6 @@
}
summaries;
}
- interface lsq-5/1/0.137 {
- authentication {
- md5 7# key <removed>;
- }
- }
interface lsq-5/1/0.37 {
authentication {
md5 7# key <removed>;
@@ -9145,36 +9272,6 @@
md5 7# key <removed>;
}
}
- interface t1-3/3/0:2:11.0 {
- authentication {
- md5 7# key <removed>;
- }
- }
- interface t1-2/3/0:7:2.0 {
- authentication {
- md5 7# key <removed>;
- }
- }
- interface t1-3/3/0:1:10.0 {
- authentication {
- md5 7# key <removed>;
- }
- }
- interface t1-3/3/0:6:3.0 {
- authentication {
- md5 7# key <removed>;
- }
- }
- interface t1-2/3/0:7:9.0 {
- authentication {
- md5 7# key <removed>;
- }
- }
- interface t1-4/0/2:21.0 {
- authentication {
- md5 7# key <removed>;
- }
- }
}
}
ospf3 {
@@ -9205,16 +9302,9 @@
track-igp-metric;
interface xe-0/0/0.36;
interface xe-1/0/0.52;
- interface t1-2/3/0:7:2.0;
- interface t1-2/3/0:7:9.0;
- interface t1-3/3/0:1:10.0;
- interface t1-3/3/0:2:11.0;
- interface t1-3/3/0:6:3.0;
interface t1-3/3/0:7:19.0;
- interface t1-4/0/2:21.0;
interface t1-4/1/3:6.0;
interface lsq-5/1/0.37;
- interface lsq-5/1/0.137;
interface lo0.0;
}
l2circuit {
@@ -10779,14 +10869,19 @@
interface t1-2/3/0:2:28.17;
interface t1-2/3/0:6:20.17;
interface t1-2/3/0:7:1.17;
+ interface t1-2/3/0:7:2.17;
+ interface t1-2/3/0:7:9.17;
interface t1-2/3/0:8:14.17;
interface t1-2/3/0:8:16.17;
interface t1-2/3/0:8:17.17;
+ interface t1-3/3/0:1:10.17;
interface t1-3/3/0:1:26.17;
+ interface t1-3/3/0:2:11.17;
interface t1-3/3/0:3:11.17;
interface t1-3/3/0:3:17.17;
interface t1-3/3/0:4:1.17;
interface t1-3/3/0:5:20.17;
+ interface t1-3/3/0:6:3.17;
interface t1-3/3/0:6:17.17;
interface t1-3/3/0:6:20.17;
interface t1-3/3/0:7:14.17;
@@ -10799,7 +10894,9 @@
interface t1-3/3/0:12:2.17;
interface t1-3/3/0:12:6.17;
interface t1-3/3/0:12:26.17;
+ interface t1-4/0/2:21.17;
interface lsq-5/1/0:6.17;
+ interface lsq-5/1/0:7.17;
route-distinguisher 164.58.199.213:3000;
vrf-import DOH-VRF-IMPORT;
vrf-export DOH-VRF-EXPORT;
@@ -10834,6 +10931,13 @@
route 172.23.100.64/26 next-hop 10.119.76.215;
route 172.23.30.64/26 next-hop 10.119.76.207;
route 172.23.72.64/26 next-hop 10.119.76.201;
+ route 172.23.92.0/25 next-hop 10.119.76.35;
+ route 172.23.124.64/26 next-hop 10.119.76.121;
+ route 172.23.75.64/26 next-hop 10.119.76.155;
+ route 172.23.26.64/26 next-hop 10.119.76.159;
+ route 172.23.67.192/26 next-hop 10.119.76.191;
+ route 172.23.112.128/26 next-hop 10.119.76.211;
+ route 172.23.112.64/26 next-hop 10.119.76.233;
}
}
}
@@ -11239,6 +11343,8 @@
interface t1-2/3/0:6:3.16;
interface t1-2/3/0:6:20.16;
interface t1-2/3/0:7:1.16;
+ interface t1-2/3/0:7:2.16;
+ interface t1-2/3/0:7:9.16;
interface t1-2/3/0:8:8.16;
interface t1-2/3/0:8:14.16;
interface t1-2/3/0:8:16.16;
@@ -11248,17 +11354,20 @@
interface t1-2/3/0:9:3.16;
interface t1-2/3/0:10:7.16;
interface t1-2/3/0:12:24.16;
+ interface t1-3/3/0:1:10.16;
interface t1-3/3/0:1:26.16;
interface t1-3/3/0:2:1.16;
interface t1-3/3/0:2:4.16;
interface t1-3/3/0:2:8.16;
interface t1-3/3/0:2:10.16;
+ interface t1-3/3/0:2:11.16;
interface t1-3/3/0:2:22.16;
interface t1-3/3/0:3:11.16;
interface t1-3/3/0:3:17.16;
interface t1-3/3/0:4:1.16;
interface t1-3/3/0:5:15.16;
interface t1-3/3/0:5:20.16;
+ interface t1-3/3/0:6:3.16;
interface t1-3/3/0:6:17.16;
interface t1-3/3/0:6:20.16;
interface t1-3/3/0:7:14.16;
@@ -11271,12 +11380,14 @@
interface t1-3/3/0:12:2.16;
interface t1-3/3/0:12:6.16;
interface t1-3/3/0:12:26.16;
+ interface t1-4/0/2:21.16;
interface lsq-5/1/0:1.16;
interface lsq-5/1/0:2.16;
interface lsq-5/1/0:3.16;
interface lsq-5/1/0:4.16; ## 'lsq-5/1/0:4.16' is not defined
interface lsq-5/1/0:5.16;
interface lsq-5/1/0:6.16;
+ interface lsq-5/1/0:7.16;
route-distinguisher 164.58.199.213:2550;
vrf-import OMES-MGMT-VRF-IMPORT;
vrf-export OMES-MGMT-VRF-EXPORT;
@@ -11738,14 +11849,7 @@
# Address Interface State ID Pri Dead
# 164.58.15.37 xe-0/0/0.36 Full 164.58.199.211
# 164.58.15.53 xe-1/0/0.52 Full 164.58.199.212
-# 172.23.3.194 lsq-5/1/0.137 Full 10.199.2.22
# 172.23.3.6 lsq-5/1/0.37 Full 10.199.2.27
-# 172.23.5.198 t1-2/3/0:7:2.0 Full 10.199.2.68
-# 172.23.5.6 t1-2/3/0:7:9.0 Full 10.199.2.124
-# 172.23.2.38 t1-3/3/0:1:10.0 Full 10.199.2.103
-# 172.23.2.182 t1-3/3/0:2:11.0 Full 10.199.2.85
-# 172.23.5.10 t1-3/3/0:6:3.0 Full 10.199.2.113
-# 172.23.0.166 t1-4/0/2:21.0 Full 10.199.2.87
# 172.23.3.66 t1-4/1/3:6.0 Full 10.199.2.30
#
# {master}
Index: configs/odot-sand-springs-residence.client.onenet.net
===================================================================
--- configs/odot-sand-springs-residence.client.onenet.net (revision 144899)
+++ configs/odot-sand-springs-residence.client.onenet.net (working copy)
@@ -1,12 +1,12 @@
# RANCID-CONTENT-TYPE: juniper
#
# grnoc-mon at ODOT-SAND-SPRINGS-RESIDENCY-SRX220> show system commit
+# 2016-07-27 18:48:48 CDT by andrew via cli
# 2016-04-27 12:02:23 CDT by andrew via cli
# 2016-04-27 10:36:59 CDT by admin via cli
# 2016-04-25 08:16:26 CDT by admin via cli
# 2016-04-24 18:17:46 CDT by admin via cli commit confirmed, rollback in 10mins
# 2014-10-30 14:56:09 CDT by onenet via cli
-# 2014-10-28 15:15:29 CDT by onenet via cli
# grnoc-mon at ODOT-SAND-SPRINGS-RESIDENCY-SRX220> show chassis environment
# Class Item Status Measurement
# Temp Routing Engine OK
@@ -99,18 +99,16 @@
# ###PCB Group initialized for tcppcbgroup
# ad0: Device does not support APM
# ad0: 1006MB <CF 1GB 20080112> at ata2-master WDMA2
-# Trying to mount root from ufs:/dev/ad0s2a
-# WARNING: / was not properly dismounted
-# WARNING: / was not properly dismounted
+# Trying to mount root from ufs:/dev/ad0s1a
#
# grnoc-mon at ODOT-SAND-SPRINGS-RESIDENCY-SRX220> show version
# Hostname: ODOT-SAND-SPRINGS-RESIDENCY-SRX220 # Model: srx220h-poe # JUNOS Software Release [12.1X46-D20.5] # # grnoc-mon at ODOT-SAND-SPRINGS-RESIDENCY-SRX220> file list /var/tmp detail # lrw-r--r-- 1 root wheel 11 May 14 2014 /var/tmp@ -> /cf/var/tmp
# total files: 1
#
# grnoc-mon at ODOT-SAND-SPRINGS-RESIDENCY-SRX220> show system uptime
-# System booted: 2016-07-23 08:17 CDT
-# Protocols started: 2016-07-23 08:20 CDT
-# Last configured: 2016-04-27 12:02 CDT by andrew
+# System booted: 2016-07-27 17:58 CDT
+# Protocols started: 2016-07-27 18:01 CDT
+# Last configured: 2016-07-27 18:48 CDT by andrew
#
# grnoc-mon at ODOT-SAND-SPRINGS-RESIDENCY-SRX220> show interface terse
#Interface Admin Link
@@ -170,10 +168,11 @@
#vlan.500 up down
#vlan.501 up down
# grnoc-mon at ODOT-SAND-SPRINGS-RESIDENCY-SRX220> show configuration
-## Last commit: 2016-04-27 12:02:23 CDT by andrew
+## Last commit: 2016-07-27 18:48:48 CDT by andrew
version 12.1X46-D20.5;
system {
host-name ODOT-SAND-SPRINGS-RESIDENCY-SRX220;
+ auto-snapshot;
domain-name onenet.net;
time-zone America/Chicago;
authentication-order [ password radius ];
Index: configs/core.owtcred.onenet.net
===================================================================
--- configs/core.owtcred.onenet.net (revision 145072)
+++ configs/core.owtcred.onenet.net (working copy)
@@ -292,7 +292,7 @@
#lsi.1048578 up up
#lsi.1048679 up up
#lsi.1048680 up up
-#lsi.1048688 up up
+#lsi.1048692 up up
#me0 up up
#me0.0 up up
#mtun up up
Index: configs/doh-woodward.client.onenet.net
===================================================================
--- configs/doh-woodward.client.onenet.net (revision 145070)
+++ configs/doh-woodward.client.onenet.net (working copy)
@@ -0,0 +1,785 @@
+# RANCID-CONTENT-TYPE: juniper
+#
+# grnoc-mon at DOH-WOODWARD-SRX220> show system commit
+# 2016-07-27 18:34:27 CDT by andrew via cli commit confirmed, rollback in 5mins
+# 2015-05-08 13:46:14 CDT by andrew via cli
+# 2015-05-08 09:46:08 CDT by andrew via cli
+# 2015-05-08 08:58:02 CDT by andrew via cli
+# 2014-11-07 15:46:44 CST by admin via netconf
+# 2014-09-04 23:16:13 CDT by root via other
+# grnoc-mon at DOH-WOODWARD-SRX220> show chassis environment
+# Class Item Status Measurement
+# Temp Routing Engine OK
+# Routing Engine CPU Absent
+# Fans SRX220 Chassis fan 0 OK
+# SRX220 Chassis fan 1 OK
+# Power Power Supply 0 OK
+#
+# grnoc-mon at DOH-WOODWARD-SRX220> show chassis firmware
+# Part Type Version
+# FPC 0 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FPC 1 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FWDD O/S Version 12.1X46-D20.5 by builder on 2014-05
+#
+# grnoc-mon at DOH-WOODWARD-SRX220> show chassis fpc detail
+# Slot 0 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+# Slot 1 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+#
+# grnoc-mon at DOH-WOODWARD-SRX220> show chassis hardware
+# Hardware inventory:
+# Item Version Part number Serial number Description
+# Chassis AR3212AA0032 SRX220H-POE
+# Routing Engine REV 20 750-031177 AAEY4185 RE-SRX220H-POE
+# FPC 0 FPC
+# PIC 0 8x GE Base PIC
+# FPC 1 REV 07 750-023367 AAEY7063 FPC
+# PIC 0 1x T1E1 mPIM
+# Power Supply 0
+#
+# grnoc-mon at DOH-WOODWARD-SRX220> show chassis hardware models
+# grnoc-mon at DOH-WOODWARD-SRX220> show chassis routing-engine
+# Routing Engine status:
+# Serial ID AAEY4185
+#
+# grnoc-mon at DOH-WOODWARD-SRX220> show chassis scb
+# grnoc-mon at DOH-WOODWARD-SRX220> show chassis sfm detail
+# grnoc-mon at DOH-WOODWARD-SRX220> show chassis ssb
+# grnoc-mon at DOH-WOODWARD-SRX220> show system boot-messages
+# kld_map_v: 0x8ff80000, kld_map_p: 0x0
+# Copyright (c) 1996-2014, Juniper Networks, Inc.
+# All rights reserved.
+# Copyright (c) 1992-2006 The FreeBSD Project.
+# Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
+# The Regents of the University of California. All rights reserved.
+# FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
+# Security policy loaded: JUNOS MAC/pcap (mac_pcap)
+# Security policy loaded: JUNOS MAC/runasnonroot (mac_runasnonroot)
+# netisr_init: !debug_mpsafenet, forcing maxthreads from 2 to 1
+# cpu0 on motherboard
+# : CAVIUM's OCTEON 5020 CPU Rev. 0.1 with no FPU implemented
+# L1 Cache: I size 32kb(128 line), D size 8kb(128 line), sixty four way.
+# L2 Cache: Size 128kb, 8 way
+# obio0 on motherboard
+# uart0: <Octeon-16550 channel 0> on obio0
+# uart0: console (9600,n,8,1)
+# twsi0 on obio0
+# dwc0: <Synopsis DWC OTG Controller Driver> on obio0
+# usb0: <USB Bus for DWC OTG Controller> on dwc0
+# usb0: USB revision 2.0
+# uhub0: vendor 0x0000 DWC OTG root hub, class 9/0, rev 2.00/1.00, addr 1
+# uhub0: 1 port with 1 removable, self powered
+# uhub1: vendor 0x0409 product 0x005a, class 9/0, rev 2.00/1.00, addr 2
+# uhub1: single transaction translator
+# uhub1: 3 ports with 2 removable, self powered
+# cpld0 on obio0
+# pcib0: <Cavium on-chip PCI bridge> on obio0
+# Disabling Octeon big bar support
+# PCI Status: PCI 32-bit: 0xc041b
+# pcib0: Initialized controller
+# pci0: <PCI bus> on pcib0
+# pci0: <simple comms> at device 1.0 (no driver attached)
+# atapci0: <SiI 0680 UDMA133 controller> port 0x8-0xb,0x10-0x17,0x18-0x1b,0x20-0x2f mem 0x8020000-0x80200ff irq 0 at device 2.0 on pci0
+# ata2: <ATA channel 0> on atapci0
+# ata3: <ATA channel 1> on atapci0
+# gblmem0 on obio0
+# octpkt0: <Octeon RGMII> on obio0
+# cfi0: <AMD/Fujitsu - 8MB> on obio0
+# Timecounter "mips" frequency 700000000 Hz quality 0
+# ###PCB Group initialized for udppcbgroup
+# ###PCB Group initialized for tcppcbgroup
+# ad0: Device does not support APM
+# ad0: 1006MB <CF 1GB 20080112> at ata2-master WDMA2
+# Trying to mount root from ufs:/dev/ad0s1a
+# WARNING: / was not properly dismounted
+# WARNING: / was not properly dismounted
+#
+# grnoc-mon at DOH-WOODWARD-SRX220> show version
+# Hostname: DOH-WOODWARD-SRX220 # Model: srx220h-poe # JUNOS Software Release [12.1X46-D20.5] # # grnoc-mon at DOH-WOODWARD-SRX220> file list /var/tmp detail # lrw-r--r-- 1 root wheel 11 May 14 2014 /var/tmp@ -> /cf/var/tmp
+# total files: 1
+#
+# grnoc-mon at DOH-WOODWARD-SRX220> show system uptime
+# System booted: 2016-07-27 18:37 CDT
+# Protocols started: 2016-07-27 18:38 CDT
+# Last configured: 2016-07-27 18:34 CDT by andrew
+#
+# grnoc-mon at DOH-WOODWARD-SRX220> show interface terse
+#Interface Admin Link
+#ge-0/0/0 up up
+#ge-0/0/0.0 up up
+#gr-0/0/0 up up
+#ip-0/0/0 up up
+#lsq-0/0/0 up up
+#lt-0/0/0 up up
+#mt-0/0/0 up up
+#sp-0/0/0 up up
+#sp-0/0/0.0 up up
+#sp-0/0/0.16383 up up
+#ge-0/0/1 up up
+#ge-0/0/1.0 up up
+#ge-0/0/2 down down
+#ge-0/0/3 down down
+#ge-0/0/4 down down
+#ge-0/0/5 down down
+#ge-0/0/6 down down
+#ge-0/0/7 down down
+#t1-1/0/0 up up
+#t1-1/0/0.16 up up
+#t1-1/0/0.17 up up
+#t1-1/0/0.18 up up
+#fxp2 up up
+#fxp2.0 up up
+#gre up up
+#ipip up up
+#irb up up
+#lo0 up up
+#lo0.0 up up
+#lo0.16384 up up
+#lo0.16385 up up
+#lo0.32768 up up
+#lsi up up
+#mtun up up
+#pimd up up
+#pime up up
+#pp0 up up
+#ppd0 up up
+#ppe0 up up
+#st0 up up
+#tap up up
+#vlan up up
+# grnoc-mon at DOH-WOODWARD-SRX220> show configuration
+## Last commit: 2016-07-27 18:34:27 CDT by andrew
+version 12.1X46-D20.5;
+system {
+ host-name DOH-WOODWARD-SRX220;
+ domain-name onenet.net;
+ time-zone America/Chicago;
+ authentication-order [ password radius ];
+ ports {
+ console log-out-on-disconnect;
+ }
+ root-authentication {
+# encrypted-password <removed>;
+ }
+ name-server {
+ 10.119.255.3;
+ 10.119.255.4;
+ }
+ radius-server {
+ 10.119.255.7 {
+ port 1812;
+ accounting-port 1813;
+# secret "<removed>"; ## SECRET-DATA
+ source-address 10.119.78.213;
+ }
+ }
+ radius-options {
+ attributes {
+ nas-ip-address 10.119.78.213;
+ }
+ }
+ login {
+ message "\n+----------------------------------------------------------------------------+\n| |\n| Managed by Oklahoma State Regents for Higher Education |\n| Oklahoma Network for Education Enrichment (ONENET) |\n| |\n| *** Unauthorized Use or Access Prohibited *** |\n| |\n| For more information, contact: |\n| |\n| Oklahoma State Regents for Higher Education |\n| Educational Telecommunications Network -- ONENET |\n| (888) 566-3638 |\n| !
info at onenet.net |\n| |\n+----------------------------------------------------------------------------+\n";
+ class admin {
+ idle-timeout 30;
+ permissions all;
+ }
+ class lockdown {
+ idle-timeout 2;
+ permissions view;
+ deny-commands .*;
+ deny-configuration .*;
+ }
+ class operator-local {
+ idle-timeout 15;
+ permissions [ access admin configure firewall interface network routing snmp system trace view ];
+ allow-commands "show log messages";
+ }
+ class robot {
+ idle-timeout 10;
+ permissions [ admin configure firewall interface routing secret security snmp system trace view ];
+ }
+ user admin {
+ uid 1000;
+ class super-user;
+ authentication {
+# encrypted-password <removed>;
+ }
+ }
+ user client {
+ uid 2000;
+ class admin;
+ }
+ user eng {
+ uid 2018;
+ class admin;
+ }
+ user rancid {
+ uid 2001;
+ class robot;
+ }
+ user remote {
+ uid 2002;
+ class operator-local;
+ }
+ user upgrades {
+ uid 2003;
+ class operator;
+ authentication {
+# ssh-rsa <removed>;
+ }
+ }
+ }
+ services {
+ ssh {
+ root-login deny;
+ protocol-version v2;
+ }
+ }
+ syslog {
+ archive size 10m files 5;
+ user * {
+ any emergency;
+ }
+ file messages {
+ any critical;
+ authorization info;
+ }
+ file interactive-commands {
+ interactive-commands any;
+ }
+ file PROTECT-RE {
+ firewall any;
+ archive no-world-readable;
+ }
+ file updown {
+ any any;
+ match "SNMP_TRAP_LINK_|(TRAP_LINK)|bgp_rt_maxprefixes_check|RPD_BGP_NEIGHBOR_STATE";
+ }
+ }
+ max-configurations-on-flash 20;
+ max-configuration-rollbacks 20;
+ license {
+ autoupdate {
+ url https://ae1.juniper.net/junos/key_retrieval;
+ }
+ }
+ ntp {
+ server 10.119.255.5 prefer;
+ server 10.119.255.6;
+ }
+}
+interfaces {
+ ge-0/0/0 {
+ description DOH-DATA;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 172.23.15.1/26;
+ }
+ }
+ }
+ ge-0/0/1 {
+ description DOH-PUBLIC;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 156.110.143.1/29;
+ }
+ }
+ }
+ ge-0/0/2 {
+ disable;
+ }
+ ge-0/0/3 {
+ disable;
+ }
+ ge-0/0/4 {
+ disable;
+ }
+ ge-0/0/5 {
+ disable;
+ }
+ ge-0/0/6 {
+ disable;
+ }
+ ge-0/0/7 {
+ disable;
+ }
+ t1-1/0/0 {
+ description "Link to OneNet";
+ per-unit-scheduler;
+ clocking external;
+ encapsulation frame-relay;
+ t1-options {
+ remote-loopback-respond;
+ }
+ unit 16 {
+ description "DATACOMM-MGMT to OneNet";
+ dlci 16;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.78.213/31;
+ }
+ }
+ unit 17 {
+ description "DOH-DATA to OneNet";
+ dlci 17;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.76.213/31;
+ }
+ }
+ unit 18 {
+ description "DOH-PUBLIC to OneNet";
+ dlci 18;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 172.23.1.18/30;
+ }
+ }
+ }
+ t1-2/0/0 {
+ disable;
+ }
+ lo0 {
+ unit 0 {
+ family inet {
+ filter {
+ input PROTECT-RE;
+ }
+ }
+ }
+ }
+}
+snmp {
+ client-list snmp-management {
+ 10.119.255.0/24;
+ 204.61.5.128/27;
+ 0.0.0.0/0 {
+ restrict;
+ }
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+}
+routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.78.212;
+ }
+}
+protocols {
+ lldp {
+ interface all;
+ }
+ lldp-med {
+ interface all;
+ }
+}
+policy-options {
+ prefix-list PRE-MGMT-SOURCES {
+ 10.119.255.0/24;
+ 164.58.253.0/24;
+ }
+ prefix-list PRE-LOCALIPv4-SOURCES {
+ apply-path "interfaces <*> unit <*> family inet address <*>";
+ }
+ prefix-list PRE-SNMP-SOURCES {
+ 10.119.255.0/24;
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ 204.61.5.128/27;
+ }
+ prefix-list DOH-TIME-SEN-LOW-BW {
+ 172.23.32.70/32;
+ 172.23.32.72/32;
+ 172.23.32.73/32;
+ 172.23.48.10/32;
+ 172.23.48.49/32;
+ 172.23.48.210/32;
+ 172.23.49.158/32;
+ 172.23.49.160/32;
+ 172.23.49.167/32;
+ 172.23.49.208/32;
+ 204.87.86.20/32;
+ }
+ prefix-list TIME-SEN-TRANS {
+ 172.23.48.13/32;
+ 172.23.48.20/32;
+ 172.23.48.72/32;
+ 172.23.48.105/32;
+ 172.23.48.156/32;
+ 172.23.48.193/32;
+ 172.23.49.4/32;
+ 172.23.49.9/32;
+ 172.23.49.39/32;
+ 172.23.49.70/32;
+ 172.23.49.72/32;
+ }
+}
+class-of-service {
+ classifiers {
+ dscp dscp-default {
+ import default;
+ forwarding-class scavenger-service {
+ loss-priority high code-points ss;
+ }
+ }
+ }
+ code-point-aliases {
+ dscp {
+ ss 001000;
+ }
+ exp {
+ ss 001;
+ }
+ }
+ forwarding-classes {
+ queue 0 best-effort;
+ queue 1 assured-forwarding;
+ queue 2 expedited-forwarding;
+ queue 3 network-control;
+ queue 4 scavenger-service;
+ }
+ interfaces {
+ ge-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ t1-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ }
+ rewrite-rules {
+ exp exp-inet-table {
+ forwarding-class best-effort {
+ loss-priority low code-point 000;
+ loss-priority high code-point 001;
+ }
+ forwarding-class assured-forwarding {
+ loss-priority low code-point 010;
+ loss-priority high code-point 011;
+ }
+ forwarding-class expedited-forwarding {
+ loss-priority low code-point 111;
+ loss-priority high code-point 110;
+ }
+ forwarding-class network-control {
+ loss-priority low code-point 100;
+ loss-priority high code-point 101;
+ }
+ }
+ }
+ scheduler-maps {
+ t1-sch-map {
+ forwarding-class best-effort scheduler best-effort-sch;
+ forwarding-class expedited-forwarding scheduler t1-expedited-forwarding-sch;
+ forwarding-class network-control scheduler network-control-sch;
+ forwarding-class assured-forwarding scheduler t1-assured-forwarding-sch;
+ forwarding-class scavenger-service scheduler scavenger-service-sch;
+ }
+ }
+ schedulers {
+ best-effort-sch {
+ transmit-rate {
+ remainder;
+ }
+ buffer-size {
+ remainder;
+ }
+ priority low;
+ }
+ network-control-sch {
+ transmit-rate percent 5;
+ buffer-size percent 5;
+ priority high;
+ }
+ scavenger-service-sch {
+ transmit-rate percent 0;
+ buffer-size percent 0;
+ priority low;
+ }
+ t1-assured-forwarding-sch {
+ transmit-rate percent 45;
+ buffer-size percent 5;
+ priority high;
+ }
+ t1-expedited-forwarding-sch {
+ transmit-rate percent 35;
+ buffer-size percent 5;
+ priority high;
+ }
+ }
+}
+security {
+ policies {
+ from-zone DOH-DATA to-zone DOH-DATA {
+ policy DOH-DATA {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DOH-PUBLIC to-zone DOH-PUBLIC {
+ policy DOH-PUBLIC {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DATACOMM-MGMT to-zone DATACOMM-MGMT {
+ policy DATACOMM-MGMT {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ }
+ zones {
+ security-zone DOH-DATA {
+ interfaces {
+ t1-1/0/0.17 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/0.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DOH-PUBLIC {
+ interfaces {
+ t1-1/0/0.18 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/1.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DATACOMM-MGMT {
+ interfaces {
+ t1-1/0/0.16 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ }
+}
+firewall {
+ family inet {
+ filter PROTECT-RE {
+ term SSH-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-MGMT-SOURCES;
+ PRE-LOCALIPv4-SOURCES;
+ }
+ protocol tcp;
+ destination-port ssh;
+ }
+ then accept;
+ }
+ term SSH-DENY {
+ from {
+ protocol tcp;
+ destination-port ssh;
+ }
+ then {
+ discard;
+ }
+ }
+ term SNMP-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-SNMP-SOURCES;
+ }
+ protocol udp;
+ destination-port snmp;
+ }
+ then accept;
+ }
+ term SNMP-DENY {
+ from {
+ protocol udp;
+ destination-port snmp;
+ }
+ then {
+ discard;
+ }
+ }
+ term ALL-TRAFFIC {
+ then accept;
+ }
+ }
+ }
+ filter DOH-COS {
+ term expedited-forwarding {
+ from {
+ source-address {
+ 164.58.0.0/16;
+ 156.110.0.0/16;
+ }
+ }
+ then {
+ forwarding-class expedited-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-low {
+ from {
+ prefix-list {
+ DOH-TIME-SEN-LOW-BW;
+ }
+ destination-port [ 1433 80 139 445 9100 443 ];
+ }
+ then {
+ loss-priority low;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-high {
+ from {
+ prefix-list {
+ TIME-SEN-TRANS;
+ }
+ destination-port [ 80 135 139 445 1433 5088 5089 6087 ];
+ }
+ then {
+ loss-priority high;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term accept-all {
+ then {
+ forwarding-class best-effort;
+ accept;
+ }
+ }
+ }
+}
+routing-instances {
+ DOH-DATA {
+ instance-type virtual-router;
+ interface ge-0/0/0.0;
+ interface t1-1/0/0.17;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.76.212;
+ }
+ }
+ }
+ DOH-PUBLIC {
+ instance-type virtual-router;
+ interface ge-0/0/1.0;
+ interface t1-1/0/0.18;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 172.23.1.17;
+ }
+ }
+ }
+}
+# grnoc-mon at DOH-WOODWARD-SRX220> show ospf neighbor
+# OSPF instance is not running
+#
+# grnoc-mon at DOH-WOODWARD-SRX220> show bfd session
+
+0 sessions, 0 clients
+Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
+
Index: configs/hub.wea.onenet.net
===================================================================
--- configs/hub.wea.onenet.net (revision 145057)
+++ configs/hub.wea.onenet.net (working copy)
@@ -1,12 +1,12 @@
# RANCID-CONTENT-TYPE: juniper
#
# grnoc-mon at WEATHERFORD-M120-RE0> show system commit
+# 2016-07-27 18:25:44 CDT by andrew via cli commit synchronize
+# 2016-07-27 18:17:35 CDT by andrew via cli commit synchronize
# 2016-07-27 15:34:56 CDT by sky via cli commit synchronize
# 2016-07-27 15:28:57 CDT by sky via cli commit synchronize
# 2016-07-20 18:43:43 CDT by andrew via cli commit synchronize
# 2016-07-20 10:05:36 CDT by andrew via cli commit synchronize
-# 2016-06-06 11:30:28 CDT by sky via cli commit synchronize
-# 2016-04-21 21:41:28 CDT by andrew via cli commit synchronize
# grnoc-mon at WEATHERFORD-M120-RE0> show chassis environment
# Class Item Status Measurement
# Temp PEM 0 OK
@@ -264,7 +264,7 @@
# grnoc-mon at WEATHERFORD-M120-RE0> show system uptime
# System booted: 2016-03-13 01:18 CST
# Protocols started: 2016-03-13 01:27 CST
-# Last configured: 2016-07-27 15:34 CDT by sky
+# Last configured: 2016-07-27 18:25 CDT by andrew
#
# {master}
# grnoc-mon at WEATHERFORD-M120-RE0> show interface terse
@@ -337,10 +337,12 @@
#t1-2/0/3:2.16 up up
#t1-2/0/3:2.17 up up
#t1-2/0/3:3 up up
-#t1-2/0/3:3.0 up up
+#t1-2/0/3:3.16 up up
+#t1-2/0/3:3.17 up up
#t1-2/0/3:4 down down
#t1-2/0/3:5 up up
-#t1-2/0/3:5.0 up up
+#t1-2/0/3:5.16 up up
+#t1-2/0/3:5.17 up up
#t1-2/0/3:6 up up
#t1-2/0/3:6.0 up up
#t1-2/0/3:7 up up
@@ -453,7 +455,7 @@
#pp0 up up
#tap up up
# grnoc-mon at WEATHERFORD-M120-RE0> show configuration
-## Last commit: 2016-07-27 15:34:56 CDT by sky
+## Last commit: 2016-07-27 18:25:44 CDT by andrew
version 13.3R8.7;
groups {
re0 {
@@ -1105,22 +1107,27 @@
}
}
t1-2/0/3:3 {
- description "DOH-WEATHERFORD-T1-CIR0000632-OCS [DECOM]";
- mtu 1518;
- encapsulation cisco-hdlc;
- unit 0 {
+ description DOH-WEATHERFORD-T1-CIR0000632-OCS;
+ dce;
+ encapsulation frame-relay;
+ unit 16 {
+ dlci 16;
family inet {
- mtu 1512;
sampling {
input;
+ output;
}
- address 172.23.0.33/30;
+ address 10.119.78.134/31;
}
- family mpls {
- filter {
- input FLOW-MPLS;
- output FLOW-MPLS;
+ }
+ unit 17 {
+ dlci 17;
+ family inet {
+ sampling {
+ input;
+ output;
}
+ address 10.119.76.134/31;
}
}
}
@@ -1128,22 +1135,27 @@
disable;
}
t1-2/0/3:5 {
- description "DOH-Washita-County-Health-Dept-T1-CIR0001080-OCS [DECOM]";
- mtu 1518;
- encapsulation cisco-hdlc;
- unit 0 {
+ description DOH-CORDELL-T1-CIR0001080-OCS;
+ dce;
+ encapsulation frame-relay;
+ unit 16 {
+ dlci 16;
family inet {
- mtu 1512;
sampling {
input;
+ output;
}
- address 172.23.0.37/30;
+ address 10.119.78.244/31;
}
- family mpls {
- filter {
- input FLOW-MPLS;
- output FLOW-MPLS;
+ }
+ unit 17 {
+ dlci 17;
+ family inet {
+ sampling {
+ input;
+ output;
}
+ address 10.119.76.244/31;
}
}
}
@@ -1604,8 +1616,6 @@
icmp-tunneling;
interface lo0.0;
interface ge-3/2/3.0;
- interface t1-2/0/3:3.0;
- interface t1-2/0/3:5.0;
}
bgp {
inactive: path-selection cisco-non-deterministic;
@@ -1684,26 +1694,6 @@
}
}
}
- area 0.0.0.3 {
- nssa {
- default-lsa {
- default-metric 10;
- metric-type 1;
- type-7;
- }
- summaries;
- }
- interface t1-2/0/3:3.0 {
- authentication {
- md5 7# key <removed>;
- }
- }
- interface t1-2/0/3:5.0 {
- authentication {
- md5 7# key <removed>;
- }
- }
- }
}
ospf3 {
reference-bandwidth 100g;
@@ -1722,8 +1712,6 @@
ldp {
preference 255;
track-igp-metric;
- interface t1-2/0/3:3.0;
- interface t1-2/0/3:5.0;
interface ge-3/2/3.0;
interface lo0.0;
}
@@ -2368,11 +2356,19 @@
DOH-L3VPN {
description DOH-L3VPN;
instance-type vrf;
+ interface t1-2/0/3:3.17;
+ interface t1-2/0/3:5.17;
route-distinguisher 164.58.199.38:3000;
vrf-import DOH-VRF-IMPORT;
vrf-export DOH-VRF-EXPORT;
vrf-target target:5078:3000;
vrf-table-label;
+ routing-options {
+ static {
+ route 172.23.18.0/26 next-hop 10.119.76.135;
+ route 172.23.18.64/26 next-hop 10.119.76.245;
+ }
+ }
}
OMES-AGENCY-DATA-L3VPN {
description OMES-AGENCY-DATA-L3VPN;
@@ -2405,6 +2401,8 @@
description OMES-MGMT-L3VPN;
instance-type vrf;
interface t1-2/0/3:2.16;
+ interface t1-2/0/3:3.16;
+ interface t1-2/0/3:5.16;
route-distinguisher 164.58.199.38:2550;
vrf-import OMES-MGMT-VRF-IMPORT;
vrf-export OMES-MGMT-VRF-EXPORT;
@@ -2445,8 +2443,6 @@
# grnoc-mon at WEATHERFORD-M120-RE0> show ospf neighbor
# Address Interface State ID Pri Dead
# 164.58.245.41 ge-3/2/3.0 Full 164.58.199.39
-# 172.23.0.34 t1-2/0/3:3.0 Full 10.199.2.75
-# 172.23.0.38 t1-2/0/3:5.0 Full 10.199.2.130
#
# {master}
# grnoc-mon at WEATHERFORD-M120-RE0> show bfd session
Index: configs/hub.ton.onenet.net
===================================================================
--- configs/hub.ton.onenet.net (revision 145057)
+++ configs/hub.ton.onenet.net (working copy)
@@ -1,12 +1,12 @@
# RANCID-CONTENT-TYPE: juniper
#
# grnoc-mon at TONKAWA-M120-RE0> show system commit
+# 2016-07-27 18:43:02 CDT by andrew via cli commit synchronize
# 2016-07-27 15:30:19 CDT by sky via cli commit synchronize
# 2016-07-20 18:43:48 CDT by andrew via cli commit synchronize
# 2016-07-20 14:09:37 CDT by andrew via cli commit synchronize
# 2016-05-19 13:40:27 CDT by andrew via cli commit synchronize
# 2016-05-19 13:39:18 CDT by andrew via cli commit synchronize
-# 2016-05-19 13:36:08 CDT by andrew via cli commit synchronize
# grnoc-mon at TONKAWA-M120-RE0> show chassis environment
# Class Item Status Measurement
# Temp PEM 0 OK
@@ -287,7 +287,7 @@
# grnoc-mon at TONKAWA-M120-RE0> show system uptime
# System booted: 2016-03-20 00:48 CDT
# Protocols started: 2016-03-20 00:54 CDT
-# Last configured: 2016-07-27 15:30 CDT by sky
+# Last configured: 2016-07-27 18:43 CDT by andrew
#
# {master}
# grnoc-mon at TONKAWA-M120-RE0> show interface terse
@@ -377,7 +377,8 @@
#t1-2/0/3:19 up up
#t1-2/0/3:19.0 up up
#t1-2/0/3:20 up up
-#t1-2/0/3:20.0 up up
+#t1-2/0/3:20.16 up up
+#t1-2/0/3:20.17 up up
#t1-2/0/3:21 down down
#t1-2/0/3:22 up down
#t1-2/0/3:23 down down
@@ -465,7 +466,7 @@
#pp0 up up
#tap up up
# grnoc-mon at TONKAWA-M120-RE0> show configuration
-## Last commit: 2016-07-27 15:30:19 CDT by sky
+## Last commit: 2016-07-27 18:43:02 CDT by andrew
version 13.3R8.7;
groups {
re0 {
@@ -1164,22 +1165,27 @@
}
}
t1-2/0/3:20 {
- description "DOH-BLACKWELL-T1-CIR0000964-OCS [DECOM]";
- mtu 1518;
- encapsulation cisco-hdlc;
- unit 0 {
+ description DOH-BLACKWELL-T1-CIR0000964-OCS;
+ dce;
+ encapsulation frame-relay;
+ unit 16 {
+ dlci 16;
family inet {
- mtu 1512;
sampling {
input;
+ output;
}
- address 172.23.0.49/30;
+ address 10.119.78.230/31;
}
- family mpls {
- filter {
- input FLOW-MPLS;
- output FLOW-MPLS;
+ }
+ unit 17 {
+ dlci 17;
+ family inet {
+ sampling {
+ input;
+ output;
}
+ address 10.119.76.230/31;
}
}
}
@@ -1483,7 +1489,6 @@
interface ge-4/0/3.402;
interface ge-4/0/3.403;
interface ge-4/0/3.406;
- interface t1-2/0/3:20.0;
}
bgp {
group CORE-RR-OKC-V6 {
@@ -1593,21 +1598,6 @@
}
}
}
- area 0.0.0.3 {
- nssa {
- default-lsa {
- default-metric 10;
- metric-type 1;
- type-7;
- }
- summaries;
- }
- interface t1-2/0/3:20.0 {
- authentication {
- md5 7# key <removed>;
- }
- }
- }
}
ospf3 {
reference-bandwidth 100g;
@@ -1645,7 +1635,6 @@
ldp {
preference 255;
track-igp-metric;
- interface t1-2/0/3:20.0;
interface ge-4/0/0.0;
interface ge-4/0/3.402;
interface ge-4/0/3.403;
@@ -2237,15 +2226,22 @@
DOH-L3VPN {
description DOH-L3VPN;
instance-type vrf;
+ interface t1-2/0/3:20.17;
route-distinguisher 164.58.199.70:3000;
vrf-import DOH-VRF-IMPORT;
vrf-export DOH-VRF-EXPORT;
vrf-target target:5078:3000;
vrf-table-label;
+ routing-options {
+ static {
+ route 172.23.19.0/26 next-hop 10.119.76.231;
+ }
+ }
}
OMES-MGMT-L3VPN {
description OMES-MGMT-L3VPN;
instance-type vrf;
+ interface t1-2/0/3:20.16;
route-distinguisher 164.58.199.70:2550;
vrf-import OMES-MGMT-VRF-IMPORT;
vrf-export OMES-MGMT-VRF-EXPORT;
@@ -2268,7 +2264,6 @@
# grnoc-mon at TONKAWA-M120-RE0> show ospf neighbor
# Address Interface State ID Pri Dead
# 164.58.245.166 ge-4/0/0.0 Full 164.58.199.186
-# 172.23.0.50 t1-2/0/3:20.0 Full 10.199.2.123
#
# {master}
# grnoc-mon at TONKAWA-M120-RE0> show bfd session
Index: configs/doh-walters.client.onenet.net
===================================================================
--- configs/doh-walters.client.onenet.net (revision 145066)
+++ configs/doh-walters.client.onenet.net (working copy)
@@ -0,0 +1,785 @@
+# RANCID-CONTENT-TYPE: juniper
+#
+# grnoc-mon at DOH-WALTERS-SRX220> show system commit
+# 2016-07-27 18:20:01 CDT by admin via cli commit confirmed, rollback in 5mins
+# 2015-12-04 11:41:10 CST by sky via cli
+# 2015-12-04 11:26:42 CST by sky via cli
+# 2014-11-07 15:47:04 CST by admin via netconf
+# 2014-09-04 22:29:32 CDT by root via other
+# 2014-09-02 21:07:11 CDT by andrew via cli
+# grnoc-mon at DOH-WALTERS-SRX220> show chassis environment
+# Class Item Status Measurement
+# Temp Routing Engine OK
+# Routing Engine CPU Absent
+# Fans SRX220 Chassis fan 0 OK
+# SRX220 Chassis fan 1 OK
+# Power Power Supply 0 OK
+#
+# grnoc-mon at DOH-WALTERS-SRX220> show chassis firmware
+# Part Type Version
+# FPC 0 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FPC 1 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FWDD O/S Version 12.1X46-D20.5 by builder on 2014-05
+#
+# grnoc-mon at DOH-WALTERS-SRX220> show chassis fpc detail
+# Slot 0 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+# Slot 1 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+#
+# grnoc-mon at DOH-WALTERS-SRX220> show chassis hardware
+# Hardware inventory:
+# Item Version Part number Serial number Description
+# Chassis AR3612AA0020 SRX220H-POE
+# Routing Engine REV 20 750-031177 AAFA6695 RE-SRX220H-POE
+# FPC 0 FPC
+# PIC 0 8x GE Base PIC
+# FPC 1 REV 07 750-023367 AAEY7059 FPC
+# PIC 0 1x T1E1 mPIM
+# Power Supply 0
+#
+# grnoc-mon at DOH-WALTERS-SRX220> show chassis hardware models
+# grnoc-mon at DOH-WALTERS-SRX220> show chassis routing-engine
+# Routing Engine status:
+# Serial ID AAFA6695
+#
+# grnoc-mon at DOH-WALTERS-SRX220> show chassis scb
+# grnoc-mon at DOH-WALTERS-SRX220> show chassis sfm detail
+# grnoc-mon at DOH-WALTERS-SRX220> show chassis ssb
+# grnoc-mon at DOH-WALTERS-SRX220> show system boot-messages
+# kld_map_v: 0x8ff80000, kld_map_p: 0x0
+# Copyright (c) 1996-2014, Juniper Networks, Inc.
+# All rights reserved.
+# Copyright (c) 1992-2006 The FreeBSD Project.
+# Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
+# The Regents of the University of California. All rights reserved.
+# FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
+# Security policy loaded: JUNOS MAC/pcap (mac_pcap)
+# Security policy loaded: JUNOS MAC/runasnonroot (mac_runasnonroot)
+# netisr_init: !debug_mpsafenet, forcing maxthreads from 2 to 1
+# cpu0 on motherboard
+# : CAVIUM's OCTEON 5020 CPU Rev. 0.1 with no FPU implemented
+# L1 Cache: I size 32kb(128 line), D size 8kb(128 line), sixty four way.
+# L2 Cache: Size 128kb, 8 way
+# obio0 on motherboard
+# uart0: <Octeon-16550 channel 0> on obio0
+# uart0: console (9600,n,8,1)
+# twsi0 on obio0
+# dwc0: <Synopsis DWC OTG Controller Driver> on obio0
+# usb0: <USB Bus for DWC OTG Controller> on dwc0
+# usb0: USB revision 2.0
+# uhub0: vendor 0x0000 DWC OTG root hub, class 9/0, rev 2.00/1.00, addr 1
+# uhub0: 1 port with 1 removable, self powered
+# uhub1: vendor 0x0409 product 0x005a, class 9/0, rev 2.00/1.00, addr 2
+# uhub1: single transaction translator
+# uhub1: 3 ports with 2 removable, self powered
+# cpld0 on obio0
+# pcib0: <Cavium on-chip PCI bridge> on obio0
+# Disabling Octeon big bar support
+# PCI Status: PCI 32-bit: 0xc041b
+# pcib0: Initialized controller
+# pci0: <PCI bus> on pcib0
+# pci0: <simple comms> at device 1.0 (no driver attached)
+# atapci0: <SiI 0680 UDMA133 controller> port 0x8-0xb,0x10-0x17,0x18-0x1b,0x20-0x2f mem 0x8020000-0x80200ff irq 0 at device 2.0 on pci0
+# ata2: <ATA channel 0> on atapci0
+# ata3: <ATA channel 1> on atapci0
+# gblmem0 on obio0
+# octpkt0: <Octeon RGMII> on obio0
+# cfi0: <AMD/Fujitsu - 8MB> on obio0
+# Timecounter "mips" frequency 700000000 Hz quality 0
+# ###PCB Group initialized for udppcbgroup
+# ###PCB Group initialized for tcppcbgroup
+# ad0: Device does not support APM
+# ad0: 1006MB <CF 1GB 20080112> at ata2-master WDMA2
+# Trying to mount root from ufs:/dev/ad0s2a
+# WARNING: / was not properly dismounted
+# WARNING: / was not properly dismounted
+#
+# grnoc-mon at DOH-WALTERS-SRX220> show version
+# Hostname: DOH-WALTERS-SRX220 # Model: srx220h-poe # JUNOS Software Release [12.1X46-D20.5] # # grnoc-mon at DOH-WALTERS-SRX220> file list /var/tmp detail # lrw-r--r-- 1 root wheel 11 May 14 2014 /var/tmp@ -> /cf/var/tmp
+# total files: 1
+#
+# grnoc-mon at DOH-WALTERS-SRX220> show system uptime
+# System booted: 2016-07-27 18:25 CDT
+# Protocols started: 2016-07-27 18:27 CDT
+# Last configured: 2016-07-27 18:20 CDT by admin
+#
+# grnoc-mon at DOH-WALTERS-SRX220> show interface terse
+#Interface Admin Link
+#ge-0/0/0 up up
+#ge-0/0/0.0 up up
+#gr-0/0/0 up up
+#ip-0/0/0 up up
+#lsq-0/0/0 up up
+#lt-0/0/0 up up
+#mt-0/0/0 up up
+#sp-0/0/0 up up
+#sp-0/0/0.0 up up
+#sp-0/0/0.16383 up up
+#ge-0/0/1 up up
+#ge-0/0/1.0 up up
+#ge-0/0/2 down down
+#ge-0/0/3 down down
+#ge-0/0/4 down down
+#ge-0/0/5 down down
+#ge-0/0/6 down down
+#ge-0/0/7 down down
+#t1-1/0/0 up up
+#t1-1/0/0.16 up up
+#t1-1/0/0.17 up up
+#t1-1/0/0.18 up up
+#fxp2 up up
+#fxp2.0 up up
+#gre up up
+#ipip up up
+#irb up up
+#lo0 up up
+#lo0.0 up up
+#lo0.16384 up up
+#lo0.16385 up up
+#lo0.32768 up up
+#lsi up up
+#mtun up up
+#pimd up up
+#pime up up
+#pp0 up up
+#ppd0 up up
+#ppe0 up up
+#st0 up up
+#tap up up
+#vlan up up
+# grnoc-mon at DOH-WALTERS-SRX220> show configuration
+## Last commit: 2016-07-27 18:20:01 CDT by admin
+version 12.1X46-D20.5;
+system {
+ host-name DOH-WALTERS-SRX220;
+ domain-name onenet.net;
+ time-zone America/Chicago;
+ authentication-order [ password radius ];
+ ports {
+ console log-out-on-disconnect;
+ }
+ root-authentication {
+# encrypted-password <removed>;
+ }
+ name-server {
+ 10.119.255.3;
+ 10.119.255.4;
+ }
+ radius-server {
+ 10.119.255.7 {
+ port 1812;
+ accounting-port 1813;
+# secret "<removed>"; ## SECRET-DATA
+ source-address 10.119.78.121;
+ }
+ }
+ radius-options {
+ attributes {
+ nas-ip-address 10.119.78.121;
+ }
+ }
+ login {
+ message "\n+----------------------------------------------------------------------------+\n| |\n| Managed by Oklahoma State Regents for Higher Education |\n| Oklahoma Network for Education Enrichment (ONENET) |\n| |\n| *** Unauthorized Use or Access Prohibited *** |\n| |\n| For more information, contact: |\n| |\n| Oklahoma State Regents for Higher Education |\n| Educational Telecommunications Network -- ONENET |\n| (888) 566-3638 |\n| !
info at onenet.net |\n| |\n+----------------------------------------------------------------------------+\n";
+ class admin {
+ idle-timeout 30;
+ permissions all;
+ }
+ class lockdown {
+ idle-timeout 2;
+ permissions view;
+ deny-commands .*;
+ deny-configuration .*;
+ }
+ class operator-local {
+ idle-timeout 15;
+ permissions [ access admin configure firewall interface network routing snmp system trace view ];
+ allow-commands "show log messages";
+ }
+ class robot {
+ idle-timeout 10;
+ permissions [ admin configure firewall interface routing secret security snmp system trace view ];
+ }
+ user admin {
+ uid 1000;
+ class super-user;
+ authentication {
+# encrypted-password <removed>;
+ }
+ }
+ user client {
+ uid 2000;
+ class admin;
+ }
+ user eng {
+ uid 2018;
+ class admin;
+ }
+ user rancid {
+ uid 2001;
+ class robot;
+ }
+ user remote {
+ uid 2002;
+ class operator-local;
+ }
+ user upgrades {
+ uid 2003;
+ class operator;
+ authentication {
+# ssh-rsa <removed>;
+ }
+ }
+ }
+ services {
+ ssh {
+ root-login deny;
+ protocol-version v2;
+ }
+ }
+ syslog {
+ archive size 10m files 5;
+ user * {
+ any emergency;
+ }
+ file messages {
+ any critical;
+ authorization info;
+ }
+ file interactive-commands {
+ interactive-commands any;
+ }
+ file PROTECT-RE {
+ firewall any;
+ archive no-world-readable;
+ }
+ file updown {
+ any any;
+ match "SNMP_TRAP_LINK_|(TRAP_LINK)|bgp_rt_maxprefixes_check|RPD_BGP_NEIGHBOR_STATE";
+ }
+ }
+ max-configurations-on-flash 20;
+ max-configuration-rollbacks 20;
+ license {
+ autoupdate {
+ url https://ae1.juniper.net/junos/key_retrieval;
+ }
+ }
+ ntp {
+ server 10.119.255.5 prefer;
+ server 10.119.255.6;
+ }
+}
+interfaces {
+ ge-0/0/0 {
+ description DOH-DATA;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 172.23.124.65/26;
+ }
+ }
+ }
+ ge-0/0/1 {
+ description DOH-PUBLIC;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 164.58.22.137/30;
+ }
+ }
+ }
+ ge-0/0/2 {
+ disable;
+ }
+ ge-0/0/3 {
+ disable;
+ }
+ ge-0/0/4 {
+ disable;
+ }
+ ge-0/0/5 {
+ disable;
+ }
+ ge-0/0/6 {
+ disable;
+ }
+ ge-0/0/7 {
+ disable;
+ }
+ t1-1/0/0 {
+ description "Link to OneNet";
+ per-unit-scheduler;
+ clocking external;
+ encapsulation frame-relay;
+ t1-options {
+ remote-loopback-respond;
+ }
+ unit 16 {
+ description "DATACOMM-MGMT to OneNet";
+ dlci 16;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.78.121/31;
+ }
+ }
+ unit 17 {
+ description "DOH-DATA to OneNet";
+ dlci 17;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.76.121/31;
+ }
+ }
+ unit 18 {
+ description "DOH-PUBLIC to OneNet";
+ dlci 18;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 172.23.5.198/30;
+ }
+ }
+ }
+ t1-2/0/0 {
+ disable;
+ }
+ lo0 {
+ unit 0 {
+ family inet {
+ filter {
+ input PROTECT-RE;
+ }
+ }
+ }
+ }
+}
+snmp {
+ client-list snmp-management {
+ 10.119.255.0/24;
+ 204.61.5.128/27;
+ 0.0.0.0/0 {
+ restrict;
+ }
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+}
+routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.78.120;
+ }
+}
+protocols {
+ lldp {
+ interface all;
+ }
+ lldp-med {
+ interface all;
+ }
+}
+policy-options {
+ prefix-list PRE-MGMT-SOURCES {
+ 10.119.255.0/24;
+ 164.58.253.0/24;
+ }
+ prefix-list PRE-LOCALIPv4-SOURCES {
+ apply-path "interfaces <*> unit <*> family inet address <*>";
+ }
+ prefix-list PRE-SNMP-SOURCES {
+ 10.119.255.0/24;
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ 204.61.5.128/27;
+ }
+ prefix-list DOH-TIME-SEN-LOW-BW {
+ 172.23.32.70/32;
+ 172.23.32.72/32;
+ 172.23.32.73/32;
+ 172.23.48.10/32;
+ 172.23.48.49/32;
+ 172.23.48.210/32;
+ 172.23.49.158/32;
+ 172.23.49.160/32;
+ 172.23.49.167/32;
+ 172.23.49.208/32;
+ 204.87.86.20/32;
+ }
+ prefix-list TIME-SEN-TRANS {
+ 172.23.48.13/32;
+ 172.23.48.20/32;
+ 172.23.48.72/32;
+ 172.23.48.105/32;
+ 172.23.48.156/32;
+ 172.23.48.193/32;
+ 172.23.49.4/32;
+ 172.23.49.9/32;
+ 172.23.49.39/32;
+ 172.23.49.70/32;
+ 172.23.49.72/32;
+ }
+}
+class-of-service {
+ classifiers {
+ dscp dscp-default {
+ import default;
+ forwarding-class scavenger-service {
+ loss-priority high code-points ss;
+ }
+ }
+ }
+ code-point-aliases {
+ dscp {
+ ss 001000;
+ }
+ exp {
+ ss 001;
+ }
+ }
+ forwarding-classes {
+ queue 0 best-effort;
+ queue 1 assured-forwarding;
+ queue 2 expedited-forwarding;
+ queue 3 network-control;
+ queue 4 scavenger-service;
+ }
+ interfaces {
+ ge-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ t1-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ }
+ rewrite-rules {
+ exp exp-inet-table {
+ forwarding-class best-effort {
+ loss-priority low code-point 000;
+ loss-priority high code-point 001;
+ }
+ forwarding-class assured-forwarding {
+ loss-priority low code-point 010;
+ loss-priority high code-point 011;
+ }
+ forwarding-class expedited-forwarding {
+ loss-priority low code-point 111;
+ loss-priority high code-point 110;
+ }
+ forwarding-class network-control {
+ loss-priority low code-point 100;
+ loss-priority high code-point 101;
+ }
+ }
+ }
+ scheduler-maps {
+ t1-sch-map {
+ forwarding-class best-effort scheduler best-effort-sch;
+ forwarding-class expedited-forwarding scheduler t1-expedited-forwarding-sch;
+ forwarding-class network-control scheduler network-control-sch;
+ forwarding-class assured-forwarding scheduler t1-assured-forwarding-sch;
+ forwarding-class scavenger-service scheduler scavenger-service-sch;
+ }
+ }
+ schedulers {
+ best-effort-sch {
+ transmit-rate {
+ remainder;
+ }
+ buffer-size {
+ remainder;
+ }
+ priority low;
+ }
+ network-control-sch {
+ transmit-rate percent 5;
+ buffer-size percent 5;
+ priority high;
+ }
+ scavenger-service-sch {
+ transmit-rate percent 0;
+ buffer-size percent 0;
+ priority low;
+ }
+ t1-assured-forwarding-sch {
+ transmit-rate percent 45;
+ buffer-size percent 5;
+ priority high;
+ }
+ t1-expedited-forwarding-sch {
+ transmit-rate percent 35;
+ buffer-size percent 5;
+ priority high;
+ }
+ }
+}
+security {
+ policies {
+ from-zone DOH-DATA to-zone DOH-DATA {
+ policy DOH-DATA {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DOH-PUBLIC to-zone DOH-PUBLIC {
+ policy DOH-PUBLIC {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DATACOMM-MGMT to-zone DATACOMM-MGMT {
+ policy DATACOMM-MGMT {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ }
+ zones {
+ security-zone DOH-DATA {
+ interfaces {
+ t1-1/0/0.17 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/0.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DOH-PUBLIC {
+ interfaces {
+ t1-1/0/0.18 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/1.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DATACOMM-MGMT {
+ interfaces {
+ t1-1/0/0.16 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ }
+}
+firewall {
+ family inet {
+ filter PROTECT-RE {
+ term SSH-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-MGMT-SOURCES;
+ PRE-LOCALIPv4-SOURCES;
+ }
+ protocol tcp;
+ destination-port ssh;
+ }
+ then accept;
+ }
+ term SSH-DENY {
+ from {
+ protocol tcp;
+ destination-port ssh;
+ }
+ then {
+ discard;
+ }
+ }
+ term SNMP-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-SNMP-SOURCES;
+ }
+ protocol udp;
+ destination-port snmp;
+ }
+ then accept;
+ }
+ term SNMP-DENY {
+ from {
+ protocol udp;
+ destination-port snmp;
+ }
+ then {
+ discard;
+ }
+ }
+ term ALL-TRAFFIC {
+ then accept;
+ }
+ }
+ }
+ filter DOH-COS {
+ term expedited-forwarding {
+ from {
+ source-address {
+ 164.58.0.0/16;
+ 156.110.0.0/16;
+ }
+ }
+ then {
+ forwarding-class expedited-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-low {
+ from {
+ prefix-list {
+ DOH-TIME-SEN-LOW-BW;
+ }
+ destination-port [ 1433 80 139 445 9100 443 ];
+ }
+ then {
+ loss-priority low;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-high {
+ from {
+ prefix-list {
+ TIME-SEN-TRANS;
+ }
+ destination-port [ 80 135 139 445 1433 5088 5089 6087 ];
+ }
+ then {
+ loss-priority high;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term accept-all {
+ then {
+ forwarding-class best-effort;
+ accept;
+ }
+ }
+ }
+}
+routing-instances {
+ DOH-DATA {
+ instance-type virtual-router;
+ interface ge-0/0/0.0;
+ interface t1-1/0/0.17;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.76.120;
+ }
+ }
+ }
+ DOH-PUBLIC {
+ instance-type virtual-router;
+ interface ge-0/0/1.0;
+ interface t1-1/0/0.18;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 172.23.5.197;
+ }
+ }
+ }
+}
+# grnoc-mon at DOH-WALTERS-SRX220> show ospf neighbor
+# OSPF instance is not running
+#
+# grnoc-mon at DOH-WALTERS-SRX220> show bfd session
+
+0 sessions, 0 clients
+Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
+
Index: configs/doh-stigler.client.onenet.net
===================================================================
--- configs/doh-stigler.client.onenet.net (revision 145064)
+++ configs/doh-stigler.client.onenet.net (working copy)
@@ -0,0 +1,785 @@
+# RANCID-CONTENT-TYPE: juniper
+#
+# grnoc-mon at DOH-STIGLER-SRX220> show system commit
+# 2016-07-27 18:33:17 CDT by admin via cli commit confirmed, rollback in 5mins
+# 2015-12-17 13:12:25 CST by root via other
+# 2015-12-17 13:08:41 CST by joel via cli commit confirmed, rollback in 3mins
+# 2015-12-17 12:44:19 CST by joel via cli commit confirmed, rollback in 5mins
+# 2014-11-07 15:47:04 CST by admin via netconf
+# 2014-09-04 23:01:08 CDT by andrew via cli
+# grnoc-mon at DOH-STIGLER-SRX220> show chassis environment
+# Class Item Status Measurement
+# Temp Routing Engine OK
+# Routing Engine CPU Absent
+# Fans SRX220 Chassis fan 0 OK
+# SRX220 Chassis fan 1 OK
+# Power Power Supply 0 OK
+#
+# grnoc-mon at DOH-STIGLER-SRX220> show chassis firmware
+# Part Type Version
+# FPC 0 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FPC 1 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FWDD O/S Version 12.1X46-D20.5 by builder on 2014-05
+#
+# grnoc-mon at DOH-STIGLER-SRX220> show chassis fpc detail
+# Slot 0 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+# Slot 1 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+#
+# grnoc-mon at DOH-STIGLER-SRX220> show chassis hardware
+# Hardware inventory:
+# Item Version Part number Serial number Description
+# Chassis AR3612AA0047 SRX220H-POE
+# Routing Engine REV 20 750-031177 AAEY9215 RE-SRX220H-POE
+# FPC 0 FPC
+# PIC 0 8x GE Base PIC
+# FPC 1 REV 07 750-023367 AAEW6621 FPC
+# PIC 0 1x T1E1 mPIM
+# Power Supply 0
+#
+# grnoc-mon at DOH-STIGLER-SRX220> show chassis hardware models
+# grnoc-mon at DOH-STIGLER-SRX220> show chassis routing-engine
+# Routing Engine status:
+# Serial ID AAEY9215
+#
+# grnoc-mon at DOH-STIGLER-SRX220> show chassis scb
+# grnoc-mon at DOH-STIGLER-SRX220> show chassis sfm detail
+# grnoc-mon at DOH-STIGLER-SRX220> show chassis ssb
+# grnoc-mon at DOH-STIGLER-SRX220> show system boot-messages
+# kld_map_v: 0x8ff80000, kld_map_p: 0x0
+# Copyright (c) 1996-2014, Juniper Networks, Inc.
+# All rights reserved.
+# Copyright (c) 1992-2006 The FreeBSD Project.
+# Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
+# The Regents of the University of California. All rights reserved.
+# FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
+# Security policy loaded: JUNOS MAC/pcap (mac_pcap)
+# Security policy loaded: JUNOS MAC/runasnonroot (mac_runasnonroot)
+# netisr_init: !debug_mpsafenet, forcing maxthreads from 2 to 1
+# cpu0 on motherboard
+# : CAVIUM's OCTEON 5020 CPU Rev. 0.1 with no FPU implemented
+# L1 Cache: I size 32kb(128 line), D size 8kb(128 line), sixty four way.
+# L2 Cache: Size 128kb, 8 way
+# obio0 on motherboard
+# uart0: <Octeon-16550 channel 0> on obio0
+# uart0: console (9600,n,8,1)
+# twsi0 on obio0
+# dwc0: <Synopsis DWC OTG Controller Driver> on obio0
+# usb0: <USB Bus for DWC OTG Controller> on dwc0
+# usb0: USB revision 2.0
+# uhub0: vendor 0x0000 DWC OTG root hub, class 9/0, rev 2.00/1.00, addr 1
+# uhub0: 1 port with 1 removable, self powered
+# uhub1: vendor 0x0409 product 0x005a, class 9/0, rev 2.00/1.00, addr 2
+# uhub1: single transaction translator
+# uhub1: 3 ports with 2 removable, self powered
+# cpld0 on obio0
+# pcib0: <Cavium on-chip PCI bridge> on obio0
+# Disabling Octeon big bar support
+# PCI Status: PCI 32-bit: 0xc041b
+# pcib0: Initialized controller
+# pci0: <PCI bus> on pcib0
+# pci0: <simple comms> at device 1.0 (no driver attached)
+# atapci0: <SiI 0680 UDMA133 controller> port 0x8-0xb,0x10-0x17,0x18-0x1b,0x20-0x2f mem 0x8020000-0x80200ff irq 0 at device 2.0 on pci0
+# ata2: <ATA channel 0> on atapci0
+# ata3: <ATA channel 1> on atapci0
+# gblmem0 on obio0
+# octpkt0: <Octeon RGMII> on obio0
+# cfi0: <AMD/Fujitsu - 8MB> on obio0
+# Timecounter "mips" frequency 700000000 Hz quality 0
+# ###PCB Group initialized for udppcbgroup
+# ###PCB Group initialized for tcppcbgroup
+# ad0: Device does not support APM
+# ad0: 1006MB <CF 1GB 20080112> at ata2-master WDMA2
+# Trying to mount root from ufs:/dev/ad0s2a
+# WARNING: / was not properly dismounted
+# WARNING: / was not properly dismounted
+#
+# grnoc-mon at DOH-STIGLER-SRX220> show version
+# Hostname: DOH-STIGLER-SRX220 # Model: srx220h-poe # JUNOS Software Release [12.1X46-D20.5] # # grnoc-mon at DOH-STIGLER-SRX220> file list /var/tmp detail # lrw-r--r-- 1 root wheel 11 May 14 2014 /var/tmp@ -> /cf/var/tmp
+# total files: 1
+#
+# grnoc-mon at DOH-STIGLER-SRX220> show system uptime
+# System booted: 2016-07-27 18:36 CDT
+# Protocols started: 2016-07-27 18:38 CDT
+# Last configured: 2016-07-27 18:33 CDT by admin
+#
+# grnoc-mon at DOH-STIGLER-SRX220> show interface terse
+#Interface Admin Link
+#ge-0/0/0 up up
+#ge-0/0/0.0 up up
+#gr-0/0/0 up up
+#ip-0/0/0 up up
+#lsq-0/0/0 up up
+#lt-0/0/0 up up
+#mt-0/0/0 up up
+#sp-0/0/0 up up
+#sp-0/0/0.0 up up
+#sp-0/0/0.16383 up up
+#ge-0/0/1 up up
+#ge-0/0/1.0 up up
+#ge-0/0/2 down down
+#ge-0/0/3 down down
+#ge-0/0/4 down down
+#ge-0/0/5 down down
+#ge-0/0/6 down down
+#ge-0/0/7 down down
+#t1-1/0/0 up up
+#t1-1/0/0.16 up up
+#t1-1/0/0.17 up up
+#t1-1/0/0.18 up up
+#fxp2 up up
+#fxp2.0 up up
+#gre up up
+#ipip up up
+#irb up up
+#lo0 up up
+#lo0.0 up up
+#lo0.16384 up up
+#lo0.16385 up up
+#lo0.32768 up up
+#lsi up up
+#mtun up up
+#pimd up up
+#pime up up
+#pp0 up up
+#ppd0 up up
+#ppe0 up up
+#st0 up up
+#tap up up
+#vlan up up
+# grnoc-mon at DOH-STIGLER-SRX220> show configuration
+## Last commit: 2016-07-27 18:33:17 CDT by admin
+version 12.1X46-D20.5;
+system {
+ host-name DOH-STIGLER-SRX220;
+ domain-name onenet.net;
+ time-zone America/Chicago;
+ authentication-order [ password radius ];
+ ports {
+ console log-out-on-disconnect;
+ }
+ root-authentication {
+# encrypted-password <removed>;
+ }
+ name-server {
+ 10.119.255.3;
+ 10.119.255.4;
+ }
+ radius-server {
+ 10.119.255.7 {
+ port 1812;
+ accounting-port 1813;
+# secret "<removed>"; ## SECRET-DATA
+ source-address 10.119.78.159;
+ }
+ }
+ radius-options {
+ attributes {
+ nas-ip-address 10.119.78.159;
+ }
+ }
+ login {
+ message "\n+----------------------------------------------------------------------------+\n| |\n| Managed by Oklahoma State Regents for Higher Education |\n| Oklahoma Network for Education Enrichment (ONENET) |\n| |\n| *** Unauthorized Use or Access Prohibited *** |\n| |\n| For more information, contact: |\n| |\n| Oklahoma State Regents for Higher Education |\n| Educational Telecommunications Network -- ONENET |\n| (888) 566-3638 |\n| !
info at onenet.net |\n| |\n+----------------------------------------------------------------------------+\n";
+ class admin {
+ idle-timeout 30;
+ permissions all;
+ }
+ class lockdown {
+ idle-timeout 2;
+ permissions view;
+ deny-commands .*;
+ deny-configuration .*;
+ }
+ class operator-local {
+ idle-timeout 15;
+ permissions [ access admin configure firewall interface network routing snmp system trace view ];
+ allow-commands "show log messages";
+ }
+ class robot {
+ idle-timeout 10;
+ permissions [ admin configure firewall interface routing secret security snmp system trace view ];
+ }
+ user admin {
+ uid 1000;
+ class super-user;
+ authentication {
+# encrypted-password <removed>;
+ }
+ }
+ user client {
+ uid 2000;
+ class admin;
+ }
+ user eng {
+ uid 2018;
+ class admin;
+ }
+ user rancid {
+ uid 2001;
+ class robot;
+ }
+ user remote {
+ uid 2002;
+ class operator-local;
+ }
+ user upgrades {
+ uid 2003;
+ class operator;
+ authentication {
+# ssh-rsa <removed>;
+ }
+ }
+ }
+ services {
+ ssh {
+ root-login deny;
+ protocol-version v2;
+ }
+ }
+ syslog {
+ archive size 10m files 5;
+ user * {
+ any emergency;
+ }
+ file messages {
+ any critical;
+ authorization info;
+ }
+ file interactive-commands {
+ interactive-commands any;
+ }
+ file PROTECT-RE {
+ firewall any;
+ archive no-world-readable;
+ }
+ file updown {
+ any any;
+ match "SNMP_TRAP_LINK_|(TRAP_LINK)|bgp_rt_maxprefixes_check|RPD_BGP_NEIGHBOR_STATE";
+ }
+ }
+ max-configurations-on-flash 20;
+ max-configuration-rollbacks 20;
+ license {
+ autoupdate {
+ url https://ae1.juniper.net/junos/key_retrieval;
+ }
+ }
+ ntp {
+ server 10.119.255.5 prefer;
+ server 10.119.255.6;
+ }
+}
+interfaces {
+ ge-0/0/0 {
+ description DOH-DATA;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 172.23.26.65/26;
+ }
+ }
+ }
+ ge-0/0/1 {
+ description DOH-PUBLIC;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 156.110.134.101/30;
+ }
+ }
+ }
+ ge-0/0/2 {
+ disable;
+ }
+ ge-0/0/3 {
+ disable;
+ }
+ ge-0/0/4 {
+ disable;
+ }
+ ge-0/0/5 {
+ disable;
+ }
+ ge-0/0/6 {
+ disable;
+ }
+ ge-0/0/7 {
+ disable;
+ }
+ t1-1/0/0 {
+ description "Link to OneNet";
+ per-unit-scheduler;
+ clocking external;
+ encapsulation frame-relay;
+ t1-options {
+ remote-loopback-respond;
+ }
+ unit 16 {
+ description "DATACOMM-MGMT to OneNet";
+ dlci 16;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.78.159/31;
+ }
+ }
+ unit 17 {
+ description "DOH-DATA to OneNet";
+ dlci 17;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.76.159/31;
+ }
+ }
+ unit 18 {
+ description "DOH-PUBLIC to OneNet";
+ dlci 18;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 172.23.0.166/30;
+ }
+ }
+ }
+ t1-2/0/0 {
+ disable;
+ }
+ lo0 {
+ unit 0 {
+ family inet {
+ filter {
+ input PROTECT-RE;
+ }
+ }
+ }
+ }
+}
+snmp {
+ client-list snmp-management {
+ 10.119.255.0/24;
+ 204.61.5.128/27;
+ 0.0.0.0/0 {
+ restrict;
+ }
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+}
+routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.78.158;
+ }
+}
+protocols {
+ lldp {
+ interface all;
+ }
+ lldp-med {
+ interface all;
+ }
+}
+policy-options {
+ prefix-list PRE-MGMT-SOURCES {
+ 10.119.255.0/24;
+ 164.58.253.0/24;
+ }
+ prefix-list PRE-LOCALIPv4-SOURCES {
+ apply-path "interfaces <*> unit <*> family inet address <*>";
+ }
+ prefix-list PRE-SNMP-SOURCES {
+ 10.119.255.0/24;
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ 204.61.5.128/27;
+ }
+ prefix-list DOH-TIME-SEN-LOW-BW {
+ 172.23.32.70/32;
+ 172.23.32.72/32;
+ 172.23.32.73/32;
+ 172.23.48.10/32;
+ 172.23.48.49/32;
+ 172.23.48.210/32;
+ 172.23.49.158/32;
+ 172.23.49.160/32;
+ 172.23.49.167/32;
+ 172.23.49.208/32;
+ 204.87.86.20/32;
+ }
+ prefix-list TIME-SEN-TRANS {
+ 172.23.48.13/32;
+ 172.23.48.20/32;
+ 172.23.48.72/32;
+ 172.23.48.105/32;
+ 172.23.48.156/32;
+ 172.23.48.193/32;
+ 172.23.49.4/32;
+ 172.23.49.9/32;
+ 172.23.49.39/32;
+ 172.23.49.70/32;
+ 172.23.49.72/32;
+ }
+}
+class-of-service {
+ classifiers {
+ dscp dscp-default {
+ import default;
+ forwarding-class scavenger-service {
+ loss-priority high code-points ss;
+ }
+ }
+ }
+ code-point-aliases {
+ dscp {
+ ss 001000;
+ }
+ exp {
+ ss 001;
+ }
+ }
+ forwarding-classes {
+ queue 0 best-effort;
+ queue 1 assured-forwarding;
+ queue 2 expedited-forwarding;
+ queue 3 network-control;
+ queue 4 scavenger-service;
+ }
+ interfaces {
+ ge-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ t1-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ }
+ rewrite-rules {
+ exp exp-inet-table {
+ forwarding-class best-effort {
+ loss-priority low code-point 000;
+ loss-priority high code-point 001;
+ }
+ forwarding-class assured-forwarding {
+ loss-priority low code-point 010;
+ loss-priority high code-point 011;
+ }
+ forwarding-class expedited-forwarding {
+ loss-priority low code-point 111;
+ loss-priority high code-point 110;
+ }
+ forwarding-class network-control {
+ loss-priority low code-point 100;
+ loss-priority high code-point 101;
+ }
+ }
+ }
+ scheduler-maps {
+ t1-sch-map {
+ forwarding-class best-effort scheduler best-effort-sch;
+ forwarding-class expedited-forwarding scheduler t1-expedited-forwarding-sch;
+ forwarding-class network-control scheduler network-control-sch;
+ forwarding-class assured-forwarding scheduler t1-assured-forwarding-sch;
+ forwarding-class scavenger-service scheduler scavenger-service-sch;
+ }
+ }
+ schedulers {
+ best-effort-sch {
+ transmit-rate {
+ remainder;
+ }
+ buffer-size {
+ remainder;
+ }
+ priority low;
+ }
+ network-control-sch {
+ transmit-rate percent 5;
+ buffer-size percent 5;
+ priority high;
+ }
+ scavenger-service-sch {
+ transmit-rate percent 0;
+ buffer-size percent 0;
+ priority low;
+ }
+ t1-assured-forwarding-sch {
+ transmit-rate percent 45;
+ buffer-size percent 5;
+ priority high;
+ }
+ t1-expedited-forwarding-sch {
+ transmit-rate percent 35;
+ buffer-size percent 5;
+ priority high;
+ }
+ }
+}
+security {
+ policies {
+ from-zone DOH-DATA to-zone DOH-DATA {
+ policy DOH-DATA {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DOH-PUBLIC to-zone DOH-PUBLIC {
+ policy DOH-PUBLIC {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DATACOMM-MGMT to-zone DATACOMM-MGMT {
+ policy DATACOMM-MGMT {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ }
+ zones {
+ security-zone DOH-DATA {
+ interfaces {
+ t1-1/0/0.17 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/0.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DOH-PUBLIC {
+ interfaces {
+ t1-1/0/0.18 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/1.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DATACOMM-MGMT {
+ interfaces {
+ t1-1/0/0.16 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ }
+}
+firewall {
+ family inet {
+ filter PROTECT-RE {
+ term SSH-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-MGMT-SOURCES;
+ PRE-LOCALIPv4-SOURCES;
+ }
+ protocol tcp;
+ destination-port ssh;
+ }
+ then accept;
+ }
+ term SSH-DENY {
+ from {
+ protocol tcp;
+ destination-port ssh;
+ }
+ then {
+ discard;
+ }
+ }
+ term SNMP-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-SNMP-SOURCES;
+ }
+ protocol udp;
+ destination-port snmp;
+ }
+ then accept;
+ }
+ term SNMP-DENY {
+ from {
+ protocol udp;
+ destination-port snmp;
+ }
+ then {
+ discard;
+ }
+ }
+ term ALL-TRAFFIC {
+ then accept;
+ }
+ }
+ }
+ filter DOH-COS {
+ term expedited-forwarding {
+ from {
+ source-address {
+ 164.58.0.0/16;
+ 156.110.0.0/16;
+ }
+ }
+ then {
+ forwarding-class expedited-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-low {
+ from {
+ prefix-list {
+ DOH-TIME-SEN-LOW-BW;
+ }
+ destination-port [ 1433 80 139 445 9100 443 ];
+ }
+ then {
+ loss-priority low;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-high {
+ from {
+ prefix-list {
+ TIME-SEN-TRANS;
+ }
+ destination-port [ 80 135 139 445 1433 5088 5089 6087 ];
+ }
+ then {
+ loss-priority high;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term accept-all {
+ then {
+ forwarding-class best-effort;
+ accept;
+ }
+ }
+ }
+}
+routing-instances {
+ DOH-DATA {
+ instance-type virtual-router;
+ interface ge-0/0/0.0;
+ interface t1-1/0/0.17;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.76.158;
+ }
+ }
+ }
+ DOH-PUBLIC {
+ instance-type virtual-router;
+ interface ge-0/0/1.0;
+ interface t1-1/0/0.18;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 172.23.0.165;
+ }
+ }
+ }
+}
+# grnoc-mon at DOH-STIGLER-SRX220> show ospf neighbor
+# OSPF instance is not running
+#
+# grnoc-mon at DOH-STIGLER-SRX220> show bfd session
+
+0 sessions, 0 clients
+Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
+
Index: configs/doh-cordell.client.onenet.net
===================================================================
--- configs/doh-cordell.client.onenet.net (revision 145060)
+++ configs/doh-cordell.client.onenet.net (working copy)
@@ -0,0 +1,718 @@
+# RANCID-CONTENT-TYPE: juniper
+#
+# grnoc-mon at DOH-CORDELL-SRX220> show system commit
+# 2016-07-27 18:25:21 CDT by andrew via cli commit confirmed, rollback in 5mins
+# 2014-11-07 15:47:20 CST by admin via netconf
+# 2014-09-03 21:25:30 CDT by root via other
+# 2014-09-02 20:53:22 CDT by andrew via cli
+# 2014-09-01 23:41:21 CDT by rnordmark via cli
+# 2014-09-01 12:40:32 CDT by rnordmark via cli
+# grnoc-mon at DOH-CORDELL-SRX220> show chassis environment
+# Class Item Status Measurement
+# Temp Routing Engine OK
+# Routing Engine CPU Absent
+# Fans SRX220 Chassis fan 0 OK
+# SRX220 Chassis fan 1 OK
+# Power Power Supply 0 OK
+#
+# grnoc-mon at DOH-CORDELL-SRX220> show chassis firmware
+# Part Type Version
+# FPC 0 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FPC 1 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FWDD O/S Version 12.1X46-D20.5 by builder on 2014-05
+#
+# grnoc-mon at DOH-CORDELL-SRX220> show chassis fpc detail
+# Slot 0 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+# Slot 1 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+#
+# grnoc-mon at DOH-CORDELL-SRX220> show chassis hardware
+# Hardware inventory:
+# Item Version Part number Serial number Description
+# Chassis AR3212AA0037 SRX220H-POE
+# Routing Engine REV 20 750-031177 AAEY4166 RE-SRX220H-POE
+# FPC 0 FPC
+# PIC 0 8x GE Base PIC
+# FPC 1 REV 07 750-023367 AAEZ1383 FPC
+# PIC 0 1x T1E1 mPIM
+# Power Supply 0
+#
+# grnoc-mon at DOH-CORDELL-SRX220> show chassis hardware models
+# grnoc-mon at DOH-CORDELL-SRX220> show chassis routing-engine
+# Routing Engine status:
+# Serial ID AAEY4166
+#
+# grnoc-mon at DOH-CORDELL-SRX220> show chassis scb
+# grnoc-mon at DOH-CORDELL-SRX220> show chassis sfm detail
+# grnoc-mon at DOH-CORDELL-SRX220> show chassis ssb
+# grnoc-mon at DOH-CORDELL-SRX220> show system boot-messages
+# kld_map_v: 0x8ff80000, kld_map_p: 0x0
+# Copyright (c) 1996-2014, Juniper Networks, Inc.
+# All rights reserved.
+# Copyright (c) 1992-2006 The FreeBSD Project.
+# Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
+# The Regents of the University of California. All rights reserved.
+# FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
+# Security policy loaded: JUNOS MAC/pcap (mac_pcap)
+# Security policy loaded: JUNOS MAC/runasnonroot (mac_runasnonroot)
+# netisr_init: !debug_mpsafenet, forcing maxthreads from 2 to 1
+# cpu0 on motherboard
+# : CAVIUM's OCTEON 5020 CPU Rev. 0.1 with no FPU implemented
+# L1 Cache: I size 32kb(128 line), D size 8kb(128 line), sixty four way.
+# L2 Cache: Size 128kb, 8 way
+# obio0 on motherboard
+# uart0: <Octeon-16550 channel 0> on obio0
+# uart0: console (9600,n,8,1)
+# twsi0 on obio0
+# dwc0: <Synopsis DWC OTG Controller Driver> on obio0
+# usb0: <USB Bus for DWC OTG Controller> on dwc0
+# usb0: USB revision 2.0
+# uhub0: vendor 0x0000 DWC OTG root hub, class 9/0, rev 2.00/1.00, addr 1
+# uhub0: 1 port with 1 removable, self powered
+# uhub1: vendor 0x0409 product 0x005a, class 9/0, rev 2.00/1.00, addr 2
+# uhub1: single transaction translator
+# uhub1: 3 ports with 2 removable, self powered
+# cpld0 on obio0
+# pcib0: <Cavium on-chip PCI bridge> on obio0
+# Disabling Octeon big bar support
+# PCI Status: PCI 32-bit: 0xc041b
+# pcib0: Initialized controller
+# pci0: <PCI bus> on pcib0
+# pci0: <simple comms> at device 1.0 (no driver attached)
+# atapci0: <SiI 0680 UDMA133 controller> port 0x8-0xb,0x10-0x17,0x18-0x1b,0x20-0x2f mem 0x8020000-0x80200ff irq 0 at device 2.0 on pci0
+# ata2: <ATA channel 0> on atapci0
+# ata3: <ATA channel 1> on atapci0
+# gblmem0 on obio0
+# octpkt0: <Octeon RGMII> on obio0
+# cfi0: <AMD/Fujitsu - 8MB> on obio0
+# Timecounter "mips" frequency 700000000 Hz quality 0
+# ###PCB Group initialized for udppcbgroup
+# ###PCB Group initialized for tcppcbgroup
+# ad0: Device does not support APM
+# ad0: 1006MB <CF 1GB 20080112> at ata2-master WDMA2
+# Trying to mount root from ufs:/dev/ad0s2a
+# WARNING: / was not properly dismounted
+# WARNING: / was not properly dismounted
+#
+# grnoc-mon at DOH-CORDELL-SRX220> show version
+# Hostname: DOH-CORDELL-SRX220 # Model: srx220h-poe # JUNOS Software Release [12.1X46-D20.5] # # grnoc-mon at DOH-CORDELL-SRX220> file list /var/tmp detail # lrw-r--r-- 1 root wheel 11 May 14 2014 /var/tmp@ -> /cf/var/tmp
+# total files: 1
+#
+# grnoc-mon at DOH-CORDELL-SRX220> show system uptime
+# System booted: 2016-07-27 18:27 CDT
+# Protocols started: 2016-07-27 18:29 CDT
+# Last configured: 2016-07-27 18:25 CDT by andrew
+#
+# grnoc-mon at DOH-CORDELL-SRX220> show interface terse
+#Interface Admin Link
+#ge-0/0/0 up up
+#ge-0/0/0.0 up up
+#gr-0/0/0 up up
+#ip-0/0/0 up up
+#lsq-0/0/0 up up
+#lt-0/0/0 up up
+#mt-0/0/0 up up
+#sp-0/0/0 up up
+#sp-0/0/0.0 up up
+#sp-0/0/0.16383 up up
+#ge-0/0/1 down down
+#ge-0/0/2 down down
+#ge-0/0/3 down down
+#ge-0/0/4 down down
+#ge-0/0/5 down down
+#ge-0/0/6 down down
+#ge-0/0/7 down down
+#t1-1/0/0 up up
+#t1-1/0/0.16 up up
+#t1-1/0/0.17 up up
+#fxp2 up up
+#fxp2.0 up up
+#gre up up
+#ipip up up
+#irb up up
+#lo0 up up
+#lo0.0 up up
+#lo0.16384 up up
+#lo0.16385 up up
+#lo0.32768 up up
+#lsi up up
+#mtun up up
+#pimd up up
+#pime up up
+#pp0 up up
+#ppd0 up up
+#ppe0 up up
+#st0 up up
+#tap up up
+#vlan up up
+# grnoc-mon at DOH-CORDELL-SRX220> show configuration
+## Last commit: 2016-07-27 18:25:21 CDT by andrew
+version 12.1X46-D20.5;
+system {
+ host-name DOH-CORDELL-SRX220;
+ domain-name onenet.net;
+ time-zone America/Chicago;
+ authentication-order [ password radius ];
+ ports {
+ console log-out-on-disconnect;
+ }
+ root-authentication {
+# encrypted-password <removed>;
+ }
+ name-server {
+ 10.119.255.3;
+ 10.119.255.4;
+ }
+ radius-server {
+ 10.119.255.7 {
+ port 1812;
+ accounting-port 1813;
+# secret "<removed>"; ## SECRET-DATA
+ source-address 10.119.78.245;
+ }
+ }
+ radius-options {
+ attributes {
+ nas-ip-address 10.119.78.245;
+ }
+ }
+ login {
+ message "\n+----------------------------------------------------------------------------+\n| |\n| Managed by Oklahoma State Regents for Higher Education |\n| Oklahoma Network for Education Enrichment (ONENET) |\n| |\n| *** Unauthorized Use or Access Prohibited *** |\n| |\n| For more information, contact: |\n| |\n| Oklahoma State Regents for Higher Education |\n| Educational Telecommunications Network -- ONENET |\n| (888) 566-3638 |\n| !
info at onenet.net |\n| |\n+----------------------------------------------------------------------------+\n";
+ class admin {
+ idle-timeout 30;
+ permissions all;
+ }
+ class lockdown {
+ idle-timeout 2;
+ permissions view;
+ deny-commands .*;
+ deny-configuration .*;
+ }
+ class operator-local {
+ idle-timeout 15;
+ permissions [ access admin configure firewall interface network routing snmp system trace view ];
+ allow-commands "show log messages";
+ }
+ class robot {
+ idle-timeout 10;
+ permissions [ admin configure firewall interface routing secret security snmp system trace view ];
+ }
+ user admin {
+ uid 1000;
+ class super-user;
+ authentication {
+# encrypted-password <removed>;
+ }
+ }
+ user client {
+ uid 2000;
+ class admin;
+ }
+ user eng {
+ uid 2018;
+ class admin;
+ }
+ user rancid {
+ uid 2001;
+ class robot;
+ }
+ user remote {
+ uid 2002;
+ class operator-local;
+ }
+ user upgrades {
+ uid 2003;
+ class operator;
+ authentication {
+# ssh-rsa <removed>;
+ }
+ }
+ }
+ services {
+ ssh {
+ root-login deny;
+ protocol-version v2;
+ }
+ }
+ syslog {
+ archive size 10m files 5;
+ user * {
+ any emergency;
+ }
+ file messages {
+ any critical;
+ authorization info;
+ }
+ file interactive-commands {
+ interactive-commands any;
+ }
+ file PROTECT-RE {
+ firewall any;
+ archive no-world-readable;
+ }
+ file updown {
+ any any;
+ match "SNMP_TRAP_LINK_|(TRAP_LINK)|bgp_rt_maxprefixes_check|RPD_BGP_NEIGHBOR_STATE";
+ }
+ }
+ max-configurations-on-flash 20;
+ max-configuration-rollbacks 20;
+ license {
+ autoupdate {
+ url https://ae1.juniper.net/junos/key_retrieval;
+ }
+ }
+ ntp {
+ server 10.119.255.5 prefer;
+ server 10.119.255.6;
+ }
+}
+interfaces {
+ ge-0/0/0 {
+ description DOH-DATA;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 172.23.18.65/26;
+ }
+ }
+ }
+ ge-0/0/1 {
+ disable;
+ }
+ ge-0/0/2 {
+ disable;
+ }
+ ge-0/0/3 {
+ disable;
+ }
+ ge-0/0/4 {
+ disable;
+ }
+ ge-0/0/5 {
+ disable;
+ }
+ ge-0/0/6 {
+ disable;
+ }
+ ge-0/0/7 {
+ disable;
+ }
+ t1-1/0/0 {
+ description "Link to OneNet";
+ per-unit-scheduler;
+ clocking external;
+ encapsulation frame-relay;
+ t1-options {
+ remote-loopback-respond;
+ }
+ unit 16 {
+ description "DATACOMM-MGMT to OneNet";
+ dlci 16;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.78.245/31;
+ }
+ }
+ unit 17 {
+ description "DOH-DATA to OneNet";
+ dlci 17;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.76.245/31;
+ }
+ }
+ }
+ t1-2/0/0 {
+ disable;
+ }
+ lo0 {
+ unit 0 {
+ family inet {
+ filter {
+ input PROTECT-RE;
+ }
+ }
+ }
+ }
+}
+snmp {
+ client-list snmp-management {
+ 10.119.255.0/24;
+ 204.61.5.128/27;
+ 0.0.0.0/0 {
+ restrict;
+ }
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+}
+routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.78.244;
+ }
+}
+protocols {
+ lldp {
+ interface all;
+ }
+ lldp-med {
+ interface all;
+ }
+}
+policy-options {
+ prefix-list PRE-MGMT-SOURCES {
+ 10.119.255.0/24;
+ 164.58.253.0/24;
+ }
+ prefix-list PRE-LOCALIPv4-SOURCES {
+ apply-path "interfaces <*> unit <*> family inet address <*>";
+ }
+ prefix-list PRE-SNMP-SOURCES {
+ 10.119.255.0/24;
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ 204.61.5.128/27;
+ }
+ prefix-list DOH-TIME-SEN-LOW-BW {
+ 172.23.32.70/32;
+ 172.23.32.72/32;
+ 172.23.32.73/32;
+ 172.23.48.10/32;
+ 172.23.48.49/32;
+ 172.23.48.210/32;
+ 172.23.49.158/32;
+ 172.23.49.160/32;
+ 172.23.49.167/32;
+ 172.23.49.208/32;
+ 204.87.86.20/32;
+ }
+ prefix-list TIME-SEN-TRANS {
+ 172.23.48.13/32;
+ 172.23.48.20/32;
+ 172.23.48.72/32;
+ 172.23.48.105/32;
+ 172.23.48.156/32;
+ 172.23.48.193/32;
+ 172.23.49.4/32;
+ 172.23.49.9/32;
+ 172.23.49.39/32;
+ 172.23.49.70/32;
+ 172.23.49.72/32;
+ }
+}
+class-of-service {
+ classifiers {
+ dscp dscp-default {
+ import default;
+ forwarding-class scavenger-service {
+ loss-priority high code-points ss;
+ }
+ }
+ }
+ code-point-aliases {
+ dscp {
+ ss 001000;
+ }
+ exp {
+ ss 001;
+ }
+ }
+ forwarding-classes {
+ queue 0 best-effort;
+ queue 1 assured-forwarding;
+ queue 2 expedited-forwarding;
+ queue 3 network-control;
+ queue 4 scavenger-service;
+ }
+ interfaces {
+ ge-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ t1-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ }
+ rewrite-rules {
+ exp exp-inet-table {
+ forwarding-class best-effort {
+ loss-priority low code-point 000;
+ loss-priority high code-point 001;
+ }
+ forwarding-class assured-forwarding {
+ loss-priority low code-point 010;
+ loss-priority high code-point 011;
+ }
+ forwarding-class expedited-forwarding {
+ loss-priority low code-point 111;
+ loss-priority high code-point 110;
+ }
+ forwarding-class network-control {
+ loss-priority low code-point 100;
+ loss-priority high code-point 101;
+ }
+ }
+ }
+ scheduler-maps {
+ t1-sch-map {
+ forwarding-class best-effort scheduler best-effort-sch;
+ forwarding-class expedited-forwarding scheduler t1-expedited-forwarding-sch;
+ forwarding-class network-control scheduler network-control-sch;
+ forwarding-class assured-forwarding scheduler t1-assured-forwarding-sch;
+ forwarding-class scavenger-service scheduler scavenger-service-sch;
+ }
+ }
+ schedulers {
+ best-effort-sch {
+ transmit-rate {
+ remainder;
+ }
+ buffer-size {
+ remainder;
+ }
+ priority low;
+ }
+ network-control-sch {
+ transmit-rate percent 5;
+ buffer-size percent 5;
+ priority high;
+ }
+ scavenger-service-sch {
+ transmit-rate percent 0;
+ buffer-size percent 0;
+ priority low;
+ }
+ t1-assured-forwarding-sch {
+ transmit-rate percent 45;
+ buffer-size percent 5;
+ priority high;
+ }
+ t1-expedited-forwarding-sch {
+ transmit-rate percent 35;
+ buffer-size percent 5;
+ priority high;
+ }
+ }
+}
+security {
+ policies {
+ from-zone DOH-DATA to-zone DOH-DATA {
+ policy DOH-DATA {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DATACOMM-MGMT to-zone DATACOMM-MGMT {
+ policy DATACOMM-MGMT {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ }
+ zones {
+ security-zone DOH-DATA {
+ interfaces {
+ t1-1/0/0.17 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/0.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DATACOMM-MGMT {
+ interfaces {
+ t1-1/0/0.16 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ }
+}
+firewall {
+ family inet {
+ filter PROTECT-RE {
+ term SSH-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-MGMT-SOURCES;
+ PRE-LOCALIPv4-SOURCES;
+ }
+ protocol tcp;
+ destination-port ssh;
+ }
+ then accept;
+ }
+ term SSH-DENY {
+ from {
+ protocol tcp;
+ destination-port ssh;
+ }
+ then {
+ discard;
+ }
+ }
+ term SNMP-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-SNMP-SOURCES;
+ }
+ protocol udp;
+ destination-port snmp;
+ }
+ then accept;
+ }
+ term SNMP-DENY {
+ from {
+ protocol udp;
+ destination-port snmp;
+ }
+ then {
+ discard;
+ }
+ }
+ term ALL-TRAFFIC {
+ then accept;
+ }
+ }
+ }
+ filter DOH-COS {
+ term expedited-forwarding {
+ from {
+ source-address {
+ 164.58.0.0/16;
+ 156.110.0.0/16;
+ }
+ }
+ then {
+ forwarding-class expedited-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-low {
+ from {
+ prefix-list {
+ DOH-TIME-SEN-LOW-BW;
+ }
+ destination-port [ 1433 80 139 445 9100 443 ];
+ }
+ then {
+ loss-priority low;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-high {
+ from {
+ prefix-list {
+ TIME-SEN-TRANS;
+ }
+ destination-port [ 80 135 139 445 1433 5088 5089 6087 ];
+ }
+ then {
+ loss-priority high;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term accept-all {
+ then {
+ forwarding-class best-effort;
+ accept;
+ }
+ }
+ }
+}
+routing-instances {
+ DOH-DATA {
+ instance-type virtual-router;
+ interface ge-0/0/0.0;
+ interface t1-1/0/0.17;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.76.244;
+ }
+ }
+ }
+}
+# grnoc-mon at DOH-CORDELL-SRX220> show ospf neighbor
+# OSPF instance is not running
+#
+# grnoc-mon at DOH-CORDELL-SRX220> show bfd session
+
+0 sessions, 0 clients
+Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
+
Index: configs/doh-stilwell.client.onenet.net
===================================================================
--- configs/doh-stilwell.client.onenet.net (revision 145065)
+++ configs/doh-stilwell.client.onenet.net (working copy)
@@ -0,0 +1,785 @@
+# RANCID-CONTENT-TYPE: juniper
+#
+# grnoc-mon at DOH-STILWELL-SRX220> show system commit
+# 2016-07-27 18:27:11 CDT by admin via cli commit confirmed, rollback in 5mins
+# 2014-11-07 15:47:06 CST by admin via netconf
+# 2014-09-03 21:12:02 CDT by root via other
+# 2014-09-02 21:54:29 CDT by andrew via cli
+# 2014-09-02 18:07:24 CDT by rnordmark via cli
+# 2014-09-01 23:33:37 CDT by rnordmark via cli
+# grnoc-mon at DOH-STILWELL-SRX220> show chassis environment
+# Class Item Status Measurement
+# Temp Routing Engine OK
+# Routing Engine CPU Absent
+# Fans SRX220 Chassis fan 0 OK
+# SRX220 Chassis fan 1 OK
+# Power Power Supply 0 OK
+#
+# grnoc-mon at DOH-STILWELL-SRX220> show chassis firmware
+# Part Type Version
+# FPC 0 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FPC 1 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FWDD O/S Version 12.1X46-D20.5 by builder on 2014-05
+#
+# grnoc-mon at DOH-STILWELL-SRX220> show chassis fpc detail
+# Slot 0 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+# Slot 1 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+#
+# grnoc-mon at DOH-STILWELL-SRX220> show chassis hardware
+# Hardware inventory:
+# Item Version Part number Serial number Description
+# Chassis AR4012AA0021 SRX220H-POE
+# Routing Engine REV 20 750-031177 AAFB0583 RE-SRX220H-POE
+# FPC 0 FPC
+# PIC 0 8x GE Base PIC
+# FPC 1 REV 07 750-023367 AAEW6648 FPC
+# PIC 0 1x T1E1 mPIM
+# Power Supply 0
+#
+# grnoc-mon at DOH-STILWELL-SRX220> show chassis hardware models
+# grnoc-mon at DOH-STILWELL-SRX220> show chassis routing-engine
+# Routing Engine status:
+# Serial ID AAFB0583
+#
+# grnoc-mon at DOH-STILWELL-SRX220> show chassis scb
+# grnoc-mon at DOH-STILWELL-SRX220> show chassis sfm detail
+# grnoc-mon at DOH-STILWELL-SRX220> show chassis ssb
+# grnoc-mon at DOH-STILWELL-SRX220> show system boot-messages
+# kld_map_v: 0x8ff80000, kld_map_p: 0x0
+# Copyright (c) 1996-2014, Juniper Networks, Inc.
+# All rights reserved.
+# Copyright (c) 1992-2006 The FreeBSD Project.
+# Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
+# The Regents of the University of California. All rights reserved.
+# FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
+# Security policy loaded: JUNOS MAC/pcap (mac_pcap)
+# Security policy loaded: JUNOS MAC/runasnonroot (mac_runasnonroot)
+# netisr_init: !debug_mpsafenet, forcing maxthreads from 2 to 1
+# cpu0 on motherboard
+# : CAVIUM's OCTEON 5020 CPU Rev. 0.1 with no FPU implemented
+# L1 Cache: I size 32kb(128 line), D size 8kb(128 line), sixty four way.
+# L2 Cache: Size 128kb, 8 way
+# obio0 on motherboard
+# uart0: <Octeon-16550 channel 0> on obio0
+# uart0: console (9600,n,8,1)
+# twsi0 on obio0
+# dwc0: <Synopsis DWC OTG Controller Driver> on obio0
+# usb0: <USB Bus for DWC OTG Controller> on dwc0
+# usb0: USB revision 2.0
+# uhub0: vendor 0x0000 DWC OTG root hub, class 9/0, rev 2.00/1.00, addr 1
+# uhub0: 1 port with 1 removable, self powered
+# uhub1: vendor 0x0409 product 0x005a, class 9/0, rev 2.00/1.00, addr 2
+# uhub1: single transaction translator
+# uhub1: 3 ports with 2 removable, self powered
+# cpld0 on obio0
+# pcib0: <Cavium on-chip PCI bridge> on obio0
+# Disabling Octeon big bar support
+# PCI Status: PCI 32-bit: 0xc041b
+# pcib0: Initialized controller
+# pci0: <PCI bus> on pcib0
+# pci0: <simple comms> at device 1.0 (no driver attached)
+# atapci0: <SiI 0680 UDMA133 controller> port 0x8-0xb,0x10-0x17,0x18-0x1b,0x20-0x2f mem 0x8020000-0x80200ff irq 0 at device 2.0 on pci0
+# ata2: <ATA channel 0> on atapci0
+# ata3: <ATA channel 1> on atapci0
+# gblmem0 on obio0
+# octpkt0: <Octeon RGMII> on obio0
+# cfi0: <AMD/Fujitsu - 8MB> on obio0
+# Timecounter "mips" frequency 700000000 Hz quality 0
+# ###PCB Group initialized for udppcbgroup
+# ###PCB Group initialized for tcppcbgroup
+# ad0: Device does not support APM
+# ad0: 1006MB <CF 1GB 20080112> at ata2-master WDMA2
+# Trying to mount root from ufs:/dev/ad0s1a
+# WARNING: / was not properly dismounted
+# WARNING: / was not properly dismounted
+#
+# grnoc-mon at DOH-STILWELL-SRX220> show version
+# Hostname: DOH-STILWELL-SRX220 # Model: srx220h-poe # JUNOS Software Release [12.1X46-D20.5] # # grnoc-mon at DOH-STILWELL-SRX220> file list /var/tmp detail # lrw-r--r-- 1 root wheel 11 May 14 2014 /var/tmp@ -> /cf/var/tmp
+# total files: 1
+#
+# grnoc-mon at DOH-STILWELL-SRX220> show system uptime
+# System booted: 2016-07-27 18:31 CDT
+# Protocols started: 2016-07-27 18:33 CDT
+# Last configured: 2016-07-27 18:27 CDT by admin
+#
+# grnoc-mon at DOH-STILWELL-SRX220> show interface terse
+#Interface Admin Link
+#ge-0/0/0 up up
+#ge-0/0/0.0 up up
+#gr-0/0/0 up up
+#ip-0/0/0 up up
+#lsq-0/0/0 up up
+#lt-0/0/0 up up
+#mt-0/0/0 up up
+#sp-0/0/0 up up
+#sp-0/0/0.0 up up
+#sp-0/0/0.16383 up up
+#ge-0/0/1 up up
+#ge-0/0/1.0 up up
+#ge-0/0/2 down down
+#ge-0/0/3 down down
+#ge-0/0/4 down down
+#ge-0/0/5 down down
+#ge-0/0/6 down down
+#ge-0/0/7 down down
+#t1-1/0/0 up up
+#t1-1/0/0.16 up up
+#t1-1/0/0.17 up up
+#t1-1/0/0.18 up up
+#fxp2 up up
+#fxp2.0 up up
+#gre up up
+#ipip up up
+#irb up up
+#lo0 up up
+#lo0.0 up up
+#lo0.16384 up up
+#lo0.16385 up up
+#lo0.32768 up up
+#lsi up up
+#mtun up up
+#pimd up up
+#pime up up
+#pp0 up up
+#ppd0 up up
+#ppe0 up up
+#st0 up up
+#tap up up
+#vlan up up
+# grnoc-mon at DOH-STILWELL-SRX220> show configuration
+## Last commit: 2016-07-27 18:27:11 CDT by admin
+version 12.1X46-D20.5;
+system {
+ host-name DOH-STILWELL-SRX220;
+ domain-name onenet.net;
+ time-zone America/Chicago;
+ authentication-order [ password radius ];
+ ports {
+ console log-out-on-disconnect;
+ }
+ root-authentication {
+# encrypted-password <removed>;
+ }
+ name-server {
+ 10.119.255.3;
+ 10.119.255.4;
+ }
+ radius-server {
+ 10.119.255.7 {
+ port 1812;
+ accounting-port 1813;
+# secret "<removed>"; ## SECRET-DATA
+ source-address 10.119.78.155;
+ }
+ }
+ radius-options {
+ attributes {
+ nas-ip-address 10.119.78.155;
+ }
+ }
+ login {
+ message "\n+----------------------------------------------------------------------------+\n| |\n| Managed by Oklahoma State Regents for Higher Education |\n| Oklahoma Network for Education Enrichment (ONENET) |\n| |\n| *** Unauthorized Use or Access Prohibited *** |\n| |\n| For more information, contact: |\n| |\n| Oklahoma State Regents for Higher Education |\n| Educational Telecommunications Network -- ONENET |\n| (888) 566-3638 |\n| !
info at onenet.net |\n| |\n+----------------------------------------------------------------------------+\n";
+ class admin {
+ idle-timeout 30;
+ permissions all;
+ }
+ class lockdown {
+ idle-timeout 2;
+ permissions view;
+ deny-commands .*;
+ deny-configuration .*;
+ }
+ class operator-local {
+ idle-timeout 15;
+ permissions [ access admin configure firewall interface network routing snmp system trace view ];
+ allow-commands "show log messages";
+ }
+ class robot {
+ idle-timeout 10;
+ permissions [ admin configure firewall interface routing secret security snmp system trace view ];
+ }
+ user admin {
+ uid 1000;
+ class super-user;
+ authentication {
+# encrypted-password <removed>;
+ }
+ }
+ user client {
+ uid 2000;
+ class admin;
+ }
+ user eng {
+ uid 2018;
+ class admin;
+ }
+ user rancid {
+ uid 2001;
+ class robot;
+ }
+ user remote {
+ uid 2002;
+ class operator-local;
+ }
+ user upgrades {
+ uid 2003;
+ class operator;
+ authentication {
+# ssh-rsa <removed>;
+ }
+ }
+ }
+ services {
+ ssh {
+ root-login deny;
+ protocol-version v2;
+ }
+ }
+ syslog {
+ archive size 10m files 5;
+ user * {
+ any emergency;
+ }
+ file messages {
+ any critical;
+ authorization info;
+ }
+ file interactive-commands {
+ interactive-commands any;
+ }
+ file PROTECT-RE {
+ firewall any;
+ archive no-world-readable;
+ }
+ file updown {
+ any any;
+ match "SNMP_TRAP_LINK_|(TRAP_LINK)|bgp_rt_maxprefixes_check|RPD_BGP_NEIGHBOR_STATE";
+ }
+ }
+ max-configurations-on-flash 20;
+ max-configuration-rollbacks 20;
+ license {
+ autoupdate {
+ url https://ae1.juniper.net/junos/key_retrieval;
+ }
+ }
+ ntp {
+ server 10.119.255.5 prefer;
+ server 10.119.255.6;
+ }
+}
+interfaces {
+ ge-0/0/0 {
+ description DOH-DATA;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 172.23.75.65/26;
+ }
+ }
+ }
+ ge-0/0/1 {
+ description DOH-PUBLIC;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 156.110.235.105/30;
+ }
+ }
+ }
+ ge-0/0/2 {
+ disable;
+ }
+ ge-0/0/3 {
+ disable;
+ }
+ ge-0/0/4 {
+ disable;
+ }
+ ge-0/0/5 {
+ disable;
+ }
+ ge-0/0/6 {
+ disable;
+ }
+ ge-0/0/7 {
+ disable;
+ }
+ t1-1/0/0 {
+ description "Link to OneNet";
+ per-unit-scheduler;
+ clocking external;
+ encapsulation frame-relay;
+ t1-options {
+ remote-loopback-respond;
+ }
+ unit 16 {
+ description "DATACOMM-MGMT to OneNet";
+ dlci 16;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.78.155/31;
+ }
+ }
+ unit 17 {
+ description "DOH-DATA to OneNet";
+ dlci 17;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.76.155/31;
+ }
+ }
+ unit 18 {
+ description "DOH-PUBLIC to OneNet";
+ dlci 18;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 172.23.2.182/30;
+ }
+ }
+ }
+ t1-2/0/0 {
+ disable;
+ }
+ lo0 {
+ unit 0 {
+ family inet {
+ filter {
+ input PROTECT-RE;
+ }
+ }
+ }
+ }
+}
+snmp {
+ client-list snmp-management {
+ 10.119.255.0/24;
+ 204.61.5.128/27;
+ 0.0.0.0/0 {
+ restrict;
+ }
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+}
+routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.78.154;
+ }
+}
+protocols {
+ lldp {
+ interface all;
+ }
+ lldp-med {
+ interface all;
+ }
+}
+policy-options {
+ prefix-list PRE-MGMT-SOURCES {
+ 10.119.255.0/24;
+ 164.58.253.0/24;
+ }
+ prefix-list PRE-LOCALIPv4-SOURCES {
+ apply-path "interfaces <*> unit <*> family inet address <*>";
+ }
+ prefix-list PRE-SNMP-SOURCES {
+ 10.119.255.0/24;
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ 204.61.5.128/27;
+ }
+ prefix-list DOH-TIME-SEN-LOW-BW {
+ 172.23.32.70/32;
+ 172.23.32.72/32;
+ 172.23.32.73/32;
+ 172.23.48.10/32;
+ 172.23.48.49/32;
+ 172.23.48.210/32;
+ 172.23.49.158/32;
+ 172.23.49.160/32;
+ 172.23.49.167/32;
+ 172.23.49.208/32;
+ 204.87.86.20/32;
+ }
+ prefix-list TIME-SEN-TRANS {
+ 172.23.48.13/32;
+ 172.23.48.20/32;
+ 172.23.48.72/32;
+ 172.23.48.105/32;
+ 172.23.48.156/32;
+ 172.23.48.193/32;
+ 172.23.49.4/32;
+ 172.23.49.9/32;
+ 172.23.49.39/32;
+ 172.23.49.70/32;
+ 172.23.49.72/32;
+ }
+}
+class-of-service {
+ classifiers {
+ dscp dscp-default {
+ import default;
+ forwarding-class scavenger-service {
+ loss-priority high code-points ss;
+ }
+ }
+ }
+ code-point-aliases {
+ dscp {
+ ss 001000;
+ }
+ exp {
+ ss 001;
+ }
+ }
+ forwarding-classes {
+ queue 0 best-effort;
+ queue 1 assured-forwarding;
+ queue 2 expedited-forwarding;
+ queue 3 network-control;
+ queue 4 scavenger-service;
+ }
+ interfaces {
+ ge-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ t1-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ }
+ rewrite-rules {
+ exp exp-inet-table {
+ forwarding-class best-effort {
+ loss-priority low code-point 000;
+ loss-priority high code-point 001;
+ }
+ forwarding-class assured-forwarding {
+ loss-priority low code-point 010;
+ loss-priority high code-point 011;
+ }
+ forwarding-class expedited-forwarding {
+ loss-priority low code-point 111;
+ loss-priority high code-point 110;
+ }
+ forwarding-class network-control {
+ loss-priority low code-point 100;
+ loss-priority high code-point 101;
+ }
+ }
+ }
+ scheduler-maps {
+ t1-sch-map {
+ forwarding-class best-effort scheduler best-effort-sch;
+ forwarding-class expedited-forwarding scheduler t1-expedited-forwarding-sch;
+ forwarding-class network-control scheduler network-control-sch;
+ forwarding-class assured-forwarding scheduler t1-assured-forwarding-sch;
+ forwarding-class scavenger-service scheduler scavenger-service-sch;
+ }
+ }
+ schedulers {
+ best-effort-sch {
+ transmit-rate {
+ remainder;
+ }
+ buffer-size {
+ remainder;
+ }
+ priority low;
+ }
+ network-control-sch {
+ transmit-rate percent 5;
+ buffer-size percent 5;
+ priority high;
+ }
+ scavenger-service-sch {
+ transmit-rate percent 0;
+ buffer-size percent 0;
+ priority low;
+ }
+ t1-assured-forwarding-sch {
+ transmit-rate percent 45;
+ buffer-size percent 5;
+ priority high;
+ }
+ t1-expedited-forwarding-sch {
+ transmit-rate percent 35;
+ buffer-size percent 5;
+ priority high;
+ }
+ }
+}
+security {
+ policies {
+ from-zone DOH-DATA to-zone DOH-DATA {
+ policy DOH-DATA {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DOH-PUBLIC to-zone DOH-PUBLIC {
+ policy DOH-PUBLIC {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DATACOMM-MGMT to-zone DATACOMM-MGMT {
+ policy DATACOMM-MGMT {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ }
+ zones {
+ security-zone DOH-DATA {
+ interfaces {
+ t1-1/0/0.17 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/0.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DOH-PUBLIC {
+ interfaces {
+ t1-1/0/0.18 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/1.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DATACOMM-MGMT {
+ interfaces {
+ t1-1/0/0.16 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ }
+}
+firewall {
+ family inet {
+ filter PROTECT-RE {
+ term SSH-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-MGMT-SOURCES;
+ PRE-LOCALIPv4-SOURCES;
+ }
+ protocol tcp;
+ destination-port ssh;
+ }
+ then accept;
+ }
+ term SSH-DENY {
+ from {
+ protocol tcp;
+ destination-port ssh;
+ }
+ then {
+ discard;
+ }
+ }
+ term SNMP-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-SNMP-SOURCES;
+ }
+ protocol udp;
+ destination-port snmp;
+ }
+ then accept;
+ }
+ term SNMP-DENY {
+ from {
+ protocol udp;
+ destination-port snmp;
+ }
+ then {
+ discard;
+ }
+ }
+ term ALL-TRAFFIC {
+ then accept;
+ }
+ }
+ }
+ filter DOH-COS {
+ term expedited-forwarding {
+ from {
+ source-address {
+ 164.58.0.0/16;
+ 156.110.0.0/16;
+ }
+ }
+ then {
+ forwarding-class expedited-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-low {
+ from {
+ prefix-list {
+ DOH-TIME-SEN-LOW-BW;
+ }
+ destination-port [ 1433 80 139 445 9100 443 ];
+ }
+ then {
+ loss-priority low;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-high {
+ from {
+ prefix-list {
+ TIME-SEN-TRANS;
+ }
+ destination-port [ 80 135 139 445 1433 5088 5089 6087 ];
+ }
+ then {
+ loss-priority high;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term accept-all {
+ then {
+ forwarding-class best-effort;
+ accept;
+ }
+ }
+ }
+}
+routing-instances {
+ DOH-DATA {
+ instance-type virtual-router;
+ interface ge-0/0/0.0;
+ interface t1-1/0/0.17;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.76.154;
+ }
+ }
+ }
+ DOH-PUBLIC {
+ instance-type virtual-router;
+ interface ge-0/0/1.0;
+ interface t1-1/0/0.18;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 172.23.2.181;
+ }
+ }
+ }
+}
+# grnoc-mon at DOH-STILWELL-SRX220> show ospf neighbor
+# OSPF instance is not running
+#
+# grnoc-mon at DOH-STILWELL-SRX220> show bfd session
+
+0 sessions, 0 clients
+Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
+
Index: configs/doh-watonga.client.onenet.net
===================================================================
--- configs/doh-watonga.client.onenet.net (revision 145067)
+++ configs/doh-watonga.client.onenet.net (working copy)
@@ -0,0 +1,785 @@
+# RANCID-CONTENT-TYPE: juniper
+#
+# grnoc-mon at DOH-WATONGA-SRX220> show system commit
+# 2016-07-27 18:46:56 CDT by admin via cli commit confirmed, rollback in 5mins
+# 2014-11-07 15:47:06 CST by admin via netconf
+# 2014-09-03 21:25:47 CDT by root via other
+# 2014-09-02 20:52:47 CDT by andrew via cli
+# 2014-09-01 23:38:53 CDT by rnordmark via cli
+# 2014-09-01 12:36:18 CDT by rnordmark via cli
+# grnoc-mon at DOH-WATONGA-SRX220> show chassis environment
+# Class Item Status Measurement
+# Temp Routing Engine OK
+# Routing Engine CPU Absent
+# Fans SRX220 Chassis fan 0 OK
+# SRX220 Chassis fan 1 OK
+# Power Power Supply 0 OK
+#
+# grnoc-mon at DOH-WATONGA-SRX220> show chassis firmware
+# Part Type Version
+# FPC 0 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FPC 1 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FWDD O/S Version 12.1X46-D20.5 by builder on 2014-05
+#
+# grnoc-mon at DOH-WATONGA-SRX220> show chassis fpc detail
+# Slot 0 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+# Slot 1 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+#
+# grnoc-mon at DOH-WATONGA-SRX220> show chassis hardware
+# Hardware inventory:
+# Item Version Part number Serial number Description
+# Chassis AR3212AA0051 SRX220H-POE
+# Routing Engine REV 20 750-031177 AAER0449 RE-SRX220H-POE
+# FPC 0 FPC
+# PIC 0 8x GE Base PIC
+# FPC 1 REV 07 750-023367 AAEY7044 FPC
+# PIC 0 1x T1E1 mPIM
+# Power Supply 0
+#
+# grnoc-mon at DOH-WATONGA-SRX220> show chassis hardware models
+# grnoc-mon at DOH-WATONGA-SRX220> show chassis routing-engine
+# Routing Engine status:
+# Serial ID AAER0449
+#
+# grnoc-mon at DOH-WATONGA-SRX220> show chassis scb
+# grnoc-mon at DOH-WATONGA-SRX220> show chassis sfm detail
+# grnoc-mon at DOH-WATONGA-SRX220> show chassis ssb
+# grnoc-mon at DOH-WATONGA-SRX220> show system boot-messages
+# kld_map_v: 0x8ff80000, kld_map_p: 0x0
+# Copyright (c) 1996-2014, Juniper Networks, Inc.
+# All rights reserved.
+# Copyright (c) 1992-2006 The FreeBSD Project.
+# Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
+# The Regents of the University of California. All rights reserved.
+# FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
+# Security policy loaded: JUNOS MAC/pcap (mac_pcap)
+# Security policy loaded: JUNOS MAC/runasnonroot (mac_runasnonroot)
+# netisr_init: !debug_mpsafenet, forcing maxthreads from 2 to 1
+# cpu0 on motherboard
+# : CAVIUM's OCTEON 5020 CPU Rev. 0.1 with no FPU implemented
+# L1 Cache: I size 32kb(128 line), D size 8kb(128 line), sixty four way.
+# L2 Cache: Size 128kb, 8 way
+# obio0 on motherboard
+# uart0: <Octeon-16550 channel 0> on obio0
+# uart0: console (9600,n,8,1)
+# twsi0 on obio0
+# dwc0: <Synopsis DWC OTG Controller Driver> on obio0
+# usb0: <USB Bus for DWC OTG Controller> on dwc0
+# usb0: USB revision 2.0
+# uhub0: vendor 0x0000 DWC OTG root hub, class 9/0, rev 2.00/1.00, addr 1
+# uhub0: 1 port with 1 removable, self powered
+# uhub1: vendor 0x0409 product 0x005a, class 9/0, rev 2.00/1.00, addr 2
+# uhub1: single transaction translator
+# uhub1: 3 ports with 2 removable, self powered
+# cpld0 on obio0
+# pcib0: <Cavium on-chip PCI bridge> on obio0
+# Disabling Octeon big bar support
+# PCI Status: PCI 32-bit: 0xc041b
+# pcib0: Initialized controller
+# pci0: <PCI bus> on pcib0
+# pci0: <simple comms> at device 1.0 (no driver attached)
+# atapci0: <SiI 0680 UDMA133 controller> port 0x8-0xb,0x10-0x17,0x18-0x1b,0x20-0x2f mem 0x8020000-0x80200ff irq 0 at device 2.0 on pci0
+# ata2: <ATA channel 0> on atapci0
+# ata3: <ATA channel 1> on atapci0
+# gblmem0 on obio0
+# octpkt0: <Octeon RGMII> on obio0
+# cfi0: <AMD/Fujitsu - 8MB> on obio0
+# Timecounter "mips" frequency 700000000 Hz quality 0
+# ###PCB Group initialized for udppcbgroup
+# ###PCB Group initialized for tcppcbgroup
+# ad0: Device does not support APM
+# ad0: 1006MB <CF 1GB 20080112> at ata2-master WDMA2
+# Trying to mount root from ufs:/dev/ad0s1a
+# WARNING: / was not properly dismounted
+# WARNING: / was not properly dismounted
+#
+# grnoc-mon at DOH-WATONGA-SRX220> show version
+# Hostname: DOH-WATONGA-SRX220 # Model: srx220h-poe # JUNOS Software Release [12.1X46-D20.5] # # grnoc-mon at DOH-WATONGA-SRX220> file list /var/tmp detail # lrw-r--r-- 1 root wheel 11 May 14 2014 /var/tmp@ -> /cf/var/tmp
+# total files: 1
+#
+# grnoc-mon at DOH-WATONGA-SRX220> show system uptime
+# System booted: 2016-07-27 18:53 CDT
+# Protocols started: 2016-07-27 18:54 CDT
+# Last configured: 2016-07-27 18:46 CDT by admin
+#
+# grnoc-mon at DOH-WATONGA-SRX220> show interface terse
+#Interface Admin Link
+#ge-0/0/0 up up
+#ge-0/0/0.0 up up
+#gr-0/0/0 up up
+#ip-0/0/0 up up
+#lsq-0/0/0 up up
+#lt-0/0/0 up up
+#mt-0/0/0 up up
+#sp-0/0/0 up up
+#sp-0/0/0.0 up up
+#sp-0/0/0.16383 up up
+#ge-0/0/1 up up
+#ge-0/0/1.0 up up
+#ge-0/0/2 down down
+#ge-0/0/3 down down
+#ge-0/0/4 down down
+#ge-0/0/5 down down
+#ge-0/0/6 down down
+#ge-0/0/7 down down
+#t1-1/0/0 up up
+#t1-1/0/0.16 up up
+#t1-1/0/0.17 up up
+#t1-1/0/0.18 up up
+#fxp2 up up
+#fxp2.0 up up
+#gre up up
+#ipip up up
+#irb up up
+#lo0 up up
+#lo0.0 up up
+#lo0.16384 up up
+#lo0.16385 up up
+#lo0.32768 up up
+#lsi up up
+#mtun up up
+#pimd up up
+#pime up up
+#pp0 up up
+#ppd0 up up
+#ppe0 up up
+#st0 up up
+#tap up up
+#vlan up up
+# grnoc-mon at DOH-WATONGA-SRX220> show configuration
+## Last commit: 2016-07-27 18:46:56 CDT by admin
+version 12.1X46-D20.5;
+system {
+ host-name DOH-WATONGA-SRX220;
+ domain-name onenet.net;
+ time-zone America/Chicago;
+ authentication-order [ password radius ];
+ ports {
+ console log-out-on-disconnect;
+ }
+ root-authentication {
+# encrypted-password <removed>;
+ }
+ name-server {
+ 10.119.255.3;
+ 10.119.255.4;
+ }
+ radius-server {
+ 10.119.255.7 {
+ port 1812;
+ accounting-port 1813;
+# secret "<removed>"; ## SECRET-DATA
+ source-address 10.119.78.211;
+ }
+ }
+ radius-options {
+ attributes {
+ nas-ip-address 10.119.78.211;
+ }
+ }
+ login {
+ message "\n+----------------------------------------------------------------------------+\n| |\n| Managed by Oklahoma State Regents for Higher Education |\n| Oklahoma Network for Education Enrichment (ONENET) |\n| |\n| *** Unauthorized Use or Access Prohibited *** |\n| |\n| For more information, contact: |\n| |\n| Oklahoma State Regents for Higher Education |\n| Educational Telecommunications Network -- ONENET |\n| (888) 566-3638 |\n| !
info at onenet.net |\n| |\n+----------------------------------------------------------------------------+\n";
+ class admin {
+ idle-timeout 30;
+ permissions all;
+ }
+ class lockdown {
+ idle-timeout 2;
+ permissions view;
+ deny-commands .*;
+ deny-configuration .*;
+ }
+ class operator-local {
+ idle-timeout 15;
+ permissions [ access admin configure firewall interface network routing snmp system trace view ];
+ allow-commands "show log messages";
+ }
+ class robot {
+ idle-timeout 10;
+ permissions [ admin configure firewall interface routing secret security snmp system trace view ];
+ }
+ user admin {
+ uid 1000;
+ class super-user;
+ authentication {
+# encrypted-password <removed>;
+ }
+ }
+ user client {
+ uid 2000;
+ class admin;
+ }
+ user eng {
+ uid 2018;
+ class admin;
+ }
+ user rancid {
+ uid 2001;
+ class robot;
+ }
+ user remote {
+ uid 2002;
+ class operator-local;
+ }
+ user upgrades {
+ uid 2003;
+ class operator;
+ authentication {
+# ssh-rsa <removed>;
+ }
+ }
+ }
+ services {
+ ssh {
+ root-login deny;
+ protocol-version v2;
+ }
+ }
+ syslog {
+ archive size 10m files 5;
+ user * {
+ any emergency;
+ }
+ file messages {
+ any critical;
+ authorization info;
+ }
+ file interactive-commands {
+ interactive-commands any;
+ }
+ file PROTECT-RE {
+ firewall any;
+ archive no-world-readable;
+ }
+ file updown {
+ any any;
+ match "SNMP_TRAP_LINK_|(TRAP_LINK)|bgp_rt_maxprefixes_check|RPD_BGP_NEIGHBOR_STATE";
+ }
+ }
+ max-configurations-on-flash 20;
+ max-configuration-rollbacks 20;
+ license {
+ autoupdate {
+ url https://ae1.juniper.net/junos/key_retrieval;
+ }
+ }
+ ntp {
+ server 10.119.255.5 prefer;
+ server 10.119.255.6;
+ }
+}
+interfaces {
+ ge-0/0/0 {
+ description DOH-DATA;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 172.23.112.129/26;
+ }
+ }
+ }
+ ge-0/0/1 {
+ description DOH-PUBLIC;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 156.110.66.109/30;
+ }
+ }
+ }
+ ge-0/0/2 {
+ disable;
+ }
+ ge-0/0/3 {
+ disable;
+ }
+ ge-0/0/4 {
+ disable;
+ }
+ ge-0/0/5 {
+ disable;
+ }
+ ge-0/0/6 {
+ disable;
+ }
+ ge-0/0/7 {
+ disable;
+ }
+ t1-1/0/0 {
+ description "Link to OneNet";
+ per-unit-scheduler;
+ clocking external;
+ encapsulation frame-relay;
+ t1-options {
+ remote-loopback-respond;
+ }
+ unit 16 {
+ description "DATACOMM-MGMT to OneNet";
+ dlci 16;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.78.211/31;
+ }
+ }
+ unit 17 {
+ description "DOH-DATA to OneNet";
+ dlci 17;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.76.211/31;
+ }
+ }
+ unit 18 {
+ description "DOH-PUBLIC to OneNet";
+ dlci 18;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 172.23.5.10/30;
+ }
+ }
+ }
+ t1-2/0/0 {
+ disable;
+ }
+ lo0 {
+ unit 0 {
+ family inet {
+ filter {
+ input PROTECT-RE;
+ }
+ }
+ }
+ }
+}
+snmp {
+ client-list snmp-management {
+ 10.119.255.0/24;
+ 204.61.5.128/27;
+ 0.0.0.0/0 {
+ restrict;
+ }
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+}
+routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.78.210;
+ }
+}
+protocols {
+ lldp {
+ interface all;
+ }
+ lldp-med {
+ interface all;
+ }
+}
+policy-options {
+ prefix-list PRE-MGMT-SOURCES {
+ 10.119.255.0/24;
+ 164.58.253.0/24;
+ }
+ prefix-list PRE-LOCALIPv4-SOURCES {
+ apply-path "interfaces <*> unit <*> family inet address <*>";
+ }
+ prefix-list PRE-SNMP-SOURCES {
+ 10.119.255.0/24;
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ 204.61.5.128/27;
+ }
+ prefix-list DOH-TIME-SEN-LOW-BW {
+ 172.23.32.70/32;
+ 172.23.32.72/32;
+ 172.23.32.73/32;
+ 172.23.48.10/32;
+ 172.23.48.49/32;
+ 172.23.48.210/32;
+ 172.23.49.158/32;
+ 172.23.49.160/32;
+ 172.23.49.167/32;
+ 172.23.49.208/32;
+ 204.87.86.20/32;
+ }
+ prefix-list TIME-SEN-TRANS {
+ 172.23.48.13/32;
+ 172.23.48.20/32;
+ 172.23.48.72/32;
+ 172.23.48.105/32;
+ 172.23.48.156/32;
+ 172.23.48.193/32;
+ 172.23.49.4/32;
+ 172.23.49.9/32;
+ 172.23.49.39/32;
+ 172.23.49.70/32;
+ 172.23.49.72/32;
+ }
+}
+class-of-service {
+ classifiers {
+ dscp dscp-default {
+ import default;
+ forwarding-class scavenger-service {
+ loss-priority high code-points ss;
+ }
+ }
+ }
+ code-point-aliases {
+ dscp {
+ ss 001000;
+ }
+ exp {
+ ss 001;
+ }
+ }
+ forwarding-classes {
+ queue 0 best-effort;
+ queue 1 assured-forwarding;
+ queue 2 expedited-forwarding;
+ queue 3 network-control;
+ queue 4 scavenger-service;
+ }
+ interfaces {
+ ge-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ t1-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ }
+ rewrite-rules {
+ exp exp-inet-table {
+ forwarding-class best-effort {
+ loss-priority low code-point 000;
+ loss-priority high code-point 001;
+ }
+ forwarding-class assured-forwarding {
+ loss-priority low code-point 010;
+ loss-priority high code-point 011;
+ }
+ forwarding-class expedited-forwarding {
+ loss-priority low code-point 111;
+ loss-priority high code-point 110;
+ }
+ forwarding-class network-control {
+ loss-priority low code-point 100;
+ loss-priority high code-point 101;
+ }
+ }
+ }
+ scheduler-maps {
+ t1-sch-map {
+ forwarding-class best-effort scheduler best-effort-sch;
+ forwarding-class expedited-forwarding scheduler t1-expedited-forwarding-sch;
+ forwarding-class network-control scheduler network-control-sch;
+ forwarding-class assured-forwarding scheduler t1-assured-forwarding-sch;
+ forwarding-class scavenger-service scheduler scavenger-service-sch;
+ }
+ }
+ schedulers {
+ best-effort-sch {
+ transmit-rate {
+ remainder;
+ }
+ buffer-size {
+ remainder;
+ }
+ priority low;
+ }
+ network-control-sch {
+ transmit-rate percent 5;
+ buffer-size percent 5;
+ priority high;
+ }
+ scavenger-service-sch {
+ transmit-rate percent 0;
+ buffer-size percent 0;
+ priority low;
+ }
+ t1-assured-forwarding-sch {
+ transmit-rate percent 45;
+ buffer-size percent 5;
+ priority high;
+ }
+ t1-expedited-forwarding-sch {
+ transmit-rate percent 35;
+ buffer-size percent 5;
+ priority high;
+ }
+ }
+}
+security {
+ policies {
+ from-zone DOH-DATA to-zone DOH-DATA {
+ policy DOH-DATA {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DOH-PUBLIC to-zone DOH-PUBLIC {
+ policy DOH-PUBLIC {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DATACOMM-MGMT to-zone DATACOMM-MGMT {
+ policy DATACOMM-MGMT {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ }
+ zones {
+ security-zone DOH-DATA {
+ interfaces {
+ t1-1/0/0.17 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/0.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DOH-PUBLIC {
+ interfaces {
+ t1-1/0/0.18 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/1.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DATACOMM-MGMT {
+ interfaces {
+ t1-1/0/0.16 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ }
+}
+firewall {
+ family inet {
+ filter PROTECT-RE {
+ term SSH-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-MGMT-SOURCES;
+ PRE-LOCALIPv4-SOURCES;
+ }
+ protocol tcp;
+ destination-port ssh;
+ }
+ then accept;
+ }
+ term SSH-DENY {
+ from {
+ protocol tcp;
+ destination-port ssh;
+ }
+ then {
+ discard;
+ }
+ }
+ term SNMP-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-SNMP-SOURCES;
+ }
+ protocol udp;
+ destination-port snmp;
+ }
+ then accept;
+ }
+ term SNMP-DENY {
+ from {
+ protocol udp;
+ destination-port snmp;
+ }
+ then {
+ discard;
+ }
+ }
+ term ALL-TRAFFIC {
+ then accept;
+ }
+ }
+ }
+ filter DOH-COS {
+ term expedited-forwarding {
+ from {
+ source-address {
+ 164.58.0.0/16;
+ 156.110.0.0/16;
+ }
+ }
+ then {
+ forwarding-class expedited-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-low {
+ from {
+ prefix-list {
+ DOH-TIME-SEN-LOW-BW;
+ }
+ destination-port [ 1433 80 139 445 9100 443 ];
+ }
+ then {
+ loss-priority low;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-high {
+ from {
+ prefix-list {
+ TIME-SEN-TRANS;
+ }
+ destination-port [ 80 135 139 445 1433 5088 5089 6087 ];
+ }
+ then {
+ loss-priority high;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term accept-all {
+ then {
+ forwarding-class best-effort;
+ accept;
+ }
+ }
+ }
+}
+routing-instances {
+ DOH-DATA {
+ instance-type virtual-router;
+ interface ge-0/0/0.0;
+ interface t1-1/0/0.17;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.76.210;
+ }
+ }
+ }
+ DOH-PUBLIC {
+ instance-type virtual-router;
+ interface ge-0/0/1.0;
+ interface t1-1/0/0.18;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 172.23.5.9;
+ }
+ }
+ }
+}
+# grnoc-mon at DOH-WATONGA-SRX220> show ospf neighbor
+# OSPF instance is not running
+#
+# grnoc-mon at DOH-WATONGA-SRX220> show bfd session
+
+0 sessions, 0 clients
+Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
+
Index: configs/doh-claremore.client.onenet.net
===================================================================
--- configs/doh-claremore.client.onenet.net (revision 144375)
+++ configs/doh-claremore.client.onenet.net (working copy)
@@ -137,7 +137,7 @@
#ge-0/0/6 down down
#ge-0/0/7 down down
#t1-1/0/0 down up
-#t1-2/0/0 down up
+#t1-2/0/0 down down
#fxp2 up up
#fxp2.0 up up
#gre up up
Index: configs/hub.wil.onenet.net
===================================================================
--- configs/hub.wil.onenet.net (revision 145057)
+++ configs/hub.wil.onenet.net (working copy)
@@ -1,12 +1,12 @@
# RANCID-CONTENT-TYPE: juniper
#
# grnoc-mon at WILBURTON-M120-RE0> show system commit
+# 2016-07-27 18:47:55 CDT by sean via cli commit synchronize
+# 2016-07-27 18:45:49 CDT by sean via cli commit synchronize
+# 2016-07-27 18:30:20 CDT by sean via cli commit synchronize
+# 2016-07-27 18:17:19 CDT by sean via cli commit synchronize
+# 2016-07-27 18:14:17 CDT by sean via cli commit synchronize
# 2016-07-27 15:26:44 CDT by sky via cli commit synchronize
-# 2016-07-20 18:45:26 CDT by andrew via cli commit synchronize
-# 2016-07-20 14:06:17 CDT by andrew via cli commit synchronize
-# 2016-07-13 14:37:57 CDT by aberrios via cli commit synchronize
-# 2016-07-06 12:17:25 CDT by andrew via cli commit synchronize
-# 2016-06-28 23:30:56 CDT by andrew via cli commit synchronize
# grnoc-mon at WILBURTON-M120-RE0> show chassis environment
# Class Item Status Measurement
# Temp PEM 0 OK
@@ -263,7 +263,7 @@
# grnoc-mon at WILBURTON-M120-RE0> show system uptime
# System booted: 2016-03-13 01:23 CST
# Protocols started: 2016-03-13 01:28 CST
-# Last configured: 2016-07-27 15:26 CDT by sky
+# Last configured: 2016-07-27 18:47 CDT by sean
#
# {master}
# grnoc-mon at WILBURTON-M120-RE0> show interface terse
@@ -285,7 +285,9 @@
#t1-2/0/2:5.0 up up
#t1-2/0/2:6 down down
#t1-2/0/2:7 up up
-#t1-2/0/2:7.0 up up
+#t1-2/0/2:7.16 up up
+#t1-2/0/2:7.17 up up
+#t1-2/0/2:7.18 up up
#t1-2/0/2:8 down down
#t1-2/0/2:9 up down
#t1-2/0/2:10 up down
@@ -324,7 +326,8 @@
#t1-2/0/3:8 down down
#t1-2/0/3:9 down down
#t1-2/0/3:10 up up
-#t1-2/0/3:10.0 up up
+#t1-2/0/3:10.16 up up
+#t1-2/0/3:10.17 up up
#t1-2/0/3:11 down down
#t1-2/0/3:12 down down
#t1-2/0/3:13 up up
@@ -412,7 +415,7 @@
#pp0 up up
#tap up up
# grnoc-mon at WILBURTON-M120-RE0> show configuration
-## Last commit: 2016-07-27 15:26:44 CDT by sky
+## Last commit: 2016-07-27 18:47:55 CDT by sean
version 13.3R8.7;
groups {
re0 {
@@ -755,24 +758,38 @@
disable;
}
t1-2/0/2:7 {
- description "DOH-WILBURTON-T1-CIR0000459-OCS [DECOM]";
- mtu 1518;
- encapsulation cisco-hdlc;
- unit 0 {
+ description "DOH-WILBURTON-T1-CIR0000459-OCS ";
+ dce;
+ encapsulation frame-relay;
+ unit 16 {
+ dlci 16;
family inet {
- mtu 1512;
sampling {
input;
+ output;
}
- address 172.23.0.193/30;
+ address 10.119.78.98/31;
}
- family mpls {
- filter {
- input FLOW-MPLS;
- output FLOW-MPLS;
+ }
+ unit 17 {
+ dlci 17;
+ family inet {
+ sampling {
+ input;
+ output;
}
+ address 10.119.76.98/31;
}
}
+ unit 18 {
+ dlci 18;
+ family inet {
+ sampling {
+ input;
+ }
+ address 172.23.0.193/30;
+ }
+ }
}
t1-2/0/2:8 {
disable;
@@ -933,22 +950,27 @@
disable;
}
t1-2/0/3:10 {
- description "DOH-Pushmataha-Clayton-T1-CIR0000971-OCS [DECOM]";
- mtu 1518;
- encapsulation cisco-hdlc;
- unit 0 {
+ description "DOH-Pushmataha-Clayton-T1-CIR0000971-OCS ";
+ dce;
+ encapsulation frame-relay;
+ unit 16 {
+ dlci 16;
family inet {
- mtu 1512;
sampling {
input;
+ output;
}
- address 172.23.0.201/30;
+ address 10.119.78.160/31;
}
- family mpls {
- filter {
- input FLOW-MPLS;
- output FLOW-MPLS;
+ }
+ unit 17 {
+ dlci 17;
+ family inet {
+ sampling {
+ input;
+ output;
}
+ address 10.119.76.160/31;
}
}
}
@@ -1189,6 +1211,7 @@
discard;
no-readvertise;
}
+ route 156.110.142.108/30 next-hop 172.23.0.194;
}
router-id 164.58.199.98;
autonomous-system 5078;
@@ -1198,7 +1221,6 @@
icmp-tunneling;
interface lo0.0;
interface ge-3/2/3.0;
- interface t1-2/0/2:7.0;
interface t1-2/0/3:10.0;
}
bgp {
@@ -1287,11 +1309,6 @@
}
summaries;
}
- interface t1-2/0/2:7.0 {
- authentication {
- md5 7# key <removed>;
- }
- }
interface t1-2/0/3:10.0 {
authentication {
md5 7# key <removed>;
@@ -1316,7 +1333,6 @@
ldp {
preference 255;
track-igp-metric;
- interface t1-2/0/2:7.0;
interface t1-2/0/3:10.0;
interface ge-3/2/3.0;
interface lo0.0;
@@ -2121,11 +2137,19 @@
DOH-L3VPN {
description DOH-L3VPN;
instance-type vrf;
+ interface t1-2/0/2:7.17;
+ interface t1-2/0/3:10.17;
route-distinguisher 164.58.199.98:3000;
vrf-import DOH-VRF-IMPORT;
vrf-export DOH-VRF-EXPORT;
vrf-target target:5078:3000;
vrf-table-label;
+ routing-options {
+ static {
+ route 172.23.28.0/26 next-hop 10.119.76.99;
+ route 172.23.28.128/26 next-hop 10.119.76.99;
+ }
+ }
}
ODMHSAS-L3VPN {
description ODMHSAS-L3VPN;
@@ -2207,7 +2231,9 @@
OMES-MGMT-L3VPN {
description OMES-MGMT-L3VPN;
instance-type vrf;
+ interface t1-2/0/2:7.16;
interface t1-2/0/2:15.16;
+ interface t1-2/0/3:10.16;
route-distinguisher 164.58.199.98:2550;
vrf-import OMES-MGMT-VRF-IMPORT;
vrf-export OMES-MGMT-VRF-EXPORT;
@@ -2248,8 +2274,6 @@
# grnoc-mon at WILBURTON-M120-RE0> show ospf neighbor
# Address Interface State ID Pri Dead
# 164.58.245.49 ge-3/2/3.0 Full 164.58.199.99
-# 172.23.0.194 t1-2/0/2:7.0 Full 10.199.2.57
-# 172.23.0.202 t1-2/0/3:10.0 Full 10.199.2.88
#
# {master}
# grnoc-mon at WILBURTON-M120-RE0> show bfd session
Index: configs/core3.tul-m120.onenet.net
===================================================================
--- configs/core3.tul-m120.onenet.net (revision 145072)
+++ configs/core3.tul-m120.onenet.net (working copy)
@@ -362,10 +362,10 @@
#sp-2/3/0 up up
#sp-2/3/0.16383 up up
#vt-2/3/0 up up
-#lsq-2/3/0:0 up down
-#lsq-2/3/0:0.16 up down
-#lsq-2/3/0:0.17 up down
-#lsq-2/3/0:0.30 up down
+#lsq-2/3/0:0 up up
+#lsq-2/3/0:0.16 up up
+#lsq-2/3/0:0.17 up up
+#lsq-2/3/0:0.30 up up
#lsq-2/3/0:1 up up
#lsq-2/3/0:1.16 up up
#lsq-2/3/0:1.17 up up
@@ -424,10 +424,10 @@
#t1-3/0/1:11.0 up up
#t1-3/0/1:12 up up
#t1-3/0/1:12.0 up up
-#t1-3/0/1:13 up down
-#t1-3/0/1:13.0 up down
-#t1-3/0/1:14 up down
-#t1-3/0/1:14.0 up down
+#t1-3/0/1:13 up up
+#t1-3/0/1:13.0 up up
+#t1-3/0/1:14 up up
+#t1-3/0/1:14.0 up up
#t1-3/0/1:15 down down
#t1-3/0/1:16 down down
#t1-3/0/1:17 down down
Index: configs/maysville-hs.client.onenet.net
===================================================================
--- configs/maysville-hs.client.onenet.net (revision 145071)
+++ configs/maysville-hs.client.onenet.net (working copy)
@@ -598,7 +598,6 @@
# OSPF instance is not running
#
# grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show bfd session
-quit
0 sessions, 0 clients
Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
Index: configs/rpswi1.okc.onenet.net
===================================================================
--- configs/rpswi1.okc.onenet.net (revision 145071)
+++ configs/rpswi1.okc.onenet.net (working copy)
@@ -261,8 +261,8 @@
#ge-0/0/42.0 up down
#ge-0/0/43 up up
#ge-0/0/43.0 up up
-#ge-0/0/44 up up
-#ge-0/0/44.0 up up
+#ge-0/0/44 up down
+#ge-0/0/44.0 up down
#ge-0/0/45 up down
#ge-0/0/45.0 up down
#ge-0/0/46 up down
Index: configs/doh-blackwell.client.onenet.net
===================================================================
--- configs/doh-blackwell.client.onenet.net (revision 145058)
+++ configs/doh-blackwell.client.onenet.net (working copy)
@@ -0,0 +1,718 @@
+# RANCID-CONTENT-TYPE: juniper
+#
+# grnoc-mon at DOH-BLACKWELL-SRX220> show system commit
+# 2016-07-27 18:42:32 CDT by andrew via cli commit confirmed, rollback in 5mins
+# 2014-09-03 21:45:18 CDT by root via other
+# 2014-09-02 22:13:10 CDT by andrew via cli
+# 2014-09-02 18:08:38 CDT by rnordmark via cli
+# 2014-09-01 23:40:24 CDT by rnordmark via cli
+# 2014-09-01 12:38:44 CDT by rnordmark via cli
+# grnoc-mon at DOH-BLACKWELL-SRX220> show chassis environment
+# Class Item Status Measurement
+# Temp Routing Engine OK
+# Routing Engine CPU Absent
+# Fans SRX220 Chassis fan 0 OK
+# SRX220 Chassis fan 1 OK
+# Power Power Supply 0 OK
+#
+# grnoc-mon at DOH-BLACKWELL-SRX220> show chassis firmware
+# Part Type Version
+# FPC 0 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FPC 1 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FWDD O/S Version 12.1X46-D20.5 by builder on 2014-05
+#
+# grnoc-mon at DOH-BLACKWELL-SRX220> show chassis fpc detail
+# Slot 0 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+# Slot 1 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+#
+# grnoc-mon at DOH-BLACKWELL-SRX220> show chassis hardware
+# Hardware inventory:
+# Item Version Part number Serial number Description
+# Chassis AR3212AA0028 SRX220H-POE
+# Routing Engine REV 20 750-031177 AAEY4163 RE-SRX220H-POE
+# FPC 0 FPC
+# PIC 0 8x GE Base PIC
+# FPC 1 REV 07 750-023367 AAEY8924 FPC
+# PIC 0 1x T1E1 mPIM
+# Power Supply 0
+#
+# grnoc-mon at DOH-BLACKWELL-SRX220> show chassis hardware models
+# grnoc-mon at DOH-BLACKWELL-SRX220> show chassis routing-engine
+# Routing Engine status:
+# Serial ID AAEY4163
+#
+# grnoc-mon at DOH-BLACKWELL-SRX220> show chassis scb
+# grnoc-mon at DOH-BLACKWELL-SRX220> show chassis sfm detail
+# grnoc-mon at DOH-BLACKWELL-SRX220> show chassis ssb
+# grnoc-mon at DOH-BLACKWELL-SRX220> show system boot-messages
+# kld_map_v: 0x8ff80000, kld_map_p: 0x0
+# Copyright (c) 1996-2014, Juniper Networks, Inc.
+# All rights reserved.
+# Copyright (c) 1992-2006 The FreeBSD Project.
+# Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
+# The Regents of the University of California. All rights reserved.
+# FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
+# Security policy loaded: JUNOS MAC/pcap (mac_pcap)
+# Security policy loaded: JUNOS MAC/runasnonroot (mac_runasnonroot)
+# netisr_init: !debug_mpsafenet, forcing maxthreads from 2 to 1
+# cpu0 on motherboard
+# : CAVIUM's OCTEON 5020 CPU Rev. 0.1 with no FPU implemented
+# L1 Cache: I size 32kb(128 line), D size 8kb(128 line), sixty four way.
+# L2 Cache: Size 128kb, 8 way
+# obio0 on motherboard
+# uart0: <Octeon-16550 channel 0> on obio0
+# uart0: console (9600,n,8,1)
+# twsi0 on obio0
+# dwc0: <Synopsis DWC OTG Controller Driver> on obio0
+# usb0: <USB Bus for DWC OTG Controller> on dwc0
+# usb0: USB revision 2.0
+# uhub0: vendor 0x0000 DWC OTG root hub, class 9/0, rev 2.00/1.00, addr 1
+# uhub0: 1 port with 1 removable, self powered
+# uhub1: vendor 0x0409 product 0x005a, class 9/0, rev 2.00/1.00, addr 2
+# uhub1: single transaction translator
+# uhub1: 3 ports with 2 removable, self powered
+# cpld0 on obio0
+# pcib0: <Cavium on-chip PCI bridge> on obio0
+# Disabling Octeon big bar support
+# PCI Status: PCI 32-bit: 0xc041b
+# pcib0: Initialized controller
+# pci0: <PCI bus> on pcib0
+# pci0: <simple comms> at device 1.0 (no driver attached)
+# atapci0: <SiI 0680 UDMA133 controller> port 0x8-0xb,0x10-0x17,0x18-0x1b,0x20-0x2f mem 0x8020000-0x80200ff irq 0 at device 2.0 on pci0
+# ata2: <ATA channel 0> on atapci0
+# ata3: <ATA channel 1> on atapci0
+# gblmem0 on obio0
+# octpkt0: <Octeon RGMII> on obio0
+# cfi0: <AMD/Fujitsu - 8MB> on obio0
+# Timecounter "mips" frequency 700000000 Hz quality 0
+# ###PCB Group initialized for udppcbgroup
+# ###PCB Group initialized for tcppcbgroup
+# ad0: Device does not support APM
+# ad0: 1006MB <CF 1GB 20080112> at ata2-master WDMA2
+# Trying to mount root from ufs:/dev/ad0s1a
+# WARNING: / was not properly dismounted
+# WARNING: / was not properly dismounted
+#
+# grnoc-mon at DOH-BLACKWELL-SRX220> show version
+# Hostname: DOH-BLACKWELL-SRX220 # Model: srx220h-poe # JUNOS Software Release [12.1X46-D20.5] # # grnoc-mon at DOH-BLACKWELL-SRX220> file list /var/tmp detail # lrw-r--r-- 1 root wheel 11 May 14 2014 /var/tmp@ -> /cf/var/tmp
+# total files: 1
+#
+# grnoc-mon at DOH-BLACKWELL-SRX220> show system uptime
+# System booted: 2016-07-27 18:48 CDT
+# Protocols started: 2016-07-27 18:50 CDT
+# Last configured: 2016-07-27 18:42 CDT by andrew
+#
+# grnoc-mon at DOH-BLACKWELL-SRX220> show interface terse
+#Interface Admin Link
+#ge-0/0/0 up up
+#ge-0/0/0.0 up up
+#gr-0/0/0 up up
+#ip-0/0/0 up up
+#lsq-0/0/0 up up
+#lt-0/0/0 up up
+#mt-0/0/0 up up
+#sp-0/0/0 up up
+#sp-0/0/0.0 up up
+#sp-0/0/0.16383 up up
+#ge-0/0/1 down down
+#ge-0/0/2 down down
+#ge-0/0/3 down down
+#ge-0/0/4 down down
+#ge-0/0/5 down down
+#ge-0/0/6 down down
+#ge-0/0/7 down down
+#t1-1/0/0 up up
+#t1-1/0/0.16 up up
+#t1-1/0/0.17 up up
+#fxp2 up up
+#fxp2.0 up up
+#gre up up
+#ipip up up
+#irb up up
+#lo0 up up
+#lo0.0 up up
+#lo0.16384 up up
+#lo0.16385 up up
+#lo0.32768 up up
+#lsi up up
+#mtun up up
+#pimd up up
+#pime up up
+#pp0 up up
+#ppd0 up up
+#ppe0 up up
+#st0 up up
+#tap up up
+#vlan up up
+# grnoc-mon at DOH-BLACKWELL-SRX220> show configuration
+## Last commit: 2016-07-27 18:42:32 CDT by andrew
+version 12.1X46-D20.5;
+system {
+ host-name DOH-BLACKWELL-SRX220;
+ domain-name onenet.net;
+ time-zone America/Chicago;
+ authentication-order [ password radius ];
+ ports {
+ console log-out-on-disconnect;
+ }
+ root-authentication {
+# encrypted-password <removed>;
+ }
+ name-server {
+ 10.119.255.3;
+ 10.119.255.4;
+ }
+ radius-server {
+ 10.119.255.7 {
+ port 1812;
+ accounting-port 1813;
+# secret "<removed>"; ## SECRET-DATA
+ source-address 10.119.78.231;
+ }
+ }
+ radius-options {
+ attributes {
+ nas-ip-address 10.119.78.231;
+ }
+ }
+ login {
+ message "\n+----------------------------------------------------------------------------+\n| |\n| Managed by Oklahoma State Regents for Higher Education |\n| Oklahoma Network for Education Enrichment (ONENET) |\n| |\n| *** Unauthorized Use or Access Prohibited *** |\n| |\n| For more information, contact: |\n| |\n| Oklahoma State Regents for Higher Education |\n| Educational Telecommunications Network -- ONENET |\n| (888) 566-3638 |\n| !
info at onenet.net |\n| |\n+----------------------------------------------------------------------------+\n";
+ class admin {
+ idle-timeout 30;
+ permissions all;
+ }
+ class lockdown {
+ idle-timeout 2;
+ permissions view;
+ deny-commands .*;
+ deny-configuration .*;
+ }
+ class operator-local {
+ idle-timeout 15;
+ permissions [ access admin configure firewall interface network routing snmp system trace view ];
+ allow-commands "show log messages";
+ }
+ class robot {
+ idle-timeout 10;
+ permissions [ admin configure firewall interface routing secret security snmp system trace view ];
+ }
+ user admin {
+ uid 1000;
+ class super-user;
+ authentication {
+# encrypted-password <removed>;
+ }
+ }
+ user client {
+ uid 2000;
+ class admin;
+ }
+ user eng {
+ uid 2018;
+ class admin;
+ }
+ user rancid {
+ uid 2001;
+ class robot;
+ }
+ user remote {
+ uid 2002;
+ class operator-local;
+ }
+ user upgrades {
+ uid 2003;
+ class operator;
+ authentication {
+# ssh-rsa <removed>;
+ }
+ }
+ }
+ services {
+ ssh {
+ root-login deny;
+ protocol-version v2;
+ }
+ }
+ syslog {
+ archive size 10m files 5;
+ user * {
+ any emergency;
+ }
+ file messages {
+ any critical;
+ authorization info;
+ }
+ file interactive-commands {
+ interactive-commands any;
+ }
+ file PROTECT-RE {
+ firewall any;
+ archive no-world-readable;
+ }
+ file updown {
+ any any;
+ match "SNMP_TRAP_LINK_|(TRAP_LINK)|bgp_rt_maxprefixes_check|RPD_BGP_NEIGHBOR_STATE";
+ }
+ }
+ max-configurations-on-flash 20;
+ max-configuration-rollbacks 20;
+ license {
+ autoupdate {
+ url https://ae1.juniper.net/junos/key_retrieval;
+ }
+ }
+ ntp {
+ server 10.119.255.5 prefer;
+ server 10.119.255.6;
+ }
+}
+interfaces {
+ ge-0/0/0 {
+ description DOH-DATA;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 172.23.19.1/26;
+ }
+ }
+ }
+ ge-0/0/1 {
+ disable;
+ }
+ ge-0/0/2 {
+ disable;
+ }
+ ge-0/0/3 {
+ disable;
+ }
+ ge-0/0/4 {
+ disable;
+ }
+ ge-0/0/5 {
+ disable;
+ }
+ ge-0/0/6 {
+ disable;
+ }
+ ge-0/0/7 {
+ disable;
+ }
+ t1-1/0/0 {
+ description "Link to OneNet";
+ per-unit-scheduler;
+ clocking external;
+ encapsulation frame-relay;
+ t1-options {
+ remote-loopback-respond;
+ }
+ unit 16 {
+ description "DATACOMM-MGMT to OneNet";
+ dlci 16;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.78.231/31;
+ }
+ }
+ unit 17 {
+ description "DOH-DATA to OneNet";
+ dlci 17;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.76.231/31;
+ }
+ }
+ }
+ t1-2/0/0 {
+ disable;
+ }
+ lo0 {
+ unit 0 {
+ family inet {
+ filter {
+ input PROTECT-RE;
+ }
+ }
+ }
+ }
+}
+snmp {
+ client-list snmp-management {
+ 10.119.255.0/24;
+ 204.61.5.128/27;
+ 0.0.0.0/0 {
+ restrict;
+ }
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+}
+routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.78.230;
+ }
+}
+protocols {
+ lldp {
+ interface all;
+ }
+ lldp-med {
+ interface all;
+ }
+}
+policy-options {
+ prefix-list PRE-MGMT-SOURCES {
+ 10.119.255.0/24;
+ 164.58.253.0/24;
+ }
+ prefix-list PRE-LOCALIPv4-SOURCES {
+ apply-path "interfaces <*> unit <*> family inet address <*>";
+ }
+ prefix-list PRE-SNMP-SOURCES {
+ 10.119.255.0/24;
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ 204.61.5.128/27;
+ }
+ prefix-list DOH-TIME-SEN-LOW-BW {
+ 172.23.32.70/32;
+ 172.23.32.72/32;
+ 172.23.32.73/32;
+ 172.23.48.10/32;
+ 172.23.48.49/32;
+ 172.23.48.210/32;
+ 172.23.49.158/32;
+ 172.23.49.160/32;
+ 172.23.49.167/32;
+ 172.23.49.208/32;
+ 204.87.86.20/32;
+ }
+ prefix-list TIME-SEN-TRANS {
+ 172.23.48.13/32;
+ 172.23.48.20/32;
+ 172.23.48.72/32;
+ 172.23.48.105/32;
+ 172.23.48.156/32;
+ 172.23.48.193/32;
+ 172.23.49.4/32;
+ 172.23.49.9/32;
+ 172.23.49.39/32;
+ 172.23.49.70/32;
+ 172.23.49.72/32;
+ }
+}
+class-of-service {
+ classifiers {
+ dscp dscp-default {
+ import default;
+ forwarding-class scavenger-service {
+ loss-priority high code-points ss;
+ }
+ }
+ }
+ code-point-aliases {
+ dscp {
+ ss 001000;
+ }
+ exp {
+ ss 001;
+ }
+ }
+ forwarding-classes {
+ queue 0 best-effort;
+ queue 1 assured-forwarding;
+ queue 2 expedited-forwarding;
+ queue 3 network-control;
+ queue 4 scavenger-service;
+ }
+ interfaces {
+ ge-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ t1-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ }
+ rewrite-rules {
+ exp exp-inet-table {
+ forwarding-class best-effort {
+ loss-priority low code-point 000;
+ loss-priority high code-point 001;
+ }
+ forwarding-class assured-forwarding {
+ loss-priority low code-point 010;
+ loss-priority high code-point 011;
+ }
+ forwarding-class expedited-forwarding {
+ loss-priority low code-point 111;
+ loss-priority high code-point 110;
+ }
+ forwarding-class network-control {
+ loss-priority low code-point 100;
+ loss-priority high code-point 101;
+ }
+ }
+ }
+ scheduler-maps {
+ t1-sch-map {
+ forwarding-class best-effort scheduler best-effort-sch;
+ forwarding-class expedited-forwarding scheduler t1-expedited-forwarding-sch;
+ forwarding-class network-control scheduler network-control-sch;
+ forwarding-class assured-forwarding scheduler t1-assured-forwarding-sch;
+ forwarding-class scavenger-service scheduler scavenger-service-sch;
+ }
+ }
+ schedulers {
+ best-effort-sch {
+ transmit-rate {
+ remainder;
+ }
+ buffer-size {
+ remainder;
+ }
+ priority low;
+ }
+ network-control-sch {
+ transmit-rate percent 5;
+ buffer-size percent 5;
+ priority high;
+ }
+ scavenger-service-sch {
+ transmit-rate percent 0;
+ buffer-size percent 0;
+ priority low;
+ }
+ t1-assured-forwarding-sch {
+ transmit-rate percent 45;
+ buffer-size percent 5;
+ priority high;
+ }
+ t1-expedited-forwarding-sch {
+ transmit-rate percent 35;
+ buffer-size percent 5;
+ priority high;
+ }
+ }
+}
+security {
+ policies {
+ from-zone DOH-DATA to-zone DOH-DATA {
+ policy DOH-DATA {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DATACOMM-MGMT to-zone DATACOMM-MGMT {
+ policy DATACOMM-MGMT {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ }
+ zones {
+ security-zone DOH-DATA {
+ interfaces {
+ t1-1/0/0.17 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/0.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DATACOMM-MGMT {
+ interfaces {
+ t1-1/0/0.16 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ }
+}
+firewall {
+ family inet {
+ filter PROTECT-RE {
+ term SSH-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-MGMT-SOURCES;
+ PRE-LOCALIPv4-SOURCES;
+ }
+ protocol tcp;
+ destination-port ssh;
+ }
+ then accept;
+ }
+ term SSH-DENY {
+ from {
+ protocol tcp;
+ destination-port ssh;
+ }
+ then {
+ discard;
+ }
+ }
+ term SNMP-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-SNMP-SOURCES;
+ }
+ protocol udp;
+ destination-port snmp;
+ }
+ then accept;
+ }
+ term SNMP-DENY {
+ from {
+ protocol udp;
+ destination-port snmp;
+ }
+ then {
+ discard;
+ }
+ }
+ term ALL-TRAFFIC {
+ then accept;
+ }
+ }
+ }
+ filter DOH-COS {
+ term expedited-forwarding {
+ from {
+ source-address {
+ 164.58.0.0/16;
+ 156.110.0.0/16;
+ }
+ }
+ then {
+ forwarding-class expedited-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-low {
+ from {
+ prefix-list {
+ DOH-TIME-SEN-LOW-BW;
+ }
+ destination-port [ 1433 80 139 445 9100 443 ];
+ }
+ then {
+ loss-priority low;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-high {
+ from {
+ prefix-list {
+ TIME-SEN-TRANS;
+ }
+ destination-port [ 80 135 139 445 1433 5088 5089 6087 ];
+ }
+ then {
+ loss-priority high;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term accept-all {
+ then {
+ forwarding-class best-effort;
+ accept;
+ }
+ }
+ }
+}
+routing-instances {
+ DOH-DATA {
+ instance-type virtual-router;
+ interface ge-0/0/0.0;
+ interface t1-1/0/0.17;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.76.230;
+ }
+ }
+ }
+}
+# grnoc-mon at DOH-BLACKWELL-SRX220> show ospf neighbor
+# OSPF instance is not running
+#
+# grnoc-mon at DOH-BLACKWELL-SRX220> show bfd session
+
+0 sessions, 0 clients
+Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
+
Index: configs/doh-clayton.client.onenet.net
===================================================================
--- configs/doh-clayton.client.onenet.net (revision 145059)
+++ configs/doh-clayton.client.onenet.net (working copy)
@@ -0,0 +1,718 @@
+# RANCID-CONTENT-TYPE: juniper
+#
+# grnoc-mon at DOH-CLAYTON-SRX220> show system commit
+# 2016-07-27 18:32:09 CDT by admin via cli commit confirmed, rollback in 10mins
+# 2016-07-27 18:28:17 CDT by admin via cli commit confirmed, rollback in 5mins
+# 2014-11-07 15:47:07 CST by admin via netconf
+# 2014-09-04 23:16:00 CDT by root via other
+# 2014-09-02 21:21:55 CDT by andrew via cli
+# 2014-09-01 23:34:02 CDT by rnordmark via cli
+# grnoc-mon at DOH-CLAYTON-SRX220> show chassis environment
+# Class Item Status Measurement
+# Temp Routing Engine OK
+# Routing Engine CPU Absent
+# Fans SRX220 Chassis fan 0 OK
+# SRX220 Chassis fan 1 OK
+# Power Power Supply 0 OK
+#
+# grnoc-mon at DOH-CLAYTON-SRX220> show chassis firmware
+# Part Type Version
+# FPC 0 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FPC 1 O/S Version 12.1X46-D20.5 by builder on 2014-05
+# FWDD O/S Version 12.1X46-D20.5 by builder on 2014-05
+#
+# grnoc-mon at DOH-CLAYTON-SRX220> show chassis fpc detail
+# Slot 0 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+# Slot 1 information:
+# State Online
+# Total CPU DRAM ---- CPU less FPC ----
+#
+# grnoc-mon at DOH-CLAYTON-SRX220> show chassis hardware
+# Hardware inventory:
+# Item Version Part number Serial number Description
+# Chassis AR3612AA0058 SRX220H-POE
+# Routing Engine REV 20 750-031177 AAFA6700 RE-SRX220H-POE
+# FPC 0 FPC
+# PIC 0 8x GE Base PIC
+# FPC 1 REV 07 750-023367 AAEY8929 FPC
+# PIC 0 1x T1E1 mPIM
+# Power Supply 0
+#
+# grnoc-mon at DOH-CLAYTON-SRX220> show chassis hardware models
+# grnoc-mon at DOH-CLAYTON-SRX220> show chassis routing-engine
+# Routing Engine status:
+# Serial ID AAFA6700
+#
+# grnoc-mon at DOH-CLAYTON-SRX220> show chassis scb
+# grnoc-mon at DOH-CLAYTON-SRX220> show chassis sfm detail
+# grnoc-mon at DOH-CLAYTON-SRX220> show chassis ssb
+# grnoc-mon at DOH-CLAYTON-SRX220> show system boot-messages
+# kld_map_v: 0x8ff80000, kld_map_p: 0x0
+# Copyright (c) 1996-2014, Juniper Networks, Inc.
+# All rights reserved.
+# Copyright (c) 1992-2006 The FreeBSD Project.
+# Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
+# The Regents of the University of California. All rights reserved.
+# FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
+# Security policy loaded: JUNOS MAC/pcap (mac_pcap)
+# Security policy loaded: JUNOS MAC/runasnonroot (mac_runasnonroot)
+# netisr_init: !debug_mpsafenet, forcing maxthreads from 2 to 1
+# cpu0 on motherboard
+# : CAVIUM's OCTEON 5020 CPU Rev. 0.1 with no FPU implemented
+# L1 Cache: I size 32kb(128 line), D size 8kb(128 line), sixty four way.
+# L2 Cache: Size 128kb, 8 way
+# obio0 on motherboard
+# uart0: <Octeon-16550 channel 0> on obio0
+# uart0: console (9600,n,8,1)
+# twsi0 on obio0
+# dwc0: <Synopsis DWC OTG Controller Driver> on obio0
+# usb0: <USB Bus for DWC OTG Controller> on dwc0
+# usb0: USB revision 2.0
+# uhub0: vendor 0x0000 DWC OTG root hub, class 9/0, rev 2.00/1.00, addr 1
+# uhub0: 1 port with 1 removable, self powered
+# uhub1: vendor 0x0409 product 0x005a, class 9/0, rev 2.00/1.00, addr 2
+# uhub1: single transaction translator
+# uhub1: 3 ports with 2 removable, self powered
+# cpld0 on obio0
+# pcib0: <Cavium on-chip PCI bridge> on obio0
+# Disabling Octeon big bar support
+# PCI Status: PCI 32-bit: 0xc041b
+# pcib0: Initialized controller
+# pci0: <PCI bus> on pcib0
+# pci0: <simple comms> at device 1.0 (no driver attached)
+# atapci0: <SiI 0680 UDMA133 controller> port 0x8-0xb,0x10-0x17,0x18-0x1b,0x20-0x2f mem 0x8020000-0x80200ff irq 0 at device 2.0 on pci0
+# ata2: <ATA channel 0> on atapci0
+# ata3: <ATA channel 1> on atapci0
+# gblmem0 on obio0
+# octpkt0: <Octeon RGMII> on obio0
+# cfi0: <AMD/Fujitsu - 8MB> on obio0
+# Timecounter "mips" frequency 700000000 Hz quality 0
+# ###PCB Group initialized for udppcbgroup
+# ###PCB Group initialized for tcppcbgroup
+# ad0: Device does not support APM
+# ad0: 1006MB <CF 1GB 20080112> at ata2-master WDMA2
+# Trying to mount root from ufs:/dev/ad0s1a
+# WARNING: / was not properly dismounted
+# WARNING: / was not properly dismounted
+#
+# grnoc-mon at DOH-CLAYTON-SRX220> show version
+# Hostname: DOH-CLAYTON-SRX220 # Model: srx220h-poe # JUNOS Software Release [12.1X46-D20.5] # # grnoc-mon at DOH-CLAYTON-SRX220> file list /var/tmp detail # lrw-r--r-- 1 root wheel 11 May 14 2014 /var/tmp@ -> /cf/var/tmp
+# total files: 1
+#
+# grnoc-mon at DOH-CLAYTON-SRX220> show system uptime
+# System booted: 2016-07-27 18:37 CDT
+# Protocols started: 2016-07-27 18:39 CDT
+# Last configured: 2016-07-27 18:32 CDT by admin
+#
+# grnoc-mon at DOH-CLAYTON-SRX220> show interface terse
+#Interface Admin Link
+#ge-0/0/0 up up
+#ge-0/0/0.0 up up
+#gr-0/0/0 up up
+#ip-0/0/0 up up
+#lsq-0/0/0 up up
+#lt-0/0/0 up up
+#mt-0/0/0 up up
+#sp-0/0/0 up up
+#sp-0/0/0.0 up up
+#sp-0/0/0.16383 up up
+#ge-0/0/1 down down
+#ge-0/0/2 down down
+#ge-0/0/3 down down
+#ge-0/0/4 down down
+#ge-0/0/5 down down
+#ge-0/0/6 down down
+#ge-0/0/7 down down
+#t1-1/0/0 up up
+#t1-1/0/0.16 up up
+#t1-1/0/0.17 up up
+#fxp2 up up
+#fxp2.0 up up
+#gre up up
+#ipip up up
+#irb up up
+#lo0 up up
+#lo0.0 up up
+#lo0.16384 up up
+#lo0.16385 up up
+#lo0.32768 up up
+#lsi up up
+#mtun up up
+#pimd up up
+#pime up up
+#pp0 up up
+#ppd0 up up
+#ppe0 up up
+#st0 up up
+#tap up up
+#vlan up up
+# grnoc-mon at DOH-CLAYTON-SRX220> show configuration
+## Last commit: 2016-07-27 18:32:09 CDT by admin
+version 12.1X46-D20.5;
+system {
+ host-name DOH-CLAYTON-SRX220;
+ domain-name onenet.net;
+ time-zone America/Chicago;
+ authentication-order [ password radius ];
+ ports {
+ console log-out-on-disconnect;
+ }
+ root-authentication {
+# encrypted-password <removed>;
+ }
+ name-server {
+ 10.119.255.3;
+ 10.119.255.4;
+ }
+ radius-server {
+ 10.119.255.7 {
+ port 1812;
+ accounting-port 1813;
+# secret "<removed>"; ## SECRET-DATA
+ source-address 10.119.78.161;
+ }
+ }
+ radius-options {
+ attributes {
+ nas-ip-address 10.119.78.161;
+ }
+ }
+ login {
+ message "\n+----------------------------------------------------------------------------+\n| |\n| Managed by Oklahoma State Regents for Higher Education |\n| Oklahoma Network for Education Enrichment (ONENET) |\n| |\n| *** Unauthorized Use or Access Prohibited *** |\n| |\n| For more information, contact: |\n| |\n| Oklahoma State Regents for Higher Education |\n| Educational Telecommunications Network -- ONENET |\n| (888) 566-3638 |\n| !
info at onenet.net |\n| |\n+----------------------------------------------------------------------------+\n";
+ class admin {
+ idle-timeout 30;
+ permissions all;
+ }
+ class lockdown {
+ idle-timeout 2;
+ permissions view;
+ deny-commands .*;
+ deny-configuration .*;
+ }
+ class operator-local {
+ idle-timeout 15;
+ permissions [ access admin configure firewall interface network routing snmp system trace view ];
+ allow-commands "show log messages";
+ }
+ class robot {
+ idle-timeout 10;
+ permissions [ admin configure firewall interface routing secret security snmp system trace view ];
+ }
+ user admin {
+ uid 1000;
+ class super-user;
+ authentication {
+# encrypted-password <removed>;
+ }
+ }
+ user client {
+ uid 2000;
+ class admin;
+ }
+ user eng {
+ uid 2018;
+ class admin;
+ }
+ user rancid {
+ uid 2001;
+ class robot;
+ }
+ user remote {
+ uid 2002;
+ class operator-local;
+ }
+ user upgrades {
+ uid 2003;
+ class operator;
+ authentication {
+# ssh-rsa <removed>;
+ }
+ }
+ }
+ services {
+ ssh {
+ root-login deny;
+ protocol-version v2;
+ }
+ }
+ syslog {
+ archive size 10m files 5;
+ user * {
+ any emergency;
+ }
+ file messages {
+ any critical;
+ authorization info;
+ }
+ file interactive-commands {
+ interactive-commands any;
+ }
+ file PROTECT-RE {
+ firewall any;
+ archive no-world-readable;
+ }
+ file updown {
+ any any;
+ match "SNMP_TRAP_LINK_|(TRAP_LINK)|bgp_rt_maxprefixes_check|RPD_BGP_NEIGHBOR_STATE";
+ }
+ }
+ max-configurations-on-flash 20;
+ max-configuration-rollbacks 20;
+ license {
+ autoupdate {
+ url https://ae1.juniper.net/junos/key_retrieval;
+ }
+ }
+ ntp {
+ server 10.119.255.5 prefer;
+ server 10.119.255.6;
+ }
+}
+interfaces {
+ ge-0/0/0 {
+ description DOH-DATA;
+ speed 100m;
+ link-mode full-duplex;
+ unit 0 {
+ family inet {
+ filter {
+ input DOH-COS;
+ }
+ address 172.23.28.129/26;
+ }
+ }
+ }
+ ge-0/0/1 {
+ disable;
+ }
+ ge-0/0/2 {
+ disable;
+ }
+ ge-0/0/3 {
+ disable;
+ }
+ ge-0/0/4 {
+ disable;
+ }
+ ge-0/0/5 {
+ disable;
+ }
+ ge-0/0/6 {
+ disable;
+ }
+ ge-0/0/7 {
+ disable;
+ }
+ t1-1/0/0 {
+ description "Link to OneNet";
+ per-unit-scheduler;
+ clocking external;
+ encapsulation frame-relay;
+ t1-options {
+ remote-loopback-respond;
+ }
+ unit 16 {
+ description "DATACOMM-MGMT to OneNet";
+ dlci 16;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.78.161/31;
+ }
+ }
+ unit 17 {
+ description "DOH-DATA to OneNet";
+ dlci 17;
+ family inet {
+ filter {
+ output DOH-COS;
+ }
+ address 10.119.76.161/31;
+ }
+ }
+ }
+ t1-2/0/0 {
+ disable;
+ }
+ lo0 {
+ unit 0 {
+ family inet {
+ filter {
+ input PROTECT-RE;
+ }
+ }
+ }
+ }
+}
+snmp {
+ client-list snmp-management {
+ 10.119.255.0/24;
+ 204.61.5.128/27;
+ 0.0.0.0/0 {
+ restrict;
+ }
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+ community "<removed>" {
+ authorization read-only;
+ }
+ community "<removed>" {
+ authorization read-write;
+ }
+}
+routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.78.160;
+ }
+}
+protocols {
+ lldp {
+ interface all;
+ }
+ lldp-med {
+ interface all;
+ }
+}
+policy-options {
+ prefix-list PRE-MGMT-SOURCES {
+ 10.119.255.0/24;
+ 164.58.253.0/24;
+ }
+ prefix-list PRE-LOCALIPv4-SOURCES {
+ apply-path "interfaces <*> unit <*> family inet address <*>";
+ }
+ prefix-list PRE-SNMP-SOURCES {
+ 10.119.255.0/24;
+ 156.110.31.0/27;
+ 156.110.31.32/28;
+ 164.58.253.0/24;
+ 204.61.5.128/27;
+ }
+ prefix-list DOH-TIME-SEN-LOW-BW {
+ 172.23.32.70/32;
+ 172.23.32.72/32;
+ 172.23.32.73/32;
+ 172.23.48.10/32;
+ 172.23.48.49/32;
+ 172.23.48.210/32;
+ 172.23.49.158/32;
+ 172.23.49.160/32;
+ 172.23.49.167/32;
+ 172.23.49.208/32;
+ 204.87.86.20/32;
+ }
+ prefix-list TIME-SEN-TRANS {
+ 172.23.48.13/32;
+ 172.23.48.20/32;
+ 172.23.48.72/32;
+ 172.23.48.105/32;
+ 172.23.48.156/32;
+ 172.23.48.193/32;
+ 172.23.49.4/32;
+ 172.23.49.9/32;
+ 172.23.49.39/32;
+ 172.23.49.70/32;
+ 172.23.49.72/32;
+ }
+}
+class-of-service {
+ classifiers {
+ dscp dscp-default {
+ import default;
+ forwarding-class scavenger-service {
+ loss-priority high code-points ss;
+ }
+ }
+ }
+ code-point-aliases {
+ dscp {
+ ss 001000;
+ }
+ exp {
+ ss 001;
+ }
+ }
+ forwarding-classes {
+ queue 0 best-effort;
+ queue 1 assured-forwarding;
+ queue 2 expedited-forwarding;
+ queue 3 network-control;
+ queue 4 scavenger-service;
+ }
+ interfaces {
+ ge-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ t1-* {
+ scheduler-map t1-sch-map;
+ unit * {
+ classifiers {
+ dscp dscp-default;
+ }
+ }
+ }
+ }
+ rewrite-rules {
+ exp exp-inet-table {
+ forwarding-class best-effort {
+ loss-priority low code-point 000;
+ loss-priority high code-point 001;
+ }
+ forwarding-class assured-forwarding {
+ loss-priority low code-point 010;
+ loss-priority high code-point 011;
+ }
+ forwarding-class expedited-forwarding {
+ loss-priority low code-point 111;
+ loss-priority high code-point 110;
+ }
+ forwarding-class network-control {
+ loss-priority low code-point 100;
+ loss-priority high code-point 101;
+ }
+ }
+ }
+ scheduler-maps {
+ t1-sch-map {
+ forwarding-class best-effort scheduler best-effort-sch;
+ forwarding-class expedited-forwarding scheduler t1-expedited-forwarding-sch;
+ forwarding-class network-control scheduler network-control-sch;
+ forwarding-class assured-forwarding scheduler t1-assured-forwarding-sch;
+ forwarding-class scavenger-service scheduler scavenger-service-sch;
+ }
+ }
+ schedulers {
+ best-effort-sch {
+ transmit-rate {
+ remainder;
+ }
+ buffer-size {
+ remainder;
+ }
+ priority low;
+ }
+ network-control-sch {
+ transmit-rate percent 5;
+ buffer-size percent 5;
+ priority high;
+ }
+ scavenger-service-sch {
+ transmit-rate percent 0;
+ buffer-size percent 0;
+ priority low;
+ }
+ t1-assured-forwarding-sch {
+ transmit-rate percent 45;
+ buffer-size percent 5;
+ priority high;
+ }
+ t1-expedited-forwarding-sch {
+ transmit-rate percent 35;
+ buffer-size percent 5;
+ priority high;
+ }
+ }
+}
+security {
+ policies {
+ from-zone DOH-DATA to-zone DOH-DATA {
+ policy DOH-DATA {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ from-zone DATACOMM-MGMT to-zone DATACOMM-MGMT {
+ policy DATACOMM-MGMT {
+ match {
+ source-address any;
+ destination-address any;
+ application any;
+ }
+ then {
+ permit;
+ }
+ }
+ }
+ }
+ zones {
+ security-zone DOH-DATA {
+ interfaces {
+ t1-1/0/0.17 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ ge-0/0/0.0 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ security-zone DATACOMM-MGMT {
+ interfaces {
+ t1-1/0/0.16 {
+ host-inbound-traffic {
+ system-services {
+ ping;
+ traceroute;
+ ssh;
+ snmp;
+ }
+ }
+ }
+ }
+ }
+ }
+}
+firewall {
+ family inet {
+ filter PROTECT-RE {
+ term SSH-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-MGMT-SOURCES;
+ PRE-LOCALIPv4-SOURCES;
+ }
+ protocol tcp;
+ destination-port ssh;
+ }
+ then accept;
+ }
+ term SSH-DENY {
+ from {
+ protocol tcp;
+ destination-port ssh;
+ }
+ then {
+ discard;
+ }
+ }
+ term SNMP-ALLOW {
+ from {
+ source-prefix-list {
+ PRE-SNMP-SOURCES;
+ }
+ protocol udp;
+ destination-port snmp;
+ }
+ then accept;
+ }
+ term SNMP-DENY {
+ from {
+ protocol udp;
+ destination-port snmp;
+ }
+ then {
+ discard;
+ }
+ }
+ term ALL-TRAFFIC {
+ then accept;
+ }
+ }
+ }
+ filter DOH-COS {
+ term expedited-forwarding {
+ from {
+ source-address {
+ 164.58.0.0/16;
+ 156.110.0.0/16;
+ }
+ }
+ then {
+ forwarding-class expedited-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-low {
+ from {
+ prefix-list {
+ DOH-TIME-SEN-LOW-BW;
+ }
+ destination-port [ 1433 80 139 445 9100 443 ];
+ }
+ then {
+ loss-priority low;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term assured-forwarding-high {
+ from {
+ prefix-list {
+ TIME-SEN-TRANS;
+ }
+ destination-port [ 80 135 139 445 1433 5088 5089 6087 ];
+ }
+ then {
+ loss-priority high;
+ forwarding-class assured-forwarding;
+ accept;
+ }
+ }
+ term accept-all {
+ then {
+ forwarding-class best-effort;
+ accept;
+ }
+ }
+ }
+}
+routing-instances {
+ DOH-DATA {
+ instance-type virtual-router;
+ interface ge-0/0/0.0;
+ interface t1-1/0/0.17;
+ routing-options {
+ static {
+ route 0.0.0.0/0 next-hop 10.119.76.160;
+ }
+ }
+ }
+}
+# grnoc-mon at DOH-CLAYTON-SRX220> show ospf neighbor
+# OSPF instance is not running
+#
+# grnoc-mon at DOH-CLAYTON-SRX220> show bfd session
+
+0 sessions, 0 clients
+Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
+
More information about the Nocrancid
mailing list