[Nocrancid] autopop-onenet.net router config diffs

rancid at rancid.noc.onenet.net rancid at rancid.noc.onenet.net
Sun Mar 6 03:02:26 CST 2016


Index: configs/maysville-es.client.onenet.net
===================================================================
--- configs/maysville-es.client.onenet.net	(revision 140472)
+++ configs/maysville-es.client.onenet.net	(working copy)
@@ -44,8 +44,10 @@
 #     Serial ID                      ACDT6307
 # 
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show chassis scb 
+# show chassis sfm detail
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show chassis sfm detail
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show chassis ssb 
+# show system boot-messages
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show system boot-messages 
 # kld_map_v: 0x8ff80000, kld_map_p: 0x0
 # Copyright (c) 1996-2014, Juniper Networks, Inc.
@@ -109,10 +111,11 @@
 # Trying to mount root from ufs:/dev/da0s1a
 # 
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show version 
-# Hostname: MAYSVILLE-ES-LEASED-ASSET-TAG-004945 # Model: srx240h2 # JUNOS Software Release [12.1X44-D35.5] #  # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> file list /var/tmp detail # lrw-r--r--  1 root  wheel         11 May 19  2014 /var/tmp@ -> /cf/var/tmp
+# Hostname: MAYSVILLE-ES-LEASED-ASSET-TAG-004945 # file list /var/tmp detail # Model: srx240h2 # JUNOS Software Release [12.1X44-D35.5] #  # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> file list /var/tmp detail # lrw-r--r--  1 root  wheel         11 May 19  2014 /var/tmp@ -> /cf/var/tmp
 # total files: 1
 # 
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show system uptime 
+# show interface terse
 # System booted: 2016-01-07 00:16 CST 
 # Protocols started: 2016-01-07 00:19 CST 
 # Last configured: 2015-10-26 13:12 CDT  by admin
@@ -168,6 +171,7 @@
 #vlan up up
 #vlan.999 up down
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show configuration 
+show ospf neighbor
 ## Last commit: 2015-10-26 13:12:04 CDT by admin
 version 12.1X44-D35.5;
 system {
Index: configs/oja-sw-youth-academy-manitou.client.onenet.net
===================================================================
--- configs/oja-sw-youth-academy-manitou.client.onenet.net	(revision 140451)
+++ configs/oja-sw-youth-academy-manitou.client.onenet.net	(working copy)
@@ -1,6 +1,7 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at OJA-SW-YOUTH-ACADEMY-MANITOU-LR-004653> show system commit 
+# show chassis environment
 #   2015-11-09 09:44:06 CST by sky via cli
 #   2015-11-09 09:19:03 CST by sky via cli
 #   2015-11-02 20:09:28 CST by joel via cli
Index: configs/granite-public-schools.client.onenet.net
===================================================================
--- configs/granite-public-schools.client.onenet.net	(revision 140473)
+++ configs/granite-public-schools.client.onenet.net	(working copy)
@@ -5,7 +5,6 @@
 #   2015-12-04 14:26:02 CST by onenet via cli commit confirmed, rollback in 5mins
 #   2014-06-27 21:42:44 CDT by onenet via cli commit confirmed, rollback in 10mins
 #   2014-06-27 21:38:48 CDT by root via other
-# show chassis environment
 #   2014-06-27 21:36:46 CDT by onenet via cli commit confirmed, rollback in 1mins
 #   2014-06-27 21:35:40 CDT by root via other
 # grnoc-mon at GRANITE-PUBLIC-SCHOOLS-TAG-004358> show chassis environment 
Index: configs/core3.okc-m120.onenet.net
===================================================================
--- configs/core3.okc-m120.onenet.net	(revision 140473)
+++ configs/core3.okc-m120.onenet.net	(working copy)
@@ -1109,8 +1109,8 @@
 #t1-3/3/0:3:19 down down
 #t1-3/3/0:3:20 down down
 #t1-3/3/0:3:21 down down
-#t1-3/3/0:3:22 up down
-#t1-3/3/0:3:22.0 up down
+#t1-3/3/0:3:22 up up
+#t1-3/3/0:3:22.0 up up
 #t1-3/3/0:3:23 up up
 #t1-3/3/0:3:23.0 up up
 #t1-3/3/0:3:24 down down
Index: configs/hub.chi.onenet.net
===================================================================
--- configs/hub.chi.onenet.net	(revision 140473)
+++ configs/hub.chi.onenet.net	(working copy)
@@ -294,7 +294,7 @@
 #t1-2/0/2:1 up up
 #t1-2/0/2:1.16 up up
 #t1-2/0/2:1.17 up up
-#t1-2/0/2:2 down up
+#t1-2/0/2:2 down down
 #t1-2/0/2:3 down down
 #t1-2/0/2:4 down down
 #t1-2/0/2:5 down down
Index: configs/acx.cai.hart-acx2100.onenet.net
===================================================================
--- configs/acx.cai.hart-acx2100.onenet.net	(revision 140473)
+++ configs/acx.cai.hart-acx2100.onenet.net	(working copy)
@@ -1,7 +1,6 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> show system commit 
-# show chassis environment
 #   2016-01-29 13:21:47 CST by sky via cli
 #   2015-10-16 09:22:41 CDT by andrew via cli
 #   2015-05-28 22:37:23 CDT by andrew via cli commit confirmed, rollback in 3mins
@@ -73,6 +72,7 @@
 # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> show chassis sfm detail 
 # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> show chassis ssb 
 # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> show system boot-messages 
+# show version
 # platform_early_bootinit: MX-PPC Series Early Boot Initialization
 # mxppc_set_re_type: hw.board.type is ACX-2100
 # WDOG initialized
@@ -141,7 +141,8 @@
 # WARNING: /var was not properly dismounted
 # 
 # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> show version 
-# Hostname: HARTSHORNE-PUBLIC-LIBRARY-ACX2100 # Model: acx2100 # JUNOS Crypto Software Suite [12.3X54-D10.6] # JUNOS Base OS Software Suite [12.3X54-D10.6] # JUNOS Kernel Software Suite [12.3X54-D10.6] # JUNOS Base OS boot [12.3X54-D10.6] # JUNOS Packet Forwarding Engine Support (ACX) [12.3X54-D10.6] # JUNOS Online Documentation [12.3X54-D10.6] # JUNOS Routing Software Suite [12.3X54-D10.6] #  # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> file list /var/tmp detail # 
+# Hostname: HARTSHORNE-PUBLIC-LIBRARY-ACX2100 # Model: acx2100 # JUNOS Crypto Software Suite [12.3X54-D10.6] # JUNOS Base OS Software Suite [12.3X54-D10.6] # JUNOS Kernel Software Suite [12.3X54-D10.6] # JUNOS Base OS boot [12.3X54-D10.6] # JUNOS Packet Forwarding Engine Support (ACX) [12.3X54-D10.6] # JUNOS Online Documentation [12.3X54-D10.6] # JUNOS Routing Software Suite [12.3X54-D10.6] #  # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> file list /var/tmp detail # show system uptime
+# 
 # /var/tmp:
 # total blocks: 291872
 # drwxr-xr-x  2 root  field        512 Dec 31  2009 gres-tp/
@@ -155,6 +156,7 @@
 # 
 # grnoc-mon at HARTSHORNE-PUBLIC-LIBRARY-ACX2100> show system uptime 
 # System booted: 2016-01-08 11:40 CST 
+# show interface terse
 # Protocols started: 2016-01-08 11:42 CST 
 # Last configured: 2016-01-29 13:21 CST  by sky
 # 
Index: configs/maysville-hs.client.onenet.net
===================================================================
--- configs/maysville-hs.client.onenet.net	(revision 140473)
+++ configs/maysville-hs.client.onenet.net	(working copy)
@@ -9,6 +9,7 @@
 #   2015-05-14 17:55:25 CDT by root via other
 # rescue  2015-10-26 17:25:18 CDT by root via recovery-mgmt
 # 
+# show chassis environment
 # grnoc-mon at MAYSVILLE-HS-LEASED-ASSET-TAG-004887> show chassis environment 
 # Class Item                           Status     Measurement
 # Temp  Routing Engine                 OK        
Index: configs/okc-vpn-cluster.okc.onenet.net
===================================================================
--- configs/okc-vpn-cluster.okc.onenet.net	(revision 140368)
+++ configs/okc-vpn-cluster.okc.onenet.net	(working copy)
@@ -1,12 +1,12 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at OKC-VPN-CLUSTER-NODE0> show system commit 
+#   2016-03-06 02:05:45 CST by andrew via cli
 #   2016-03-02 10:23:11 CST by andrew via cli commit confirmed, rollback in 3mins
 #   2016-03-01 23:35:59 CST by andrew via cli
 #   2016-03-01 23:26:20 CST by andrew via cli commit confirmed, rollback in 10mins
 #   2016-03-01 22:54:10 CST by andrew via cli commit confirmed, rollback in 10mins
 #   2016-03-01 22:48:17 CST by andrew via cli commit confirmed, rollback in 10mins
-#   2016-03-01 22:12:55 CST by andrew via cli
 # grnoc-mon at OKC-VPN-CLUSTER-NODE0> show chassis environment 
 # node0:
 # --------------------------------------------------------------------------
@@ -234,12 +234,12 @@
 # --------------------------------------------------------------------------
 # System booted: 2016-03-01 19:49 CST 
 # Protocols started: 2016-03-01 20:04 CST 
-# Last configured: 2016-03-02 10:23 CST  by andrew
+# Last configured: 2016-03-06 02:05 CST  by andrew
 # 
 # node1:
 # --------------------------------------------------------------------------
 # System booted: 2016-03-01 19:35 CST 
-# Last configured: 2016-03-02 10:23 CST  by root
+# Last configured: 2016-03-06 02:05 CST  by root
 # 
 # {primary:node0}
 # grnoc-mon at OKC-VPN-CLUSTER-NODE0> show interface terse 
@@ -346,12 +346,13 @@
 #st0.9 up up
 #st0.10 up up
 #st0.11 up up
+#st0.12 up up
 #swfab0 up down
 #swfab1 up down
 #tap up up
 #vlan up up
 # grnoc-mon at OKC-VPN-CLUSTER-NODE0> show configuration 
-## Last commit: 2016-03-02 10:23:11 CST by andrew
+## Last commit: 2016-03-06 02:05:45 CST by andrew
 version 12.1X46-D40.2;
 groups {
     node0 {
@@ -742,6 +743,12 @@
                 address 10.119.56.14/31;
             }
         }
+        unit 12 {
+            description "EODLS-MUSKOGEE-MAIN-OFFICE [NO-MONITOR]";
+            family inet {
+                address 156.110.46.17/30;
+            }
+        }
     }
 }
 snmp {
@@ -785,6 +792,22 @@
                 peer-as 64571;
             }
         }
+        group EBGP-EODLS-OFFICE-V4 {
+            type external;
+            family inet {
+                unicast;
+            }
+            neighbor 156.110.46.18 {
+                description "EBGP-EODLS-OFFICE-V4-VPN [NO-MONITOR]";
+                import EBGP-EODLS-OFFICE-V4-IMPORT;
+#                authentication-#key <removed>;
+                export EBGP-EODLS-OFFICE-V4-EXPORT;
+                remove-private {
+                    all;
+                }
+                peer-as 64516;
+            }
+        }
     }
     lldp {
         interface all;
@@ -828,6 +851,29 @@
             then reject;
         }
     }
+    policy-statement EBGP-EODLS-OFFICE-V4-EXPORT {
+        term EXPORT-DEFAULT {
+            from {
+                route-filter 0.0.0.0/0 exact;
+            }
+            then accept;
+        }
+        term REJECT-ALL-ELSE {
+            then reject;
+        }
+    }
+    policy-statement EBGP-EODLS-OFFICE-V4-IMPORT {
+        term PREFIXES {
+            from {
+                route-filter 164.58.177.32/27 exact;
+                route-filter 156.110.106.126/32 exact;
+            }
+            then accept;
+        }
+        term REJECT-ALL-ELSE {
+            then reject;
+        }
+    }
     policy-statement EBGP-ONENET-V4-EXPORT {
         term REJECT-DEFAULT {
             from {
@@ -873,7 +919,7 @@
             proposals PRE-G2-AES128-SHA;
 #            pre-shared-#key <removed>;
         }
-        policy IKE-DHS-CARTER {
+        policy IKE-DHS-DATA-CARTER {
             mode main;
             proposals PRE-G2-AES128-SHA;
 #            pre-shared-#key <removed>;
@@ -923,6 +969,11 @@
             proposals PRE-G2-AES128-SHA;
 #            pre-shared-#key <removed>;
         }
+        policy IKE-EODLS-OFFICE {
+            mode aggressive;
+            proposal-set standard;
+#            pre-shared-#key <removed>;
+        }
         gateway IKE-GATE-COMANCHE-PS {
             ike-policy IKE-COMANCHE-PS;
             address 166.141.5.145;
@@ -936,8 +987,8 @@
             external-interface lo0.0;
             local-address 164.58.0.254;
         }
-        gateway IKE-GATE-DHS-CARTER {
-            ike-policy IKE-DHS-CARTER;
+        gateway IKE-GATE-DHS-DATA-CARTER {
+            ike-policy IKE-DHS-DATA-CARTER;
             address 166.130.131.48;
             external-interface lo0.0;
             local-address 164.58.0.253;
@@ -996,6 +1047,12 @@
             external-interface lo0.0;
             local-address 164.58.0.252;
         }
+        gateway IKE-GATE-EODLS-OFFICE {
+            ike-policy IKE-EODLS-OFFICE;
+            dynamic user-at-hostname "eodls at vpn.onenet.net";
+            external-interface lo0.0;
+            local-address 164.58.0.252;
+        }
     }
     ipsec {
         proposal ESP-AES128-SHA {
@@ -1010,7 +1067,7 @@
         policy VPN-POLICY-DHS-GUEST-CARTER {
             proposals ESP-AES128-SHA;
         }
-        policy VPN-POLICY-DHS-CARTER {
+        policy VPN-POLICY-DHS-DATA-CARTER {
             proposals ESP-AES128-SHA;
         }
         policy VPN-POLICY-OTRD-GUEST-BEAV-BEND {
@@ -1040,6 +1097,9 @@
         policy VPN-POLICY-OTRD-MGMT-ROMAN-NOSE {
             proposals ESP-AES128-SHA;
         }
+        policy VPN-POLICY-EODLS-OFFICE {
+            proposal-set standard;
+        }
         vpn IPSEC-VPN-COMANCHE-PS {
             bind-interface st0.0;
             ike {
@@ -1061,7 +1121,7 @@
             }
             establish-tunnels immediately;
         }
-        vpn IPSEC-VPN-DHS-CARTER {
+        vpn IPSEC-VPN-DHS-DATA-CARTER {
             bind-interface st0.10;
             vpn-monitor {
                 optimized;
@@ -1069,8 +1129,8 @@
                 destination-ip 10.119.52.15;
             }
             ike {
-                gateway IKE-GATE-DHS-CARTER;
-                ipsec-policy VPN-POLICY-DHS-CARTER;
+                gateway IKE-GATE-DHS-DATA-CARTER;
+                ipsec-policy VPN-POLICY-DHS-DATA-CARTER;
             }
             establish-tunnels immediately;
         }
@@ -1161,6 +1221,14 @@
             }
             establish-tunnels immediately;
         }
+        vpn IPSEC-VPN-EODLS {
+            bind-interface st0.12;
+            ike {
+                gateway IKE-GATE-EODLS-OFFICE;
+                ipsec-policy VPN-POLICY-EODLS-OFFICE;
+            }
+            establish-tunnels immediately;
+        }
     }
     alg {
         msrpc disable;
@@ -1339,6 +1407,17 @@
                         }
                     }
                 }
+                st0.12 {
+                    host-inbound-traffic {
+                        system-services {
+                            ping;
+                            traceroute;
+                        }
+                        protocols {
+                            bgp;
+                        }
+                    }
+                }
             }
         }
         security-zone OMES-MGMT {
Index: configs/hub.tsb.onenet.net
===================================================================
--- configs/hub.tsb.onenet.net	(revision 140473)
+++ configs/hub.tsb.onenet.net	(working copy)
@@ -198,7 +198,7 @@
 # -rw-rw----  1 root  field   51994624 Oct 24  2013 ifinfo.core.1
 # -rw-rw----  1 root  field   51974144 Oct 24  2013 ifinfo.core.2
 # -rw-rw----  1 root  field   52744192 Oct 24  2013 ifinfo.core.3
-# -rw-rw----  1 root  field   52727808 Mar 6  01:58 ifinfo.core.4
+# -rw-rw----  1 root  field   52727808 Mar 6  02:58 ifinfo.core.4
 # drwxrwxrwx  2 root  wheel        512 Oct 12  2012 install/
 # -rw-rw----  1 root  field   33464320 Mar 3   2014 jdiameterd.core.0
 # -rw-r--r--  1 eng   field   99542994 Apr 23  2013 jinstall-ppc-11.4R7.5-domestic-signed.tgz



More information about the Nocrancid mailing list