[Nocrancid] autopop-onenet.net router config diffs

rancid at rancid.noc.onenet.net rancid at rancid.noc.onenet.net
Fri Sep 8 16:04:59 CDT 2017


Index: configs/hub.tis.onenet.net
===================================================================
--- configs/hub.tis.onenet.net	(revision 156447)
+++ configs/hub.tis.onenet.net	(working copy)
@@ -474,8 +474,8 @@
 #pc-2/2/0 up up
 #pc-2/2/0.16383 up up
 #ge-2/2/1 down down
-#ge-2/2/2 up down
-#ge-2/2/2.0 up down
+#ge-2/2/2 up up
+#ge-2/2/2.0 up up
 #ge-2/2/3 up up
 #ge-2/2/3.901 up up
 #ge-2/2/3.902 up up
Index: configs/allen-public-library.client.onenet.net
===================================================================
--- configs/allen-public-library.client.onenet.net	(revision 156432)
+++ configs/allen-public-library.client.onenet.net	(working copy)
@@ -150,10 +150,10 @@
 #ge-0/0/1.0 up down
 #ge-0/0/2 up up
 #ge-0/0/2.0 up up
-#ge-0/0/3 up down
-#ge-0/0/3.0 up down
-#ge-0/0/4 up down
-#ge-0/0/4.0 up down
+#ge-0/0/3 up up
+#ge-0/0/3.0 up up
+#ge-0/0/4 up up
+#ge-0/0/4.0 up up
 #ge-0/0/5 up up
 #ge-0/0/5.0 up up
 #ge-0/0/6 up up
Index: configs/maysville-es.client.onenet.net
===================================================================
--- configs/maysville-es.client.onenet.net	(revision 156329)
+++ configs/maysville-es.client.onenet.net	(working copy)
@@ -630,6 +630,7 @@
 # OSPF instance is not running
 # 
 # grnoc-mon at MAYSVILLE-ES-LEASED-ASSET-TAG-004945> show bfd session 
+quit
 
 0 sessions, 0 clients
 Cumulative transmit rate 0.0 pps, cumulative receive rate 0.0 pps
Index: configs/core.hut.sal.onenet.net
===================================================================
--- configs/core.hut.sal.onenet.net	(revision 156447)
+++ configs/core.hut.sal.onenet.net	(working copy)
@@ -26,6 +26,16 @@
 #       TFEB 0 TBB PFE Chip            OK        
 #       TFEB 0 TFEB PCIE TSen          OK        
 #       TFEB 0 TFEB PCIE Chip          OK        
+#       TFEB 0 QX 0 TSen               OK        
+#       TFEB 0 QX 0 Chip               OK        
+#       TFEB 0 LU 0 TSen               OK        
+#       TFEB 0 LU 0 Chip               OK        
+#       TFEB 0 MQ 0 TSen               OK        
+#       TFEB 0 MQ 0 Chip               OK        
+#       TFEB 0 TBB PFE TSen            OK        
+#       TFEB 0 TBB PFE Chip            OK        
+#       TFEB 0 TFEB PCIE TSen          OK        
+#       TFEB 0 TFEB PCIE Chip          OK        
 # Fans  Fan 1                          OK
 #       Fan 2                          OK
 #       Fan 3                          OK
Index: configs/core.hut.ard.onenet.net
===================================================================
--- configs/core.hut.ard.onenet.net	(revision 156444)
+++ configs/core.hut.ard.onenet.net	(working copy)
@@ -1,12 +1,12 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at ARDMORE-MX40> show system commit 
+#   2017-09-08 15:56:13 CDT by andrew via cli
 #   2017-09-08 11:34:08 CDT by andrew via cli
 #   2017-09-08 10:44:08 CDT by andrew via cli
 #   2017-09-08 10:31:33 CDT by andrew via cli
 #   2017-09-08 10:23:27 CDT by andrew via cli
 #   2017-09-08 10:11:43 CDT by andrew via cli
-#   2017-09-08 10:10:43 CDT by andrew via cli
 # grnoc-mon at ARDMORE-MX40> show chassis environment 
 # Class Item                           Status     Measurement
 # Temp  PEM 0                          OK        
@@ -270,7 +270,7 @@
 # grnoc-mon at ARDMORE-MX40> show system uptime 
 # System booted: 2016-03-14 01:34 CDT 
 # Protocols started: 2016-03-14 01:36 CDT 
-# Last configured: 2017-09-08 11:34 CDT  by andrew
+# Last configured: 2017-09-08 15:56 CDT  by andrew
 # 
 # grnoc-mon at ARDMORE-MX40> show interface terse 
 #Interface Admin Link
@@ -401,7 +401,7 @@
 #pp0 up up
 #tap up up
 # grnoc-mon at ARDMORE-MX40> show configuration 
-## Last commit: 2017-09-08 11:34:08 CDT by andrew
+## Last commit: 2017-09-08 15:56:13 CDT by andrew
 version 13.3R8.7;
 groups {
     ISIS-L2-INTERFACE {
@@ -2275,12 +2275,6 @@
         vrf-export MHSSO-VRF-EXPORT;
         vrf-target target:5078:2643;
         vrf-table-label;
-        routing-options {
-            static {
-                route 192.168.1.0/24 next-hop 10.199.28.65;
-                route 192.168.2.0/24 next-hop 10.199.28.67;
-            }
-        }
     }
     ODOT-L3VPN {
         description ODOT-L3VPN;
Index: configs/core.rack59.onenet.net
===================================================================
--- configs/core.rack59.onenet.net	(revision 156447)
+++ configs/core.rack59.onenet.net	(working copy)
@@ -1,12 +1,12 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at RACK59-MX480-RE0> show system commit 
+#   2017-09-08 16:00:00 CDT by andrew via cli commit synchronize
+#   2017-09-08 15:36:50 CDT by andrew via cli commit synchronize
+#   2017-09-08 15:26:43 CDT by sky via cli commit synchronize
+#   2017-09-08 15:19:51 CDT by sky via cli commit synchronize
 #   2017-09-08 14:51:52 CDT by sky via cli commit synchronize
 #   2017-09-08 14:46:35 CDT by sky via cli commit synchronize
-#   2017-08-24 14:32:18 CDT by andrew via cli commit synchronize
-#   2017-08-23 12:02:01 CDT by andrew via cli commit synchronize
-#   2017-08-22 19:28:57 CDT by andrew via cli commit synchronize
-#   2017-08-22 14:17:54 CDT by andrew via cli commit synchronize
 # grnoc-mon at RACK59-MX480-RE0> show chassis environment 
 # Class Item                           Status     Measurement
 # Temp  PEM 0                          OK        
@@ -446,7 +446,7 @@
 # grnoc-mon at RACK59-MX480-RE0> show system uptime 
 # System booted: 2016-03-30 08:27 CDT 
 # Protocols started: 2016-03-30 08:30 CDT 
-# Last configured: 2017-09-08 14:51 CDT  by sky
+# Last configured: 2017-09-08 16:00 CDT  by andrew
 # 
 # {master}
 # grnoc-mon at RACK59-MX480-RE0> show interface terse 
@@ -466,13 +466,15 @@
 #ge-3/2/0.106 up up
 #ge-3/2/0.107 up up
 #ge-3/2/0.1103 up up
+#ge-3/2/0.1105 up up
 #ge-3/2/0.32767 up up
 #lc-3/2/0 up up
 #lc-3/2/0.32769 up up
 #pfe-3/2/0 up up
 #pfe-3/2/0.16383 up up
 #ge-3/2/1 up up
-#ge-3/2/1.308 up up
+#ge-3/2/1.1438 up up
+#ge-3/2/1.2438 up up
 #ge-3/2/1.32767 up up
 #ge-3/2/2 up down
 #ge-3/2/3 up down
@@ -580,6 +582,7 @@
 #lsi.256 up up
 #lsi.257 up up
 #lsi.258 up up
+#lsi.259 up up
 #mtun up up
 #pimd up up
 #pime up up
@@ -587,7 +590,7 @@
 #pp0 up up
 #tap up up
 # grnoc-mon at RACK59-MX480-RE0> show configuration 
-## Last commit: 2017-09-08 14:51:52 CDT by sky
+## Last commit: 2017-09-08 16:00:00 CDT by andrew
 version 13.3R9.13;
 groups {
     re0 {
@@ -940,19 +943,53 @@
                 address 10.250.70.1/30;
             }
         }
+        unit 1105 {
+            vlan-tags outer 105 inner 500;
+            family inet {
+                address 10.250.71.1/30;
+            }
+        }
     }
     ge-3/2/1 {
         description NNI-TO-CABLEONE-1G-CIR000XXXX;
         flexible-vlan-tagging;
         mtu 9192;
         encapsulation flexible-ethernet-services;
-        unit 308 {
-            description "MHSSO-ADA [ORDERED]";
-            vlan-tags outer 308 inner 500;
+        unit 1438 {
+            description MHSSO-ADA-100M-CIR0020312;
+            bandwidth 100m;
+            vlan-tags outer 1438 inner 500;
             family inet {
+                rpf-check;
+                mtu 1500;
+                policer {
+                    input 100M-POL;
+                    output 100M-POL;
+                }
+                sampling {
+                    input;
+                }
                 address 156.110.34.16/31;
             }
         }
+        unit 2438 {
+            description MHSSO-ADA-MPLS-100M-CIR0020312;
+            bandwidth 100m;
+            vlan-tags outer 1438 inner 501;
+            family inet {
+                rpf-check;
+                mtu 1500;
+                policer {
+                    input 100M-POL;
+                    output 100M-POL;
+                }
+                sampling {
+                    input;
+                    output;
+                }
+                address 10.199.28.70/31;
+            }
+        }
     }
     xe-4/0/0 {
         description "CORE 10GE to core2.okc xe-3/0/1 [AE0-1of4] | OneNet-OKC-RACK59-XE-19846";
@@ -2533,6 +2570,41 @@
             load-balance per-packet;
         }
     }
+    policy-statement MHSSO-VRF-EXPORT {
+        term 1 {
+            from protocol static;
+            then {
+                community add MHSSO-VPN;
+                accept;
+            }
+        }
+        term 2 {
+            from protocol direct;
+            then {
+                community add MHSSO-VPN;
+                accept;
+            }
+        }
+        term 3 {
+            from protocol ospf;
+            then {
+                community add MHSSO-VPN;
+                accept;
+            }
+        }
+    }
+    policy-statement MHSSO-VRF-IMPORT {
+        term 1 {
+            from {
+                protocol bgp;
+                community MHSSO-VPN;
+            }
+            then accept;
+        }
+        term 2 {
+            then reject;
+        }
+    }
     policy-statement NEXT-HOP-SELF {
         term BLACKHOLE {
             from community ONENET_BLACKHOLE;
@@ -2704,6 +2776,7 @@
     community 65003:0 members 65003:0;
     community AERON-NETFLIX members 40581:3003;
     community GPN-NETFLIX members 11317:3003;
+    community MHSSO-VPN members target:5078:2643;
     community NETFLIX-REJECT members [ 11317:3006 40581:3006 ];
     community NON_ONENET {
         invert-match;
@@ -3014,6 +3087,16 @@
     }
 }
 routing-instances {
+    MHSSO-L3VPN {
+        description MENTAL-HEALTH-SERVICES-OF-SOUTHERN-OKLAHOMA-L3VPN;
+        instance-type vrf;
+        interface ge-3/2/1.2438;
+        route-distinguisher 164.58.199.80:2643;
+        vrf-import MHSSO-VRF-IMPORT;
+        vrf-export MHSSO-VRF-EXPORT;
+        vrf-target target:5078:2643;
+        vrf-table-label;
+    }
     OMES-AGENCY-DATA-L3VPN {
         description OMES-AGENCY-DATA-L3VPN;
         instance-type vrf;
Index: configs/core.law.onenet.net
===================================================================
--- configs/core.law.onenet.net	(revision 156446)
+++ configs/core.law.onenet.net	(working copy)
@@ -1,12 +1,12 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at LAWTON-MX480-RE0> show system commit 
+#   2017-09-08 15:17:36 CDT by sean via cli commit synchronize
 #   2017-09-08 13:37:07 CDT by sean via cli commit synchronize
 #   2017-08-29 00:22:47 CDT by andrew via cli commit synchronize
 #   2017-08-26 14:45:48 CDT by andrew via cli commit synchronize
 #   2017-08-26 14:23:46 CDT by andrew via cli commit synchronize
 #   2017-08-26 13:14:16 CDT by andrew via cli commit synchronize
-#   2017-08-24 16:08:56 CDT by joel via cli commit synchronize
 # grnoc-mon at LAWTON-MX480-RE0> show chassis environment 
 # Class Item                           Status     Measurement
 # Temp  PEM 0                          OK        
@@ -451,7 +451,7 @@
 # grnoc-mon at LAWTON-MX480-RE0> show system uptime 
 # System booted: 2016-03-16 01:11 CDT 
 # Protocols started: 2016-03-16 01:22 CDT 
-# Last configured: 2017-09-08 13:37 CDT  by sean
+# Last configured: 2017-09-08 15:17 CDT  by sean
 # 
 # {master}
 # grnoc-mon at LAWTON-MX480-RE0> show interface terse 
@@ -713,7 +713,7 @@
 #pp0 up up
 #tap up up
 # grnoc-mon at LAWTON-MX480-RE0> show configuration 
-## Last commit: 2017-09-08 13:37:07 CDT by sean
+## Last commit: 2017-09-08 15:17:36 CDT by sean
 version 13.3R8.7;
 groups {
     re0 {
@@ -1058,7 +1058,7 @@
         disable;
     }
     ge-0/1/9 {
-        description "HEI-CAMERON-2509-VPLS-GE-CIR000XXXX [NO-MONITOR]";
+        description "HEI-CAMERON-2509-VPLS-GE-CIR0020538 [NO-MONITOR]";
         vlan-tagging;
         mtu 9192;
         encapsulation vlan-vpls;
@@ -1222,7 +1222,7 @@
         }
     }
     ge-0/3/2 {
-        description "HEI-CAMERON-LAW-DUN-CCC-GE-CIR000XXXX [NO-MONITOR]";
+        description "HEI-CAMERON-LAW-DUN-CCC-GE-CIR0020539 [NO-MONITOR]";
         flexible-vlan-tagging;
         mtu 1518;
         encapsulation flexible-ethernet-services;
@@ -1714,7 +1714,7 @@
         }
     }
     xe-1/1/0 {
-        description HEI-CAMERON-UNIVERSITY-10G-CIR0005427;
+        description HEI-CAMERON-UNIVERSITY-10G-CIR0020540;
         unit 0 {
             family bridge {
                 interface-mode access;
@@ -1792,7 +1792,7 @@
         }
     }
     xe-1/2/0 {
-        description "HEI-CAMERON-LAW-DUN-CCC-CIR0020525-[NO-MONITOR]";
+        description "HEI-CAMERON-LAW-DUN-CCC-CIR0020541-[NO-MONITOR]";
         flexible-vlan-tagging;
         mtu 1518;
         encapsulation flexible-ethernet-services;
@@ -1820,7 +1820,7 @@
         }
     }
     xe-1/3/0 {
-        description HEI-CAMERON-UNIVERSITY-10G-CIR0005428;
+        description HEI-CAMERON-UNIVERSITY-10G-CIR0020542;
         unit 0 {
             family bridge {
                 interface-mode access;
@@ -1982,7 +1982,7 @@
     }
     irb {
         unit 500 {
-            description HEI-CAMERON-UNIVERSITY;
+            description HEI-CAMERON-UNIVERSITY-CIR0020543;
             family inet {
                 sampling {
                     input;
Index: configs/core5.okc.onenet.net
===================================================================
--- configs/core5.okc.onenet.net	(revision 156446)
+++ configs/core5.okc.onenet.net	(working copy)
@@ -1,12 +1,12 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at OKC-CORE5-MX480-RE0> show system commit 
+#   2017-09-08 15:59:01 CDT by sky via cli commit synchronize
+#   2017-09-08 15:53:11 CDT by andrew via cli commit synchronize
+#   2017-09-08 15:45:47 CDT by andrew via cli commit synchronize
 #   2017-09-08 13:49:12 CDT by sky via cli commit synchronize
 #   2017-09-08 11:49:43 CDT by sky via cli commit synchronize
 #   2017-09-08 11:45:56 CDT by sky via cli commit synchronize
-#   2017-09-08 11:38:28 CDT by andrew via cli commit synchronize
-#   2017-09-08 11:21:52 CDT by sky via cli commit synchronize
-#   2017-09-08 11:09:33 CDT by sky via cli commit synchronize
 # grnoc-mon at OKC-CORE5-MX480-RE0> show chassis environment 
 # Class Item                           Status     Measurement
 # Temp  PEM 0                          OK        
@@ -562,7 +562,7 @@
 # grnoc-mon at OKC-CORE5-MX480-RE0> show system uptime 
 # System booted: 2016-10-12 08:16 CDT 
 # Protocols started: 2016-10-12 08:18 CDT 
-# Last configured: 2017-09-08 13:49 CDT  by sky
+# Last configured: 2017-09-08 15:59 CDT  by sky
 # 
 # {master}
 # grnoc-mon at OKC-CORE5-MX480-RE0> show interface terse 
@@ -716,6 +716,7 @@
 #xe-1/0/0.699 up up
 #xe-1/0/0.715 up up
 #xe-1/0/0.726 up up
+#xe-1/0/0.752 up up
 #xe-1/0/0.753 up up
 #xe-1/0/0.754 up up
 #xe-1/0/0.761 up up
@@ -806,6 +807,7 @@
 #xe-1/0/0.1699 up up
 #xe-1/0/0.1715 up up
 #xe-1/0/0.1726 up up
+#xe-1/0/0.1753 up up
 #xe-1/0/0.1754 up up
 #xe-1/0/0.1822 up up
 #xe-1/0/0.1932 up up
@@ -1000,6 +1002,7 @@
 #xe-1/1/0.1598 up up
 #xe-1/1/0.1599 up up
 #xe-1/1/0.1629 up up
+#xe-1/1/0.1755 up up
 #xe-1/1/0.1938 up up
 #xe-1/1/0.2560 up up
 #xe-1/1/0.2629 up up
@@ -1403,7 +1406,7 @@
 #pp0 up up
 #tap up up
 # grnoc-mon at OKC-CORE5-MX480-RE0> show configuration 
-## Last commit: 2017-09-08 13:49:12 CDT by sky
+## Last commit: 2017-09-08 15:59:01 CDT by sky
 version 13.3R9.13;
 groups {
     re0 {
@@ -3066,10 +3069,27 @@
                 address 10.119.73.4/31;
             }
         }
+        unit 752 {
+            description "MHSSO-TISH [ORDERED]";
+            vlan-tags outer 752 inner 500;
+            family inet {
+                address 156.110.34.192/31;
+            }
+        }
         unit 753 {
-            description "MHSSSO-PAULS-VALLEY [ORDERED]";
+            description MHSSO-PAULS-VALLEY-100M-CIR0020317;
+            bandwidth 100m;
             vlan-tags outer 753 inner 500;
             family inet {
+                rpf-check;
+                mtu 1500;
+                policer {
+                    input 100M-POL;
+                    output 100M-POL;
+                }
+                sampling {
+                    input;
+                }
                 address 156.110.34.18/31;
             }
         }
@@ -4635,6 +4655,24 @@
                 address 10.119.53.4/31;
             }
         }
+        unit 1753 {
+            description MHSSO-PAULS-VALLEY-MPLS-100M-CIR0020317;
+            bandwidth 100m;
+            vlan-tags outer 753 inner 501;
+            family inet {
+                rpf-check;
+                mtu 1500;
+                policer {
+                    input 100M-POL;
+                    output 100M-POL;
+                }
+                sampling {
+                    input;
+                    output;
+                }
+                address 10.199.28.72/31;
+            }
+        }
         unit 1754 {
             description MHSSO-DURANT-MPLS-100M-CIR0020315;
             bandwidth 100m;
@@ -7707,9 +7745,19 @@
             }
         }
         unit 755 {
-            description MHSSO-SEMINOLE;
+            description MHSSO-SEMINOLE-100M-CIR0020318;
+            bandwidth 100m;
             vlan-tags outer 755 inner 500;
             family inet {
+                rpf-check;
+                mtu 1500;
+                policer {
+                    input 100M-POL;
+                    output 100M-POL;
+                }
+                sampling {
+                    input;
+                }
                 address 156.110.34.146/31;
             }
         }
@@ -7857,6 +7905,24 @@
                 address 10.119.76.214/31;
             }
         }
+        unit 1755 {
+            description MHSSO-SEMINOLE-MPLS-100M-CIR0020318;
+            bandwidth 100m;
+            vlan-tags outer 755 inner 501;
+            family inet {
+                rpf-check;
+                mtu 1500;
+                policer {
+                    input 100M-POL;
+                    output 100M-POL;
+                }
+                sampling {
+                    input;
+                    output;
+                }
+                address 10.199.28.74/31;
+            }
+        }
         unit 1938 {
             description DHS-ATOKA-N-GREATHOUSE-DATA-20M-CIR0020252;
             bandwidth 20m;
@@ -10664,6 +10730,7 @@
         route 164.58.1.104/30 next-hop 156.110.27.75;
         route 164.58.2.32/28 next-hop 156.110.34.19;
         route 164.58.2.64/28 next-hop 156.110.34.147;
+        route 164.58.2.176/28 next-hop 156.110.34.193;
     }
     router-id 164.58.199.215;
     autonomous-system 5078;
@@ -21089,7 +21156,9 @@
     MHSSO-L3VPN {
         description MENTAL-HEALTH-SERVICES-OF-SOUTHERN-OKLAHOMA-L3VPN;
         instance-type vrf;
+        interface xe-1/0/0.1753;
         interface xe-1/0/0.1754;
+        interface xe-1/1/0.1755;
         interface irb.607;
         route-distinguisher 164.58.199.215:2643;
         vrf-import MHSSO-VRF-IMPORT;
@@ -21101,7 +21170,6 @@
                 route 10.0.0.0/8 next-hop 10.199.28.95;
                 route 172.16.0.0/12 next-hop 10.199.28.95;
                 route 192.168.0.0/16 next-hop 10.199.28.95;
-                route 192.168.6.0/24 next-hop 10.199.28.69;
             }
         }
     }
Index: configs/city-of-lawton.client.onenet.net
===================================================================
--- configs/city-of-lawton.client.onenet.net	(revision 156445)
+++ configs/city-of-lawton.client.onenet.net	(working copy)
@@ -1,12 +1,12 @@
 # RANCID-CONTENT-TYPE: juniper
 #
 # grnoc-mon at CITY-OF-LAWTON-005231> show system commit 
+#   2017-09-08 15:56:50 CDT by sky via cli
+#   2017-09-08 15:55:36 CDT by sky via cli
 #   2017-09-08 12:34:32 CDT by joel via cli commit confirmed, rollback in 5mins
 #   2017-09-08 11:48:16 CDT by joel via cli
 #   2017-09-08 11:23:36 CDT by joel via cli commit confirmed, rollback in 5mins
 #   2017-09-08 11:07:31 CDT by joel via cli
-#   2017-09-07 23:27:33 CDT by joel via cli
-#   2017-09-07 23:22:23 CDT by joel via cli commit confirmed, rollback in 5mins
 # grnoc-mon at CITY-OF-LAWTON-005231> show chassis environment 
 # Class Item                           Status     Measurement
 # Temp  Routing Engine                 OK        
@@ -135,7 +135,7 @@
 # Time Source:  NTP CLOCK 
 # System booted: 2017-08-25 14:03 CDT 
 # Protocols started: 2017-08-25 14:03 CDT 
-# Last configured: 2017-09-08 12:34 CDT  by joel
+# Last configured: 2017-09-08 15:56 CDT  by sky
 # 
 # grnoc-mon at CITY-OF-LAWTON-005231> show interface terse 
 #Interface Admin Link
@@ -230,7 +230,7 @@
 #vlan up down
 #vtep up up
 # grnoc-mon at CITY-OF-LAWTON-005231> show configuration 
-## Last commit: 2017-09-08 12:34:32 CDT by joel
+## Last commit: 2017-09-08 15:56:50 CDT by sky
 version 15.1X49-D90.7;
 groups {
     ABUSE-DENY {
@@ -2256,34 +2256,34 @@
                     source-address TR-0100-USERS-10.1.0.0/16;
                 }
             }
-            policy COMMON-APPLICATIONS {
+            policy TEMPORARY-BLOCK-INTERNET-TO-LAWTONPD {
                 match {
-                    source-address TR-0100-USERS-10.1.0.0/16;
-                }
-            }
-            policy LAWTONPD-TO-OLETS {
-                match {
                     source-address LAWTONPD;
                     destination-address any;
-                    application IPSEC;
+                    application [ NON-STANDARD-WEB junos-http junos-https ];
                 }
                 then {
-                    permit;
+                    reject;
                     log {
-                        session-init;
                         session-close;
                     }
                 }
             }
-            policy TEMPORARY-BLOCK-INTERNET-TO-LAWTONPD {
+            policy COMMON-APPLICATIONS {
                 match {
+                    source-address TR-0100-USERS-10.1.0.0/16;
+                }
+            }
+            policy LAWTONPD-TO-OLETS {
+                match {
                     source-address LAWTONPD;
                     destination-address any;
-                    application [ NON-STANDARD-WEB junos-http junos-https ];
+                    application IPSEC;
                 }
                 then {
-                    reject;
+                    permit;
                     log {
+                        session-init;
                         session-close;
                     }
                 }
Index: configs/odot-bartlesville-regmaint.client.onenet.net
===================================================================
--- configs/odot-bartlesville-regmaint.client.onenet.net	(revision 156425)
+++ configs/odot-bartlesville-regmaint.client.onenet.net	(working copy)
@@ -138,8 +138,8 @@
 #ge-0/0/4.0 up down
 #ge-0/0/5 up down
 #ge-0/0/5.0 up down
-#ge-0/0/6 up up
-#ge-0/0/6.0 up up
+#ge-0/0/6 up down
+#ge-0/0/6.0 up down
 #ge-0/0/7 up up
 #ge-0/0/7.0 up up
 #t1-1/0/0 up up



More information about the Nocrancid mailing list