versions / Diff version 1 - 0 for Node 172.31.254.219

Date of version: 14-02-24 at 01:43:34 PM
Number of lines changed: added 1013 removed 0
Version ()
Version 1 (164 days 16 hours ago)
diff --git a/172.31.254.219 b/172.31.254.219
new file mode 100644
index 0000000..c20eb2a
--- /dev/null
@@ -0,0 +1,1013 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
diff --git a/172.31.254.219 b/172.31.254.219
new file mode 100644
index 0000000..c20eb2a
+++ b/172.31.254.219
@@ -0,0 +1,1013 @@
+# Hostname: BA-IBP-ACX2100-IBIRAPUA
+# Model: acx2100
+# Junos: 19.4R3.11
+# JUNOS Base OS boot [19.4R3.11]
+# JUNOS Base OS Software Suite [19.4R3.11]
+# JUNOS Crypto Software Suite [19.4R3.11]
+# JUNOS Packet Forwarding Engine Support (ACX) [19.4R3.11]
+# JUNOS Web Management [19.4R3.11]
+# JUNOS Online Documentation [19.4R3.11]
+# JUNOS SDN Software Suite [19.4R3.11]
+# JUNOS Services Application Level Gateways [19.4R3.11]
+# JUNOS Services COS [19.4R3.11]
+# JUNOS Services Jflow Container package [19.4R3.11]
+# JUNOS Services Stateful Firewall [19.4R3.11]
+# JUNOS Services NAT [19.4R3.11]
+# JUNOS Services RPM [19.4R3.11]
+# JUNOS Services SOFTWIRE [19.4R3.11]
+# JUNOS Services Captive Portal and Content Delivery Container package [19.4R3.11]
+# JUNOS Macsec Software Suite [19.4R3.11]
+# JUNOS Services Crypto [19.4R3.11]
+# JUNOS Services IPSec [19.4R3.11]
+# JUNOS Services RTCOM [19.4R3.11]
+# JUNOS Services SSL [19.4R3.11]
+# JUNOS Services TCP-LOG [19.4R3.11]
+# JUNOS DP Crypto Software Software Suite [19.4R3.11]
+# JUNOS py-base-powerpc [19.4R3.11]
+# JUNOS py-base2-powerpc [19.4R3.11]
+# JUNOS py-extensions-powerpc [19.4R3.11]
+# JUNOS py-extensions2-powerpc [19.4R3.11]
+# JUNOS jsd [powerpc-19.4R3.11-jet-1]
+# JUNOS Kernel Software Suite [19.4R3.11]
+# JUNOS Routing Software Suite [19.4R3.11]
+# Hardware inventory:
+# Item Version Part number Serial number Description
+# Chassis NK0214200123 ACX2100
+# Midplane REV 10 650-045221 NK0214200123 ACX2100
+# Routing Engine BUILTIN BUILTIN Routing Engine
+# FEB 0 BUILTIN BUILTIN Forwarding Engine Processor
+# FPC 0 BUILTIN BUILTIN FPC BUILTIN
+# MIC 0 BUILTIN BUILTIN 16x CHE1T1, RJ48
+# PIC 0 BUILTIN BUILTIN 16x CHE1T1, RJ48
+# FPC 1 BUILTIN BUILTIN FPC BUILTIN
+# MIC 0 BUILTIN BUILTIN 4x 1GE(LAN) RJ45
+# PIC 0 BUILTIN BUILTIN 4x 1GE(LAN) RJ45
+# MIC 1 BUILTIN BUILTIN 4x 1GE(LAN) SFP, RJ45
+# PIC 1 BUILTIN BUILTIN 4x 1GE(LAN) SFP, RJ45
+# Xcvr 2 REV 01 740-011782 p224w2pt0563 SFP-SX
+# MIC 2 BUILTIN BUILTIN 2x 1GE(LAN) SFP
+# PIC 2 BUILTIN BUILTIN 2x 1GE(LAN) SFP
+# Xcvr 0 REV 01 740-021308 b2duairj0030 SFP+-10G-SR
+# Xcvr 1 REV 01 740-011782 z2fhj24n0307 SFP-SX
+# MIC 3 BUILTIN BUILTIN 2x 10GE(LAN) SFP+
+# PIC 3 BUILTIN BUILTIN 2x 10GE(LAN) SFP+
+# License usage: none
+#
+# Licenses installed: none
+#
+## Last commit: 2024-01-25 16:59:50 GMT+3 by wilson
+version 19.4R3.11;
+groups {
+ OSPF-BFD {
+ protocols {
+ ospf {
+ area <*> {
+ interface <*> {
+ bfd-liveness-detection {
+ minimum-interval 1000;
+ multiplier 4;
+ full-neighbors-only;
+ }
+ }
+ }
+ }
+ }
+ }
+}
+system {
+ host-name BA-IBP-ACX2100-IBIRAPUA;
+ root-authentication {
+ encrypted-password "$5$8oSOQjvX$et1nd.2tIqfpmBqp9AZIQRJpp7eBJ5FhRrwCP6Gp7Z7"; ## SECRET-DATA
+ }
+ login {
+ class CGR {
+ idle-timeout 2;
+ permissions [ configure view view-configuration ];
+ allow-commands "(quit)|(configure)|(show .*)|(ping .*)|(traceroute .*)|(commit .*)";
+ deny-commands .*;
+ allow-configuration "(interfaces)|(vlans)|(delete .*)|(set .*)";
+ }
+ user OP {
+ full-name "Usuario Operador";
+ uid 2008;
+ class CGR;
+ }
+ user RO {
+ full-name "Usuario Read Only";
+ uid 2009;
+ class read-only;
+ }
+ user SU {
+ full-name "Usuario Super User";
+ uid 2010;
+ class super-user;
+ }
+ user wkve {
+ full-name "Usuario Wkve Telecom";
+ uid 2002;
+ class super-user;
+ authentication {
+ encrypted-password "$5$Tsp3kqqo$fnkypxgRXRNvfU1vpNwWxJOcACAcP13zamlgcuOdm.8"; ## SECRET-DATA
+ }
+ }
+ }
+ services {
+ ssh {
+ root-login deny;
+ no-tcp-forwarding;
+ protocol-version v2;
+ }
+ }
+ domain-name wkve.net.br;
+ time-zone GMT+3;
+ debugger-on-panic;
+ debugger-on-break;
+ dump-on-panic;
+ authentication-order radius;
+ name-server {
+ 177.8.8.8;
+ 177.8.8.9;
+ }
+ radius-server {
+ 189.76.208.98 {
+ port 1840;
+ accounting-port 1841;
+ secret "$9$BACIyK8X-Vs2vWGDkqzFSre"; ## SECRET-DATA
+ timeout 15;
+ source-address 172.31.254.219;
+ }
+ }
+ accounting {
+ events [ login change-log interactive-commands ];
+ destination {
+ radius;
+ }
+ }
+ syslog {
+ user * {
+ any emergency;
+ }
+ host 189.76.208.85 {
+ any notice;
+ kernel info;
+ firewall info;
+ pfe info;
+ interactive-commands any;
+ }
+ file messages {
+ any notice;
+ authorization info;
+ match "!(.*mld6_input.*)";
+ }
+ file interactive-commands {
+ interactive-commands any;
+ }
+ }
+ ntp {
+ server 189.76.208.72;
+ source-address 172.31.254.219;
+ }
+}
+chassis {
+ dump-on-panic;
+ aggregated-devices {
+ ethernet {
+ device-count 2;
+ }
+ }
+ fpc 0 {
+ pic 0 {
+ tunnel-services {
+ bandwidth 1g;
+ }
+ }
+ pic 1 {
+ tunnel-services {
+ bandwidth 10g;
+ }
+ }
+ }
+ alarm {
+ management-ethernet {
+ link-down ignore;
+ }
+ }
+}
+services {
+ rpm {
+ probe RPM_BA-MUI-MK-SUZANO.CPD {
+ test icmp {
+ probe-type icmp-ping;
+ target address 172.16.252.247;
+ probe-count 15;
+ probe-interval 1;
+ test-interval 15;
+ source-address 172.31.254.219;
+ data-size 64;
+ thresholds {
+ successive-loss 2;
+ }
+ }
+ }
+ }
+}
+interfaces {
+ ge-1/0/0 {
+ description "INTERFACE - SWITCH DELL6224 IBIRAPUA/IBP - 1/g1";
+ link-mode full-duplex;
+ gigether-options {
+ 802.3ad ae1;
+ }
+ }
+ ge-1/0/1 {
+ description "INTERFACE - SWITCH DELL6224 IBIRAPUA/IBP - 1/g2";
+ link-mode full-duplex;
+ gigether-options {
+ 802.3ad ae1;
+ }
+ }
+ ge-1/0/2 {
+ description "INTERFACE - ROUTERBOARD IBIRAPUA/BA - ether1";
+ vlan-tagging;
+ mtu 9000;
+ link-mode full-duplex;
+ encapsulation flexible-ethernet-services;
+ unit 1301 {
+ description "VLAN 1301 - PEER BA-IBP-MK-IBIRAPUA";
+ vlan-id 1301;
+ statistics;
+ family inet {
+ mtu 1500;
+ address 172.16.194.17/30;
+ }
+ }
+ }
+ ge-1/1/2 {
+ description "INTERFACE - CERAGON IP10 - REP ITABATA/BA";
+ vlan-tagging;
+ mtu 9000;
+ link-mode full-duplex;
+ unit 1320 {
+ description "VLAN 1320 - PEER BA-MUI-MK-REP.ITABATA - VIA IBP/MUI";
+ vlan-id 1320;
+ family inet {
+ mtu 1500;
+ address 172.16.252.49/30;
+ }
+ }
+ unit 1321 {
+ description "VLAN 1321 - PEER BA-MUI-MK-REP.SUZANO - VIA IBP/MUI";
+ vlan-id 1321;
+ family inet {
+ mtu 1500;
+ address 172.16.252.61/30;
+ }
+ }
+ }
+ ge-1/1/3 {
+ mtu 9000;
+ }
+ ge-1/2/0 {
+ description "INTERFACE - CERAGON IP20C - CARLOS CHAGAS/MG";
+ flexible-vlan-tagging;
+ mtu 9000;
+ link-mode full-duplex;
+ unit 212 {
+ description "VLAN 212 - MG-IBP-ACX2100-DERRIBADINHA - VIA CERAGONIP20C IBP/CCH";
+ vlan-id 212;
+ statistics;
+ family inet {
+ mtu 1600;
+ address 172.30.0.182/30;
+ }
+ family mpls {
+ ##
+ ## Warning: statement ignored: unsupported platform (acx2100)
+ ##
+ mtu 1600;
+ }
+ }
+ unit 1201 {
+ description "VLAN 1201 - CERAGON IP20C - CARLOS CHAGAS/MG";
+ vlan-id 1201;
+ family inet {
+ mtu 1600;
+ address 172.16.102.153/30;
+ }
+ }
+ }
+ ge-1/2/1 {
+ description "INTERFACE - SIAE 2+0 - NANUQUE/NNE";
+ vlan-tagging;
+ mtu 9192;
+ link-mode full-duplex;
+ encapsulation flexible-ethernet-services;
+ unit 510 {
+ description "VLAN 510 - MG-NNE-MK-NANUQUE - VIA SIAE 2+0 IBP/NNE";
+ vlan-id 510;
+ family inet {
+ mtu 9160;
+ address 172.30.1.89/30;
+ }
+ }
+ }
+ ae1 {
+ description "LACP - SWITCH DELL6224 IBIRAPUA/IBP";
+ flexible-vlan-tagging;
+ encapsulation flexible-ethernet-services;
+ aggregated-ether-options {
+ minimum-links 1;
+ link-speed 1g;
+ lacp {
+ active;
+ }
+ }
+ unit 1300 {
+ description "VLAN 1300 - ADM BA-IBP-D6224-IBIRAPUA";
+ vlan-id 1300;
+ family inet {
+ mtu 1500;
+ address 172.16.255.237/30;
+ }
+ }
+ unit 1311 {
+ description "VLAN 1311 - PEER BA-MSN-MK-MNETO - VIA R5";
+ vlan-id 1311;
+ family inet {
+ mtu 1500;
+ address 172.16.253.173/30;
+ }
+ }
+ }
+ fxp0 {
+ description "GERENCIA LOCAL - JUNIPER ACX2200";
+ unit 0 {
+ family inet {
+ address 192.168.1.1/24;
+ }
+ }
+ }
+ lo0 {
+ unit 255 {
+ description "LOOPBACK - AREA BACKBONE";
+ family inet {
+ primary;
+ filter {
+ input PROTECT-RE;
+ }
+ address 172.31.254.219/32;
+ }
+ }
+ }
+}
+snmp {
+ description BA-IBP-ACX2100-IBIRAPUA;
+ contact "cgr@wkve.com.br";
+ community cilbup {
+ authorization read-only;
+ clients {
+ 189.76.208.0/24;
+ }
+ }
+}
+forwarding-options {
+ hash-key {
+ family inet {
+ layer-3;
+ layer-4;
+ }
+ family mpls {
+ label-1;
+ label-2;
+ label-3;
+ payload {
+ ip;
+ }
+ }
+ }
+}
+policy-options {
+ prefix-list localhost {
+ 127.0.0.0/8;
+ }
+ prefix-list ntp-servers {
+ apply-path "system ntp server <*>";
+ }
+ prefix-list NetworkBGP-Prefixes {
+ 172.16.102.152/30;
+ 172.16.255.0/28;
+ 172.16.255.32/28;
+ 172.16.255.236/30;
+ }
+ prefix-list NetworkBGPv6-Prefixes;
+ policy-statement Default-originate {
+ term gateway {
+ from {
+ route-filter 0.0.0.0/0 exact;
+ }
+ then {
+ next-hop self;
+ accept;
+ }
+ }
+ then next policy;
+ }
+ policy-statement Discard-All {
+ term implicit-deny {
+ then reject;
+ }
+ }
+ policy-statement ECMP {
+ term area-0 {
+ from {
+ protocol direct;
+ area 0.0.0.0;
+ }
+ then accept;
+ }
+ term area-24 {
+ from {
+ protocol direct;
+ area 0.0.0.24;
+ }
+ then accept;
+ }
+ then {
+ load-balance per-packet;
+ }
+ }
+ policy-statement EXPORT-LDP {
+ term ACCEPT-LOOPBACK {
+ from {
+ route-filter 189.76.208.0/24 prefix-length-range /32-/32;
+ route-filter 177.8.16.0/23 prefix-length-range /32-/32;
+ route-filter 172.31.255.0/24 prefix-length-range /32-/32;
+ route-filter 172.31.254.0/24 prefix-length-range /32-/32;
+ route-filter 172.31.253.0/24 prefix-length-range /32-/32;
+ }
+ then accept;
+ }
+ term DENY-ALL {
+ then reject;
+ }
+ }
+ policy-statement IMPORT-LDP {
+ term ACCEPT-LOOPBACK {
+ from {
+ route-filter 189.76.208.0/24 prefix-length-range /32-/32;
+ route-filter 177.8.16.0/23 prefix-length-range /32-/32;
+ route-filter 172.31.255.0/24 prefix-length-range /32-/32;
+ route-filter 172.31.254.0/24 prefix-length-range /32-/32;
+ route-filter 172.31.253.0/24 prefix-length-range /32-/32;
+ }
+ then accept;
+ }
+ term DENY-ALL {
+ then reject;
+ }
+ }
+ policy-statement IN-RR {
+ then accept;
+ }
+ policy-statement IN-iBGP-IPv4-WKVE {
+ term PERMIT-PREFIX-ASLOCAL {
+ from {
+ protocol bgp;
+ as-path local-as;
+ }
+ then accept;
+ }
+ then reject;
+ }
+ policy-statement Next-hop-self {
+ term all {
+ from {
+ external;
+ }
+ then {
+ next-hop self;
+ }
+ }
+ }
+ policy-statement OUT-RR {
+ term DIRECT-V4 {
+ from {
+ family inet;
+ protocol direct;
+ prefix-list NetworkBGP-Prefixes;
+ }
+ then accept;
+ }
+ term DIRECT-V6 {
+ from {
+ family inet6;
+ protocol direct;
+ prefix-list NetworkBGPv6-Prefixes;
+ }
+ then accept;
+ }
+ term STATIC-V4 {
+ from {
+ family inet;
+ protocol static;
+ prefix-list NetworkBGP-Prefixes;
+ }
+ then accept;
+ }
+ term STATIC-V6 {
+ from {
+ family inet6;
+ protocol static;
+ prefix-list NetworkBGPv6-Prefixes;
+ }
+ then accept;
+ }
+ term ASPATH-LOCAL {
+ from {
+ protocol bgp;
+ as-path local-as;
+ }
+ then accept;
+ }
+ term CLIENTES {
+ from community COMMUNITY-CLIENTES;
+ then accept;
+ }
+ term GERENCIA {
+ from community COMMUNITY-GERENCIA;
+ then accept;
+ }
+ term ISP-TRANSIT {
+ from community COMMUNITY-ISPs;
+ then accept;
+ }
+ term ISP-CDN {
+ from community COMMUNITY-ISP-CDNs;
+ then accept;
+ }
+ term VPN-V4 {
+ from family inet-vpn;
+ then accept;
+ }
+ term VPN-V6 {
+ from family inet6-vpn;
+ then accept;
+ }
+ then reject;
+ }
+ policy-statement OUT-iBGP-IPv4-WKVE {
+ term export-bgp {
+ from {
+ protocol bgp;
+ as-path local-as;
+ }
+ then accept;
+ }
+ term export-static {
+ from protocol static;
+ then {
+ next-hop self;
+ accept;
+ }
+ }
+ term export-networks {
+ from {
+ protocol direct;
+ prefix-list NetworkBGP-Prefixes;
+ }
+ then accept;
+ }
+ term export-downstream {
+ from community COMMUNITY-ISPs;
+ then accept;
+ }
+ then reject;
+ }
+ policy-statement explicit-deny {
+ then reject;
+ }
+ community 28360:6 members 28360:6;
+ community COMMUNITY-ALL members *:*;
+ community COMMUNITY-CLIENTES members 28360:1010;
+ community COMMUNITY-GERENCIA members 28360:1019;
+ community COMMUNITY-ISP-CDNs members 28360:15;
+ community COMMUNITY-ISPs members 28360:10;
+ community no-export members no-export;
+ as-path local-as "()";
+}
+firewall {
+ family inet {
+ filter PROTECT-RE {
+ interface-specific;
+ term aceita-bgp-src {
+ from {
+ source-address {
+ 177.8.0.0/20;
+ 177.8.16.0/20;
+ 189.76.208.0/20;
+ 189.76.224.0/20;
+ 179.124.224.0/20;
+ 138.94.8.0/22;
+ 172.16.0.0/12;
+ 10.0.0.0/8;
+ }
+ protocol tcp;
+ source-port bgp;
+ }
+ then accept;
+ }
+ term aceita-bgp-dst {
+ from {
+ source-address {
+ 177.8.0.0/20;
+ 177.8.16.0/20;
+ 189.76.208.0/20;
+ 189.76.224.0/20;
+ 179.124.224.0/20;
+ 138.94.8.0/22;
+ 172.16.0.0/12;
+ 10.0.0.0/8;
+ }
+ protocol tcp;
+ destination-port bgp;
+ }
+ then accept;
+ }
+ term aceita-ospf {
+ from {
+ protocol ospf;
+ }
+ then accept;
+ }
+ term aceita-bfd {
+ from {
+ source-address {
+ 172.16.0.0/12;
+ 10.0.0.0/8;
+ }
+ destination-address {
+ 172.16.0.0/12;
+ 10.0.0.0/8;
+ }
+ protocol udp;
+ ##
+ ## Warning: value port ignored: unsupported platform (acx2100)
+ ##
+ port [ 4784 3784 3785 ];
+ }
+ then accept;
+ }
+ term aceita-rsvp {
+ from {
+ protocol rsvp;
+ }
+ then accept;
+ }
+ term aceita-dst-ldp {
+ from {
+ destination-address {
+ 224.0.0.2/32;
+ 224.0.0.6/32;
+ 172.31.254.219/32;
+ }
+ protocol [ udp tcp ];
+ destination-port 646;
+ }
+ then accept;
+ }
+ term aceita-src-ldp {
+ from {
+ destination-address {
+ 224.0.0.2/32;
+ 224.0.0.6/32;
+ 172.31.254.219/32;
+ }
+ protocol [ udp tcp ];
+ source-port 646;
+ }
+ then accept;
+ }
+ term aceita-lsp-ping {
+ from {
+ destination-address {
+ 172.31.254.219/32;
+ }
+ protocol [ udp tcp ];
+ source-port 3503;
+ }
+ then accept;
+ }
+ term aceita-snmp {
+ from {
+ source-address {
+ 189.76.208.0/24;
+ }
+ protocol udp;
+ destination-port 161;
+ }
+ then {
+ policer limit-1m;
+ accept;
+ }
+ }
+ term radius {
+ from {
+ source-address {
+ 189.76.208.98/32;
+ }
+ }
+ then accept;
+ }
+ term aceita-ntp {
+ from {
+ source-address {
+ 189.76.208.72/32;
+ 172.31.254.219/32;
+ }
+ protocol udp;
+ destination-port ntp;
+ }
+ then {
+ policer limit-32k;
+ accept;
+ }
+ }
+ term aceita-dns {
+ from {
+ source-address {
+ 177.8.8.8/32;
+ 177.8.8.9/32;
+ }
+ protocol udp;
+ source-port 53;
+ }
+ }
+ term aceita-icmp {
+ from {
+ icmp-type [ echo-request echo-reply unreachable time-exceeded timestamp-reply timestamp ];
+ }
+ then {
+ policer limit-10m;
+ accept;
+ }
+ }
+ term aceita-traceroute {
+ from {
+ protocol udp;
+ destination-port 33434-33523;
+ }
+ then accept;
+ }
+ term aceita-ssh-out {
+ from {
+ protocol tcp;
+ source-port [ ssh 33 ];
+ }
+ then accept;
+ }
+ term aceita-ssh {
+ from {
+ source-address {
+ 189.76.208.0/24;
+ 189.76.214.0/24;
+ 189.76.230.0/24;
+ 189.76.223.0/24;
+ 177.8.16.0/23;
+ 192.168.1.0/24;
+ 172.16.0.0/12;
+ }
+ destination-port ssh;
+ }
+ then accept;
+ }
+ term descarta-resto {
+ then {
+ discard;
+ }
+ }
+ }
+ }
+ family any {
+ filter POLICER_150Mbps {
+ interface-specific;
+ term 1 {
+ then {
+ policer limit-150Mb;
+ accept;
+ }
+ }
+ }
+ filter POLICER_100Mbps {
+ interface-specific;
+ term 1 {
+ then {
+ policer limit-100Mb;
+ accept;
+ }
+ }
+ }
+ filter POLICER_250Mbps {
+ interface-specific;
+ term 1 {
+ then {
+ policer limit-250Mb;
+ accept;
+ }
+ }
+ }
+ }
+ policer limit-32k {
+ if-exceeding {
+ bandwidth-limit 32k;
+ burst-size-limit 15k;
+ }
+ then discard;
+ }
+ policer limit-1m {
+ if-exceeding {
+ bandwidth-limit 1m;
+ burst-size-limit 15k;
+ }
+ then discard;
+ }
+ policer limit-10m {
+ if-exceeding {
+ bandwidth-limit 10m;
+ burst-size-limit 625k;
+ }
+ then discard;
+ }
+ policer limit-150Mb {
+ if-exceeding {
+ bandwidth-limit 154m;
+ burst-size-limit 625k;
+ }
+ then discard;
+ }
+ policer limit-100Mb {
+ if-exceeding {
+ bandwidth-limit 100m;
+ burst-size-limit 625k;
+ }
+ then discard;
+ }
+ policer limit-250Mb {
+ if-exceeding {
+ bandwidth-limit 252m;
+ burst-size-limit 625k;
+ }
+ then discard;
+ }
+}
+routing-options {
+ forwarding-table {
+ export ECMP;
+ }
+ router-id 172.31.254.219;
+ autonomous-system 28360;
+}
+protocols {
+ ospf {
+ apply-groups OSPF-BFD;
+ traffic-engineering;
+ area 0.0.0.0 {
+ interface lo0.255 {
+ passive;
+ }
+ interface ge-1/0/2.0;
+ interface ge-1/0/2.1301 {
+ interface-type p2p;
+ metric 10;
+ }
+ interface ge-1/1/0.1303 {
+ interface-type p2p;
+ metric 500;
+ }
+ inactive: interface ge-1/1/0.505 {
+ interface-type p2p;
+ metric 10;
+ }
+ interface ae1.1311 {
+ interface-type p2p;
+ metric 10;
+ }
+ interface ge-1/1/2.1320 {
+ interface-type p2p;
+ metric 10;
+ }
+ interface ge-1/1/2.1321 {
+ interface-type p2p;
+ metric 10;
+ }
+ interface ge-1/2/1.510 {
+ interface-type p2p;
+ metric 10;
+ ldp-synchronization {
+ hold-time 10;
+ }
+ }
+ interface ge-1/2/0.212 {
+ interface-type p2p;
+ metric 10;
+ ldp-synchronization {
+ hold-time 10;
+ }
+ }
+ }
+ export ECMP;
+ reference-bandwidth 1g;
+ no-rfc-1583;
+ }
+ rsvp {
+ load-balance bandwidth;
+ interface ge-1/2/1.510 {
+ bandwidth 240m;
+ }
+ interface ge-1/2/0.212 {
+ bandwidth 560m;
+ }
+ interface fxp0.0 {
+ disable;
+ }
+ }
+ bgp {
+ path-selection cisco-non-deterministic;
+ group iBGP-LOOPBACK {
+ type internal;
+ local-address 172.31.254.219;
+ advertise-inactive;
+ export [ Default-originate OUT-iBGP-IPv4-WKVE ];
+ cluster 172.31.254.219;
+ peer-as 28360;
+ neighbor 172.16.194.18 {
+ description "PEER - BA-IBP-MK-IBIRAPUA";
+ }
+ neighbor 172.16.252.246 {
+ description "PEER - BA-MSN-MK-MNETO";
+ }
+ neighbor 172.16.252.245 {
+ description "PEER - BA-MSN-MK-REP.SIMONETTI";
+ }
+ neighbor 172.16.252.242 {
+ description "PEER - BA-MUI-MK-REP.ITABATA";
+ }
+ neighbor 172.16.252.241 {
+ description "PEER - BA-MUI-MK-REP.SUZANO";
+ }
+ neighbor 172.16.192.6 {
+ description "PEER - MG-NNH-MK-NANUQUE";
+ }
+ }
+ group RR {
+ type internal;
+ local-address 172.31.254.219;
+ advertise-inactive;
+ import IN-RR;
+ family inet {
+ unicast;
+ }
+ family inet-vpn {
+ unicast;
+ }
+ family inet6 {
+ labeled-unicast {
+ explicit-null;
+ }
+ }
+ family inet6-vpn {
+ unicast;
+ }
+ family l2vpn {
+ auto-discovery-only;
+ }
+ export OUT-RR;
+ peer-as 28360;
+ neighbor 172.31.254.250 {
+ description "PEER - MG-BHE-ACX2100-RREFLECTOR1";
+ }
+ neighbor 172.31.254.251 {
+ description "PEER - MG-GVS-ACX2100-RREFLECTOR2";
+ }
+ }
+ }
+ ldp {
+ track-igp-metric;
+ import IMPORT-LDP;
+ export EXPORT-LDP;
+ transport-address 172.31.254.219;
+ interface ge-1/2/0.212;
+ interface ge-1/2/1.510;
+ interface fxp0.0 {
+ disable;
+ }
+ interface lo0.255;
+ }
+ mpls {
+ interface lo0.255;
+ interface ge-1/2/0.212;
+ interface ge-1/2/1.510;
+ interface fxp0.0 {
+ disable;
+ }
+ }
+}