Building configuration... Current configuration : 19854 bytes ! ! Last configuration change at 16:18:28 MDT Wed Jul 31 2019 by micahc_adm ! NVRAM config last updated at 16:22:56 MDT Wed Jul 31 2019 by micahc_adm ! version 15.4 service nagle no service pad service tcp-keepalives-in service tcp-keepalives-out service timestamps debug datetime msec localtime show-timezone service timestamps log datetime msec localtime show-timezone service password-encryption ! hostname jdld-1433-mdf1-rte1 ! boot-start-marker boot system flash0:c3900e-universalk9-mz.SPA.154-3.M4.bin boot-end-marker ! ! card type t1 0 0 logging buffered 16384 no logging console no logging monitor ! aaa new-model ! ! aaa group server radius radius-group server-private 172.31.0.129 auth-port 1812 acct-port 1813 key 0 (15(0 server-private 172.31.2.129 auth-port 1812 acct-port 1813 key 0 (15(0 ! aaa authentication login default group radius-group aaa authentication login CONSOLE local-case aaa authentication enable default group radius-group aaa accounting exec default stop-only group radius-group aaa accounting network default stop-only group radius-group ! ! ! ! ! aaa session-id common clock timezone MST -7 0 clock summer-time MDT recurring ! network-clock-participate wic 0 network-clock-select 1 T1 0/0/0 ! ! ! ! ! no ip source-route no ip gratuitous-arps ip icmp rate-limit unreachable 2000 ip icmp rate-limit unreachable DF 2000 ip spd mode aggressive ! ! ! ! ! ip dhcp excluded-address 10.66.38.65 ip dhcp excluded-address 10.66.38.68 10.66.38.71 ! ip dhcp pool Vendor_OOB network 10.66.38.64 255.255.255.248 default-router 10.66.38.65 domain-name cnrl.com ! ip dhcp pool DAS-BGW-ILO host 10.66.38.66 255.255.255.0 hardware-address 0cc4.7a08.5b13 default-router 10.66.38.65 ! ip dhcp pool DAS-BGW-DELTA-NODE host 10.66.38.67 255.255.255.0 hardware-address 0cc4.7a08.5cf4 default-router 10.66.38.65 ! ! ! no ip bootp server no ip domain lookup ip domain name cnrl.com ip cef login block-for 100 attempts 15 within 100 login quiet-mode access-class 101 login on-failure log login on-success log no ipv6 source-route ipv6 unicast-routing ipv6 cef ! ! multilink bundle-name authenticated ! ! ! ! ! cts logging verbose ! ! voice-card 0 ! ! ! ! ! ! ! ! license udi pid C3900-SPE250/K9 sn FOC16434X3S license boot module c3900e technology-package datak9 ! ! hw-module pvdm 0/0 ! archive log config logging enable logging size 500 notify syslog contenttype plaintext hidekeys vtp mode transparent username admin secret 0 m?JV,>g-ha&9sn! ! redundancy ! ! ! ! ! controller T1 0/0/0 cablelength long 0db ! ip tcp selective-ack ip tcp window-size 65535 ip tcp synwait-time 5 ip tcp path-mtu-discovery age-timer 30 ! class-map match-any cmap_control match protocol bgp match protocol ospf match protocol ntp match protocol dns match protocol dhcp match ip dscp cs3 cs6 class-map match-any cmap_default description Associate Best Effort Traffic match access-group name acl_default class-map match-any cmap_video match protocol rtp video match application application-group webex-group match protocol citrix match application citrix match access-group name citrix match ip dscp af41 af42 class-map match-any cmap_voice description Voice Traffic match protocol sip match application cisco-phone match protocol rtp audio match protocol rtsp match protocol h323 match application h323 match protocol mgcp match protocol rtcp match protocol skinny match ip dscp ef class-map match-any Control match ip dscp cs3 cs6 class-map match-any Video match ip dscp af41 af42 match access-group name citrix class-map match-any Voice match ip dscp ef ! policy-map pmap_IngressClassandMark class cmap_voice set dscp ef class cmap_video set dscp af41 class cmap_control set dscp cs3 class cmap_default set dscp default policy-map WAN-CLASS class Voice police cir percent 10 priority level 1 set dscp af31 class Video police cir percent 75 priority level 2 set dscp af11 class Control set dscp af11 bandwidth remaining percent 10 class class-default queue-limit 8192 packets set dscp af11 bandwidth remaining percent 90 policy-map wan-outbound class class-default shape average percent 95 service-policy WAN-CLASS ! ! ! ! ! ! ! ! ! ! ! interface Loopback0 ip address 10.78.3.65 255.255.255.255 no ip redirects ! interface GigabitEthernet0/0/0 description jdld-1433-mdf1-swc1 G1/7/47 no ip address duplex auto speed auto no shut ! interface GigabitEthernet0/0/0.12 description jdld-1433-mdf1-swc1 G1/7/47 encapsulation dot1Q 12 ip address 10.77.33.41 255.255.255.252 no ip redirects no ip unreachables no ip proxy-arp ip nbar protocol-discovery ip flow ingress ip ospf cost 200 service-policy input pmap_IngressClassandMark ! interface GigabitEthernet0/0/1 description riverbed wccp subnet ip address 10.66.39.9 255.255.255.248 no ip redirects no ip unreachables no ip proxy-arp ip nbar protocol-discovery duplex auto speed auto service-policy input pmap_IngressClassandMark no shut ! interface GigabitEthernet0/0/2 description AXIA AX532803 bandwidth 300000 ip address 10.66.63.250 255.255.255.248 no ip redirects no ip unreachables no ip proxy-arp ip nbar protocol-discovery ip flow ingress ip flow egress duplex auto speed auto service-policy input pmap_IngressClassandMark service-policy output wan-outbound no shut ! interface GigabitEthernet0/0/3 description OOB-MGMT no ip address duplex auto speed auto no shut ! interface GigabitEthernet0/0/3.960 description Vendor_OOB encapsulation dot1Q 960 ip address 10.66.38.65 255.255.255.248 no ip redirects no ip unreachables no ip proxy-arp ip nbar protocol-discovery service-policy input pmap_IngressClassandMark no shut ! interface GigabitEthernet0/0/3.961 description OOB-MGMT-DMZ encapsulation dot1Q 961 ip address 10.66.38.49 255.255.255.240 no ip redirects no ip unreachables no ip proxy-arp ip nbar protocol-discovery service-policy input pmap_IngressClassandMark no shut ! interface GigabitEthernet0/0/3.962 description MDF-LAN encapsulation dot1Q 962 ip address 10.66.254.225 255.255.255.224 no ip redirects no ip unreachables no ip proxy-arp ip nbar protocol-discovery service-policy input pmap_IngressClassandMark no shut ! interface GigabitEthernet0/0/3.963 description MDF-VOIP encapsulation dot1Q 963 native ip address 10.66.254.193 255.255.255.224 no ip redirects no ip unreachables no ip proxy-arp ip nbar protocol-discovery service-policy input pmap_IngressClassandMark no shut ! interface GigabitEthernet0/0/3.964 description DAS Repeater Remote Access encapsulation dot1Q 964 ip address 192.168.1.1 255.255.255.0 no ip redirects no ip unreachables no ip proxy-arp ip nbar protocol-discovery service-policy input pmap_IngressClassandMark no shut ! router ospf 100 router-id 10.78.3.65 passive-interface default no passive-interface GigabitEthernet0/0.12 network 10.66.38.49 0.0.0.0 area 0 network 10.66.38.65 0.0.0.0 area 50 network 10.66.254.193 0.0.0.0 area 0 network 10.66.254.225 0.0.0.0 area 0 network 10.77.33.41 0.0.0.0 area 0 network 10.78.3.65 0.0.0.0 area 0 default-information originate metric 20 metric-type 1 ! router bgp 64901 bgp router-id 10.78.3.65 bgp log-neighbor-changes bgp update-delay 1 bgp graceful-restart restart-time 120 bgp graceful-restart stalepath-time 360 bgp graceful-restart bgp scan-time 5 network 10.65.0.0 mask 255.255.0.0 network 10.66.0.0 mask 255.255.192.0 network 10.66.0.0 mask 255.255.255.0 network 10.66.1.0 mask 255.255.255.0 network 10.66.2.0 mask 255.255.255.0 network 10.66.3.0 mask 255.255.255.0 network 10.66.4.0 mask 255.255.255.0 network 10.66.5.0 mask 255.255.255.0 network 10.66.6.0 mask 255.255.255.0 network 10.66.7.0 mask 255.255.255.0 network 10.66.8.0 mask 255.255.255.0 network 10.66.9.0 mask 255.255.255.0 network 10.66.10.0 mask 255.255.255.0 network 10.66.11.0 mask 255.255.255.0 network 10.66.12.0 mask 255.255.255.0 network 10.66.13.0 mask 255.255.255.0 network 10.66.14.0 mask 255.255.255.0 network 10.66.15.0 mask 255.255.255.0 network 10.66.16.0 mask 255.255.255.0 network 10.66.17.0 mask 255.255.255.0 network 10.66.18.0 mask 255.255.255.0 network 10.66.19.0 mask 255.255.255.0 network 10.66.20.0 mask 255.255.255.0 network 10.66.21.0 mask 255.255.255.0 network 10.66.22.0 mask 255.255.255.0 network 10.66.23.0 mask 255.255.255.0 network 10.66.24.0 mask 255.255.255.0 network 10.66.25.0 mask 255.255.255.0 network 10.66.26.0 mask 255.255.255.0 network 10.66.27.0 mask 255.255.255.0 network 10.66.28.0 mask 255.255.255.0 network 10.66.29.0 mask 255.255.255.0 network 10.66.30.0 mask 255.255.255.0 network 10.66.31.0 mask 255.255.255.0 network 10.66.32.0 mask 255.255.255.0 network 10.66.33.0 mask 255.255.255.0 network 10.66.34.0 mask 255.255.255.0 network 10.66.35.0 mask 255.255.255.0 network 10.66.37.128 mask 255.255.255.240 network 10.66.38.32 mask 255.255.255.240 network 10.66.38.48 mask 255.255.255.240 network 10.66.38.64 mask 255.255.255.248 network 10.66.38.232 mask 255.255.255.252 network 10.66.38.236 mask 255.255.255.252 network 10.66.39.0 mask 255.255.255.248 network 10.66.39.8 mask 255.255.255.248 network 10.66.39.16 mask 255.255.255.240 network 10.66.40.0 mask 255.255.248.0 network 10.66.63.248 mask 255.255.255.248 network 10.66.64.0 mask 255.255.240.0 network 10.66.73.128 mask 255.255.255.224 network 10.66.73.160 mask 255.255.255.224 network 10.66.73.192 mask 255.255.255.224 network 10.66.73.224 mask 255.255.255.224 network 10.66.74.32 mask 255.255.255.224 network 10.66.74.64 mask 255.255.255.224 network 10.66.74.96 mask 255.255.255.224 network 10.66.74.128 mask 255.255.255.224 network 10.66.74.160 mask 255.255.255.224 network 10.66.74.192 mask 255.255.255.224 network 10.66.74.224 mask 255.255.255.224 network 10.66.75.0 mask 255.255.255.224 network 10.66.76.0 mask 255.255.255.240 network 10.66.76.16 mask 255.255.255.240 network 10.66.76.32 mask 255.255.255.224 network 10.66.76.64 mask 255.255.255.240 network 10.66.79.128 mask 255.255.255.252 network 10.66.80.0 mask 255.255.240.0 network 10.66.89.0 mask 255.255.255.128 network 10.66.90.96 mask 255.255.255.224 network 10.66.90.128 mask 255.255.255.224 network 10.66.90.160 mask 255.255.255.224 network 10.66.90.192 mask 255.255.255.224 network 10.66.90.224 mask 255.255.255.224 network 10.66.91.0 mask 255.255.255.224 network 10.66.92.0 mask 255.255.255.240 network 10.66.92.16 mask 255.255.255.240 network 10.66.92.32 mask 255.255.255.224 network 10.66.92.64 mask 255.255.255.240 network 10.66.95.4 mask 255.255.255.252 network 10.66.95.8 mask 255.255.255.252 network 10.66.95.20 mask 255.255.255.252 network 10.66.95.24 mask 255.255.255.252 network 10.66.95.28 mask 255.255.255.252 network 10.66.95.32 mask 255.255.255.252 network 10.66.95.44 mask 255.255.255.252 network 10.66.96.0 mask 255.255.240.0 network 10.66.106.192 mask 255.255.255.224 network 10.66.106.224 mask 255.255.255.224 network 10.66.107.0 mask 255.255.255.240 network 10.66.107.16 mask 255.255.255.240 network 10.66.107.32 mask 255.255.255.240 network 10.66.107.64 mask 255.255.255.240 network 10.66.111.4 mask 255.255.255.252 route-map manual-to-bgp network 10.66.111.8 mask 255.255.255.252 network 10.66.111.12 mask 255.255.255.252 network 10.66.112.0 mask 255.255.240.0 network 10.66.224.0 mask 255.255.248.0 network 10.66.231.0 mask 255.255.255.240 network 10.66.231.16 mask 255.255.255.240 network 10.66.231.64 mask 255.255.255.240 network 10.66.232.0 mask 255.255.248.0 network 10.66.254.0 mask 255.255.255.252 network 10.66.254.4 mask 255.255.255.252 network 10.66.254.8 mask 255.255.255.252 network 10.66.254.12 mask 255.255.255.252 network 10.66.254.16 mask 255.255.255.252 network 10.66.254.20 mask 255.255.255.252 network 10.66.254.24 mask 255.255.255.252 network 10.66.254.28 mask 255.255.255.252 network 10.66.254.32 mask 255.255.255.252 network 10.66.254.88 mask 255.255.255.252 network 10.66.254.192 mask 255.255.255.224 network 10.66.254.224 mask 255.255.255.224 network 10.66.255.17 mask 255.255.255.255 network 10.66.255.18 mask 255.255.255.255 network 10.66.255.19 mask 255.255.255.255 network 10.66.255.20 mask 255.255.255.255 network 10.66.255.21 mask 255.255.255.255 network 10.66.255.24 mask 255.255.255.255 network 10.66.255.25 mask 255.255.255.255 network 10.66.255.26 mask 255.255.255.255 network 10.66.255.27 mask 255.255.255.255 network 10.66.255.28 mask 255.255.255.255 network 10.66.255.29 mask 255.255.255.255 network 10.66.255.30 mask 255.255.255.255 network 10.66.255.31 mask 255.255.255.255 network 10.66.255.33 mask 255.255.255.255 network 10.66.255.34 mask 255.255.255.255 network 10.66.255.36 mask 255.255.255.255 network 10.66.255.38 mask 255.255.255.255 network 10.66.255.39 mask 255.255.255.255 network 10.66.255.40 mask 255.255.255.255 network 10.66.255.41 mask 255.255.255.255 network 10.66.255.42 mask 255.255.255.255 network 10.66.255.43 mask 255.255.255.255 network 10.66.255.44 mask 255.255.255.255 network 10.66.255.45 mask 255.255.255.255 network 10.66.255.46 mask 255.255.255.255 network 10.66.255.48 mask 255.255.255.255 network 10.66.255.49 mask 255.255.255.255 network 10.66.255.51 mask 255.255.255.255 network 10.66.255.52 mask 255.255.255.255 network 10.66.255.53 mask 255.255.255.255 network 10.66.255.61 mask 255.255.255.255 network 10.66.255.62 mask 255.255.255.255 network 10.66.255.63 mask 255.255.255.255 network 10.66.255.70 mask 255.255.255.255 network 10.66.255.74 mask 255.255.255.255 network 10.66.255.75 mask 255.255.255.255 network 10.66.255.76 mask 255.255.255.255 network 10.66.255.77 mask 255.255.255.255 network 10.66.255.78 mask 255.255.255.255 network 10.66.255.79 mask 255.255.255.255 network 10.66.255.91 mask 255.255.255.255 network 10.66.255.255 mask 255.255.255.255 network 10.67.64.0 mask 255.255.252.0 network 10.74.3.0 mask 255.255.255.224 network 10.74.14.0 mask 255.255.255.0 network 10.74.16.0 mask 255.255.255.0 network 10.74.50.0 mask 255.255.255.0 network 10.74.164.0 mask 255.255.255.0 network 10.74.165.0 mask 255.255.255.0 network 10.74.166.0 mask 255.255.255.0 network 10.74.167.0 mask 255.255.255.0 network 10.74.180.128 mask 255.255.255.192 network 10.74.180.192 mask 255.255.255.192 network 10.74.181.0 mask 255.255.255.0 network 10.74.182.0 mask 255.255.255.0 network 10.74.183.0 mask 255.255.255.0 network 10.74.184.0 mask 255.255.255.0 network 10.74.219.64 mask 255.255.255.192 network 10.74.250.56 mask 255.255.255.248 network 10.74.250.64 mask 255.255.255.248 network 10.75.45.0 mask 255.255.255.0 network 10.77.16.0 mask 255.255.240.0 network 10.77.17.96 mask 255.255.255.240 network 10.77.17.112 mask 255.255.255.248 network 10.77.21.0 mask 255.255.255.0 network 10.77.29.0 mask 255.255.255.0 network 10.77.30.0 mask 255.255.255.0 network 10.77.32.0 mask 255.255.224.0 network 10.77.33.0 mask 255.255.255.248 network 10.77.33.8 mask 255.255.255.248 network 10.77.33.16 mask 255.255.255.248 network 10.77.33.24 mask 255.255.255.248 network 10.77.33.40 mask 255.255.255.252 network 10.77.39.0 mask 255.255.255.0 network 10.77.39.0 mask 255.255.255.192 network 10.77.39.64 mask 255.255.255.192 network 10.77.39.128 mask 255.255.255.224 network 10.77.39.192 mask 255.255.255.224 network 10.77.40.0 mask 255.255.255.0 network 10.77.41.0 mask 255.255.255.0 network 10.77.41.0 mask 255.255.255.240 network 10.77.41.16 mask 255.255.255.240 network 10.77.41.48 mask 255.255.255.240 network 10.77.41.240 mask 255.255.255.240 network 10.77.42.96 mask 255.255.255.224 network 10.77.42.192 mask 255.255.255.240 network 10.77.44.0 mask 255.255.252.0 network 10.77.64.0 mask 255.255.240.0 network 10.77.65.40 mask 255.255.255.252 route-map manual-to-bgp network 10.77.65.144 mask 255.255.255.240 network 10.77.73.96 mask 255.255.255.224 network 10.77.73.192 mask 255.255.255.240 network 10.77.80.0 mask 255.255.240.0 network 10.77.96.0 mask 255.255.224.0 network 10.78.3.32 mask 255.255.255.255 network 10.78.3.63 mask 255.255.255.255 route-map manual-to-bgp network 10.78.3.64 mask 255.255.255.255 network 10.78.3.65 mask 255.255.255.255 network 10.78.3.202 mask 255.255.255.255 network 10.78.3.203 mask 255.255.255.255 network 10.78.3.204 mask 255.255.255.255 network 10.78.3.205 mask 255.255.255.255 network 10.78.4.0 mask 255.255.252.0 network 10.78.4.8 mask 255.255.255.248 network 10.96.2.32 mask 255.255.255.224 network 10.96.2.64 mask 255.255.255.224 neighbor 10.66.63.249 remote-as 64512 neighbor 10.66.63.249 password 7 101B5A4B5D4741 neighbor 10.66.63.249 timers 7 21 neighbor 10.66.63.249 advertisement-interval 0 neighbor 10.66.63.249 prefix-list default_only in neighbor 10.66.63.249 route-map out-networks out ! no ip forward-protocol nd ! ip bgp-community new-format ip community-list 1 permit 64901:100 ip community-list 2 permit 64901:200 no ip http server no ip http secure-server ! ip ssh version 2 ! ip access-list extended acl_default remark Bulk Best Effort Data Traffic permit ip any any ip access-list extended citrix permit udp any any eq 2598 permit udp any eq 2598 any permit udp any range 16500 16509 any range 16500 16509 ! ! ip prefix-list default_only description Only allow default route ip prefix-list default_only seq 100 permit 0.0.0.0/0 logging trap debugging logging facility local5 logging source-interface Loopback0 logging host 172.31.71.253 ! nls resp-timeout 1 cpd cr-id 1 route-map out-networks permit 100 match community 1 ! route-map out-networks permit 200 match community 2 set as-path prepend 64901 64901 64901 ! route-map out-networks permit 300 ! route-map manual-to-bgp permit 10 set community 64901:200 ! ! snmp-server community arctic RO 20 snmp-server community forest RW 20 snmp-server community d.W_QJW-].m1 RW 21 access-list 10 remark NTP Access ACL access-list 10 permit 172.31.255.253 access-list 10 permit 172.31.255.254 access-list 20 remark SNMP ACL access-list 20 permit 172.31.207.0 0.0.0.63 access-list 21 remark NAC SNMP ACL access-list 21 permit 172.31.4.16 access-list 21 permit 172.31.4.15 access-list 21 permit 172.31.193.202 access-list 21 permit 172.31.64.15 access-list 100 remark VTY Access ACL access-list 100 permit tcp 172.31.145.0 0.0.0.255 any range 22 telnet access-list 100 permit tcp 172.31.207.0 0.0.0.63 any range 22 telnet access-list 100 permit tcp 172.31.207.0 0.0.0.31 any range 22 telnet ! ! ! control-plane ! ! ! ! ! ! mgcp behavior rsip-range tgcp-only mgcp behavior comedia-role none mgcp behavior comedia-check-media-src disable mgcp behavior comedia-sdp-force disable ! mgcp profile default ! ! ! ! ! ! ! gatekeeper shutdown ! ! no vstack banner exec ^C *****************************SYSTEM DESCRIPTION********************* * * NAME: jdld-1433-mdf1-rte1 * LOCATION: Jackfish District Lodge MDF * CORPORATION: Devon Canada Corporation * SITE CONTACT: Enterprise Network Services * DESCRIPTION: C3900-SPE250/K9 * NOTES: JDL Edge Router * ******************************************************************** ^C banner motd ^C *****************************SECURITY NOTICE************************ * * ACCESS TO THIS SYSTEM IS RESTRICTED TO AUTHORIZED PERSONNEL ONLY * USAGE OF THIS SYSTEM MAY BE LOGGED AND/OR MONITORED WITHOUT NOTICE. * DISCONNECT IMMEDIATELY IF YOU ARE NOT AN AUTHORIZED USER! * ******************************************************************** ^C ! line con 0 exec-timeout 15 0 privilege level 15 login authentication CONSOLE transport output none line aux 0 line vty 0 4 access-class 100 in exec-timeout 15 0 transport input telnet ssh line vty 5 15 access-class 100 in exec-timeout 15 0 transport input telnet ssh ! scheduler allocate 20000 1000 ntp source Loopback0 ntp access-group peer 10 ntp server 172.31.255.253 ntp server 172.31.255.254 ! end