Realisations/2006-2007/Projet/Entreprise2/Switch: config_X450E_2007-01-24.cfg

File config_X450E_2007-01-24.cfg, 21.3 KB (added by alladoum, 18 years ago)
Line 
1#
2# Module devmgr configuration.
3#
4configure snmp sysName "X450e-24p"
5configure snmp sysContact "support@extremenetworks.com, +1 888 257 3000"
6configure slot 1 module X450e-24p
7
8#
9# Module vlan configuration.
10#
11enable mirroring to port 1 tagged
12configure vr VR-Default add ports 1-26
13configure vlan Default tag 1
14create vlan "vlan0"
15create vlan "vlan10"
16create vlan "vlan11"
17create vlan "vlan20"
18create vlan "vlan21"
19disable port 2
20disable port 6
21disable port 7
22disable port 8
23disable port 9
24disable port 10
25disable port 11
26disable port 12
27disable port 14
28disable port 18
29disable port 19
30disable port 20
31disable port 22
32disable port 23
33disable port 24
34disable port 25
35configure ports 25 auto off speed 10000 duplex full
36disable port 26
37configure ports 26 auto off speed 10000 duplex full
38configure vlan vlan0 add ports 21 untagged
39configure vlan vlan10 add ports 3 untagged
40configure vlan vlan11 add ports 4-5 untagged
41configure vlan vlan20 add ports 15 untagged
42configure vlan vlan21 add ports 16-17 untagged
43configure vlan Mgmt ipaddress 192.168.0.254 255.255.255.0
44configure vlan vlan0 ipaddress 10.34.252.9 255.255.255.252
45enable ipforwarding vlan vlan0
46configure vlan vlan10 ipaddress 10.40.0.2 255.255.255.252
47enable ipforwarding vlan vlan10
48configure vlan vlan20 ipaddress 10.40.0.6 255.255.255.252
49enable ipforwarding vlan vlan20
50configure qosscheduler strict-priority
51configure mirroring add port 3
52configure mirroring add port 15
53
54#
55# Module fdb configuration.
56#
57configure fdb agingtime 300
58configure iparp vr VR-Control max_entries 4096
59configure iparp vr VR-Control max_pending_entries 256
60configure iparp vr VR-Control max_proxy_entries 256
61configure iparp vr VR-Control timeout 20
62enable iparp vr VR-Control checking
63enable iparp vr VR-Control refresh
64configure iparp vr VR-Default max_entries 4096
65configure iparp vr VR-Default max_pending_entries 256
66configure iparp vr VR-Default max_proxy_entries 256
67configure iparp vr VR-Default timeout 20
68enable iparp vr VR-Default checking
69enable iparp vr VR-Default refresh
70configure iparp vr VR-Mgmt max_entries 4096
71configure iparp vr VR-Mgmt max_pending_entries 256
72configure iparp vr VR-Mgmt max_proxy_entries 256
73configure iparp vr VR-Mgmt timeout 20
74enable iparp vr VR-Mgmt checking
75enable iparp vr VR-Mgmt refresh
76
77#
78# Module rtmgr configuration.
79#
80disable iproute sharing
81configure iproute priority blackhole 50
82configure iproute priority static 1100
83configure iproute priority icmp 1200
84configure iproute priority ebgp 1700
85configure iproute priority ibgp 1900
86configure iproute priority ospf-intra 2200
87configure iproute priority ospf-inter 2300
88configure iproute priority rip 2400
89configure iproute priority ospf-as-external 3100
90configure iproute priority ospf-extern1 3200
91configure iproute priority ospf-extern2 3300
92configure iproute priority bootp 5000
93configure iproute ipv6 priority blackhole 50
94configure iproute ipv6 priority static 1100
95configure iproute ipv6 priority icmp 1200
96configure iproute ipv6 priority ospfv3-intra 2200
97configure iproute ipv6 priority ospfv3-inter 2300
98configure iproute ipv6 priority RIPng 2400
99configure iproute ipv6 priority ospfv3-as-external 3100
100configure iproute ipv6 priority ospfv3-extern1 3200
101configure iproute ipv6 priority ospfv3-extern2 3300
102configure irdp broadcast
103configure irdp 450 600 1800 0
104disable irdp "Mgmt"
105disable irdp "vlan0"
106disable irdp "vlan10"
107disable irdp "vlan20"
108disable icmp address-mask vlan "Mgmt"
109enable icmp parameter-problem vlan "Mgmt"
110enable icmp port-unreachables vlan "Mgmt"
111enable icmp unreachables vlan "Mgmt"
112enable icmp redirects vlan "Mgmt"
113enable icmp time-exceeded vlan "Mgmt"
114disable icmp timestamp vlan "Mgmt"
115disable icmp address-mask vlan "vlan0"
116enable icmp parameter-problem vlan "vlan0"
117enable icmp port-unreachables vlan "vlan0"
118enable icmp unreachables vlan "vlan0"
119enable icmp redirects vlan "vlan0"
120enable icmp time-exceeded vlan "vlan0"
121disable icmp timestamp vlan "vlan0"
122disable icmp address-mask vlan "vlan10"
123enable icmp parameter-problem vlan "vlan10"
124enable icmp port-unreachables vlan "vlan10"
125enable icmp unreachables vlan "vlan10"
126enable icmp redirects vlan "vlan10"
127enable icmp time-exceeded vlan "vlan10"
128disable icmp timestamp vlan "vlan10"
129disable icmp address-mask vlan "vlan20"
130enable icmp parameter-problem vlan "vlan20"
131enable icmp port-unreachables vlan "vlan20"
132enable icmp unreachables vlan "vlan20"
133enable icmp redirects vlan "vlan20"
134enable icmp time-exceeded vlan "vlan20"
135disable icmp timestamp vlan "vlan20"
136enable ip-option loose-source-route
137enable ip-option strict-source-route
138enable ip-option record-timestamp
139enable ip-option router-alert
140enable ip-option record-route
141configure iproute add 10.34.252.8 255.255.255.252 10.34.252.9 1 vr VR-Default
142configure iproute add 10.40.0.8 255.255.255.252 10.40.0.5 1 vr VR-Default
143configure iproute add 10.40.0.12 255.255.255.252 10.40.0.1 1 vr VR-Default
144disable ipforwarding broadcast vlan "Mgmt"
145disable ipforwarding broadcast vlan "vlan0"
146disable ipforwarding broadcast vlan "vlan10"
147disable ipforwarding broadcast vlan "vlan20"
148disable icmp useredirects
149
150#
151# Module mcmgr configuration.
152#
153configure igmp snooping cache 32 64
154configure igmp snooping timer 260 260 vr VR-Default
155configure igmp snooping leave-timeout 1000 vr VR-Default
156configure MLD snooping timer 260 260 vr VR-Default
157configure MLD snooping leave-timeout 1000 vr VR-Default
158disable igmp snooping forward-mcrouter-only vr VR-Default
159disable MLD snooping forward-mcrouter-only vr VR-Default
160configure igmp 125 10 1 2 vr VR-Default
161configure MLD 125 10 1 2 vr VR-Default
162enable igmp snooping with-proxy vr VR-Default
163enable MLD snooping with-proxy vr VR-Default
164configure igmp snooping flood-list none vr VR-Default
165configure MLD snooping flood-list none vr VR-Default
166disable mvr
167configure mvr vlan Default mvr-address none
168configure mvr vlan Default static group none
169configure mvr vlan vlan0 mvr-address none
170configure mvr vlan vlan0 static group none
171configure mvr vlan vlan10 mvr-address none
172configure mvr vlan vlan10 static group none
173configure mvr vlan vlan11 mvr-address none
174configure mvr vlan vlan11 static group none
175configure mvr vlan vlan20 mvr-address none
176configure mvr vlan vlan20 static group none
177configure mvr vlan vlan21 mvr-address none
178configure mvr vlan vlan21 static group none
179
180#
181# Module aaa configuration.
182#
183disable radius mgmt-access
184configure radius mgmt-access timeout 3
185disable radius-accounting mgmt-access
186configure radius-accounting mgmt-access timeout 3
187disable radius netlogin
188configure radius netlogin timeout 3
189disable radius-accounting netlogin
190configure radius-accounting netlogin timeout 3
191disable tacacs
192configure tacacs timeout 3
193disable tacacs-accounting
194configure tacacs-accounting timeout 3
195disable tacacs-authorization
196configure account admin encrypted xJLi2a$As89cP1wHfZWnBK4Hc7ct0
197configure account user encrypted sOSi2a$fEKW8rKI0Etk6Cj6QTz3O/
198
199#
200# Module acl configuration.
201#
202enable access-list refresh blackhole
203enable access-list permit to-cpu
204
205#
206# Module cfgmgr configuration.
207#
208disable cli-config-logging
209configure cli max-sessions 8
210configure cli max-failed-logins 3
211configure banner
212
213
214configure idletimeout 20
215enable idletimeout
216
217#
218# Module dosprotect configuration.
219#
220disable dos-protect
221configure dos-protect interval 1
222configure dos-protect trusted-ports ports
223configure dos-protect type l3-protect alert-threshold 4000
224configure dos-protect type l3-protect notify-threshold 3500
225
226#
227# Module eaps configuration.
228#
229configure eaps fast-convergence off
230configure eaps config-warnings on
231disable eaps
232
233#
234# Module edp configuration.
235#
236configure edp advertisement-interval 60 holddown-interval 180
237enable edp ports 1
238enable edp ports 2
239enable edp ports 3
240enable edp ports 4
241enable edp ports 5
242enable edp ports 6
243enable edp ports 7
244enable edp ports 8
245enable edp ports 9
246enable edp ports 10
247enable edp ports 11
248enable edp ports 12
249enable edp ports 13
250enable edp ports 14
251enable edp ports 15
252enable edp ports 16
253enable edp ports 17
254enable edp ports 18
255enable edp ports 19
256enable edp ports 20
257enable edp ports 21
258enable edp ports 22
259enable edp ports 23
260enable edp ports 24
261enable edp ports 25
262enable edp ports 26
263
264#
265# Module elrp configuration.
266#
267disable elrp-client
268
269#
270# Module ems configuration.
271#
272disable log debug-mode
273create log filter DefaultFilter
274configure log filter DefaultFilter add event All
275enable log target memory-buffer
276configure log target memory-buffer filter DefaultFilter severity Debug-Data
277configure log target memory-buffer match Any
278configure log target memory-buffer format timestamp hundredths date mm-dd-yyyy event-name condition severity
279configure log target memory-buffer number-of-messages 1000
280enable log target nvram
281configure log target nvram filter DefaultFilter severity Warning
282configure log target nvram match Any
283configure log target nvram format timestamp hundredths date mm-dd-yyyy event-name condition severity
284disable log target console
285configure log target console filter DefaultFilter severity Info
286configure log target console match Any
287configure log target console format timestamp hundredths date mm-dd-yyyy event-name condition severity
288
289#
290# Module epm configuration.
291#
292configure sys-recovery-level All
293enable watchdog
294configure firmware install-on-demand
295enable cpu-monitoring interval 20 threshold 60
296
297#
298# Module esrp configuration.
299#
300configure esrp mode extended
301
302#
303# Module etmon configuration.
304#
305configure sflow sample-rate 8192
306configure sflow max-cpu-sample-limit 2000
307configure sflow poll-interval 20
308disable sflow
309disable rmon
310
311#
312# Module hal configuration.
313#
314configure iproute sharing max-gateways 4
315
316#
317# Module lldp configuration.
318#
319configure lldp transmit-interval 30
320configure lldp transmit-hold 4
321configure lldp reinitialize-delay 2
322configure lldp transmit-delay 2
323configure lldp snmp-notification-interval 5
324configure lldp med fast-start repeat-count 3
325
326#
327# Module netLogin configuration.
328#
329configure netlogin dot1x timers server-timeout 30 quiet-period 60 reauth-period 3600 supp-resp-timeout 30
330configure netlogin dot1x eapol-transmit-version v1
331enable netlogin logout-privilege
332enable netlogin session-refresh 3
333configure netlogin base-url "network-access.com"
334configure netlogin redirect-page "http://www.extremenetworks.com"
335configure netlogin banner ""
336
337#
338# Module netTools configuration.
339#
340configure sntp-client update-interval 64
341disable sntp-client
342
343#
344# Module ospf configuration.
345#
346configure ospf routerid automatic
347configure ospf spf-hold-time 3
348configure ospf metric-table 10M 10 100M 5 1G 4 10G 2
349configure ospf lsa-batch-interval 30
350configure ospf import-policy none
351configure ospf ase-limit 0
352disable ospf originate-default
353disable ospf use-ip-router-alert
354disable ospf
355configure ospf restart none
356configure ospf restart grace-period 120
357disable ospf export direct
358disable ospf export static
359disable ospf export rip
360disable ospf export e-bgp
361disable ospf export i-bgp
362configure ospf area 0.0.0.0 external-filter none
363configure ospf area 0.0.0.0 interarea-filter none
364configure ospf area 0.0.0.0 normal
365configure ospf vlan vlan0 area 0.0.0.0
366configure ospf vlan vlan0 cost automatic
367configure ospf vlan vlan0 priority 0
368configure ospf vlan vlan0 authentication none
369configure ospf vlan vlan0 timer 5 1 10 40
370configure ospf vlan vlan0 restart-helper none
371enable ospf vlan vlan0 restart-helper-lsa-check
372configure ospf vlan vlan10 area 0.0.0.0
373configure ospf vlan vlan10 cost automatic
374configure ospf vlan vlan10 priority 0
375configure ospf vlan vlan10 authentication none
376configure ospf vlan vlan10 timer 5 1 10 40
377configure ospf vlan vlan10 restart-helper none
378enable ospf vlan vlan10 restart-helper-lsa-check
379configure ospf vlan vlan20 area 0.0.0.0
380configure ospf vlan vlan20 cost automatic
381configure ospf vlan vlan20 priority 0
382configure ospf vlan vlan20 authentication none
383configure ospf vlan vlan20 timer 5 1 10 40
384configure ospf vlan vlan20 restart-helper none
385enable ospf vlan vlan20 restart-helper-lsa-check
386
387#
388# Module pim configuration.
389#
390disable pim
391configure pim crp timer 60
392configure pim register-suppress-interval 60 register-probe-interval 5
393configure pim register-checksum-to include-data
394
395#
396# Module poe configuration.
397#
398enable inline-power
399configure inline-power usage-threshold 70
400configure inline-power disconnect-precedence deny-port
401disable inline-power legacy slot 1
402enable inline-power ports 1
403configure inline-power operator-limit 15400 ports 1
404configure inline-power label "" ports 1
405configure inline-power priority low ports 1
406enable inline-power ports 2
407configure inline-power operator-limit 15400 ports 2
408configure inline-power label "" ports 2
409configure inline-power priority low ports 2
410enable inline-power ports 3
411configure inline-power operator-limit 15400 ports 3
412configure inline-power label "" ports 3
413configure inline-power priority low ports 3
414enable inline-power ports 4
415configure inline-power operator-limit 15400 ports 4
416configure inline-power label "" ports 4
417configure inline-power priority low ports 4
418enable inline-power ports 5
419configure inline-power operator-limit 15400 ports 5
420configure inline-power label "" ports 5
421configure inline-power priority low ports 5
422enable inline-power ports 6
423configure inline-power operator-limit 15400 ports 6
424configure inline-power label "" ports 6
425configure inline-power priority low ports 6
426enable inline-power ports 7
427configure inline-power operator-limit 15400 ports 7
428configure inline-power label "" ports 7
429configure inline-power priority low ports 7
430enable inline-power ports 8
431configure inline-power operator-limit 15400 ports 8
432configure inline-power label "" ports 8
433configure inline-power priority low ports 8
434enable inline-power ports 9
435configure inline-power operator-limit 15400 ports 9
436configure inline-power label "" ports 9
437configure inline-power priority low ports 9
438enable inline-power ports 10
439configure inline-power operator-limit 15400 ports 10
440configure inline-power label "" ports 10
441configure inline-power priority low ports 10
442enable inline-power ports 11
443configure inline-power operator-limit 15400 ports 11
444configure inline-power label "" ports 11
445configure inline-power priority low ports 11
446enable inline-power ports 12
447configure inline-power operator-limit 15400 ports 12
448configure inline-power label "" ports 12
449configure inline-power priority low ports 12
450enable inline-power ports 13
451configure inline-power operator-limit 15400 ports 13
452configure inline-power label "" ports 13
453configure inline-power priority low ports 13
454enable inline-power ports 14
455configure inline-power operator-limit 15400 ports 14
456configure inline-power label "" ports 14
457configure inline-power priority low ports 14
458enable inline-power ports 15
459configure inline-power operator-limit 15400 ports 15
460configure inline-power label "" ports 15
461configure inline-power priority low ports 15
462enable inline-power ports 16
463configure inline-power operator-limit 15400 ports 16
464configure inline-power label "" ports 16
465configure inline-power priority low ports 16
466enable inline-power ports 17
467configure inline-power operator-limit 15400 ports 17
468configure inline-power label "" ports 17
469configure inline-power priority low ports 17
470enable inline-power ports 18
471configure inline-power operator-limit 15400 ports 18
472configure inline-power label "" ports 18
473configure inline-power priority low ports 18
474enable inline-power ports 19
475configure inline-power operator-limit 15400 ports 19
476configure inline-power label "" ports 19
477configure inline-power priority low ports 19
478enable inline-power ports 20
479configure inline-power operator-limit 15400 ports 20
480configure inline-power label "" ports 20
481configure inline-power priority low ports 20
482enable inline-power ports 21
483configure inline-power operator-limit 15400 ports 21
484configure inline-power label "" ports 21
485configure inline-power priority low ports 21
486enable inline-power ports 22
487configure inline-power operator-limit 15400 ports 22
488configure inline-power label "" ports 22
489configure inline-power priority low ports 22
490enable inline-power ports 23
491configure inline-power operator-limit 15400 ports 23
492configure inline-power label "" ports 23
493configure inline-power priority low ports 23
494enable inline-power ports 24
495configure inline-power operator-limit 15400 ports 24
496configure inline-power label "" ports 24
497configure inline-power priority low ports 24
498
499#
500# Module rip configuration.
501#
502configure rip garbagetime 120
503configure rip import-policy none
504configure rip routetimeout 180
505configure rip updatetime 60
506disable rip originate-default
507disable rip use-ip-router-alert
508disable rip aggregation
509enable rip poisonreverse
510enable rip splithorizon
511enable rip triggerupdates
512enable rip
513disable rip export direct
514disable rip export static
515disable rip export ospf-intra
516disable rip export ospf-inter
517disable rip export ospf-extern1
518disable rip export ospf-extern2
519disable rip export e-bgp
520disable rip export i-bgp
521configure rip add vlan vlan10
522configure rip vlan vlan10 route-policy out none
523configure rip vlan vlan10 route-policy in none
524configure rip vlan vlan10 trusted-gateway none
525configure rip vlan vlan10 rxmode any
526configure rip vlan vlan10 txmode v2only
527configure rip vlan vlan10 cost 1
528configure rip add vlan vlan20
529configure rip vlan vlan20 route-policy out none
530configure rip vlan vlan20 route-policy in none
531configure rip vlan vlan20 trusted-gateway none
532configure rip vlan vlan20 rxmode any
533configure rip vlan vlan20 txmode v2only
534configure rip vlan vlan20 cost 1
535
536#
537# Module ripng configuration.
538#
539disable ripng
540configure ripng garbagetime 120
541configure ripng updatetime 30
542configure ripng routetimeout 180
543
544#
545# Module snmpMaster configuration.
546#
547configure snmpv3 engine-id 03:00:04:96:27:c8:3a
548configure snmpv3 add user admin authentication md5 hex 93:0a:71:2b:6a:a8:0b:0f:eb:20:e8:a0:d8:29:9d:5d privacy hex 93:0a:71:2b:6a:a8:0b:0f:eb:20:e8:a0:d8:29:9d:5d
549configure snmpv3 add user initial
550configure snmpv3 add user initialmd5 authentication md5 hex 4f:3b:90:c0:25:86:be:60:c6:97:14:83:5c:2d:44:c5
551configure snmpv3 add user initialsha authentication sha hex b4:ab:24:92:9d:d8:31:ba:b1:e2:6e:f3:46:17:02:55:8b:fe:d1:98
552configure snmpv3 add user initialmd5Priv authentication md5 hex 33:0b:ff:c2:51:07:ee:32:9f:ca:2e:b2:55:82:64:cd privacy hex 33:0b:ff:c2:51:07:ee:32:9f:ca:2e:b2:55:82:64:cd
553configure snmpv3 add user initialshaPriv authentication sha hex 80:61:f8:6d:d8:0f:1b:f7:2d:b6:cf:a0:95:4c:f8:75:f3:ee:c8:f1 privacy hex 80:61:f8:6d:d8:0f:1b:f7:2d:b6:cf:a0:95:4c:f8:75:f3:ee:c8:f1
554 configure snmpv3 add group v1v2c_ro user v1v2c_ro sec-model snmpv1
555configure snmpv3 add group v1v2c_rw user v1v2c_rw sec-model snmpv1
556configure snmpv3 add group v1v2c_ro user v1v2c_ro sec-model snmpv2c
557configure snmpv3 add group v1v2c_rw user v1v2c_rw sec-model snmpv2c
558configure snmpv3 add group admin user admin sec-model usm
559configure snmpv3 add group initial user initial sec-model usm
560configure snmpv3 add group initial user initialmd5 sec-model usm
561configure snmpv3 add group initial user initialsha sec-model usm
562configure snmpv3 add group initial user initialmd5Priv sec-model usm
563configure snmpv3 add group initial user initialshaPriv sec-model usm
564configure snmpv3 add access admin sec-model usm sec-level priv read-view defaultAdminView write-view defaultAdminView notify-view defaultNotifyView
565configure snmpv3 add access initial sec-model usm sec-level noauth read-view defaultUserView notify-view defaultNotifyView
566configure snmpv3 add access initial sec-model usm sec-level authnopriv read-view defaultUserView write-view defaultUserView notify-view defaultNotifyView
567configure snmpv3 add access v1v2c_ro sec-model snmpv1 sec-level noauth read-view defaultUserView notify-view defaultNotifyView
568configure snmpv3 add access v1v2c_ro sec-model snmpv2c sec-level noauth read-view defaultUserView notify-view defaultNotifyView
569 configure snmpv3 add access v1v2c_rw sec-model snmpv1 sec-level noauth read-view defaultUserView write-view defaultUserView notify-view defaultNotifyView
570configure snmpv3 add access v1v2c_rw sec-model snmpv2c sec-level noauth read-view defaultUserView write-view defaultUserView notify-view defaultNotifyView
571configure snmpv3 add access v1v2cNotifyGroup sec-model snmpv1 sec-level noauth notify-view defaultNotifyView
572configure snmpv3 add access v1v2cNotifyGroup sec-model snmpv2c sec-level noauth notify-view defaultNotifyView
573configure snmpv3 add mib-view defaultUserView subtree 1 type included
574configure snmpv3 add mib-view defaultUserView subtree 1.3.6.1.6.3.16 type excluded
575configure snmpv3 add mib-view defaultUserView subtree 1.3.6.1.6.3.18 type excluded
576 configure snmpv3 add mib-view defaultUserView subtree 1.3.6.1.6.3.15.1.2.2.1.4 type excluded
577configure snmpv3 add mib-view defaultUserView subtree 1.3.6.1.6.3.15.1.2.2.1.6 type excluded
578configure snmpv3 add mib-view defaultUserView subtree 1.3.6.1.6.3.15.1.2.2.1.9 type excluded
579configure snmpv3 add mib-view defaultAdminView subtree 1 type included
580configure snmpv3 add mib-view defaultNotifyView subtree 1 type included
581configure snmpv3 add community private name private user v1v2c_rw
582configure snmpv3 add community public name public user v1v2c_ro
583configure snmpv3 add notify defaultNotify tag defaultNotify
584enable snmp access
585enable snmp traps
586
587#
588# Module stp configuration.
589#
590configure mstp region 00049627c83a
591configure mstp revision 3
592configure mstp format 0
593create stpd s0
594configure stpd s0 tag 0
595configure stpd s0 mode dot1d
596configure stpd s0 forwarddelay 15
597configure stpd s0 hellotime 2
598configure stpd s0 maxage 20
599configure stpd s0 priority 32768
600disable stpd s0 rapid-root-failover
601configure stpd s0 default-encapsulation dot1d
602enable stpd s0 auto-bind vlan Default
603disable stpd s0
604
605#
606# Module telnetd configuration.
607#
608configure telnet vr all
609
610#
611# Module tftpd configuration.
612#
613
614#
615# Module thttpd configuration.
616#
617
618#
619# Module vrrp configuration.
620#