I. CAT4006 engine module WS-X4013 configuration list
These include: Basic settings, VLAN configuration, Channel configuration, and port Image Port 1/2 to connect to gigabit IDS)
Cisco Systems, Inc. Console
Enter password:
CAT4006> enable
Enter password:
CAT4006> (enable)
.......
..................
..................
....................
....................
..
Begin
!
# ***** NON-DEFAULT CONFIGURATION *****
!
!
# Time: Mon Apr 11 2005, 22:02:13
!
# Version 6.1 (1)
!
!
# System web interface version (s)
Set password *********************
Set enablepass *********************
!
# Test
!
# System
Set system name CAT4006
!
# Frame distribution method
Set port channel all distribution mac both
!
# Vtp
Set vtp domain hngazk
Set vlan 1 name default type ethernet mtu 1500 said 100001 state active
Set vlan 16 name Old_Bangong type ethernet mtu 1500 said 100016 state active
Set vlan 17 name Server_Manage type ethernet mtu 1500 said 100017 state active
Set vlan 18 name New_Bangong type ethernet mtu 1500 said 100018 state active
Set vlan 19 name Library type ethernet mtu 1500 said 100019 state active
Set vlan 20 name New_Shiyanzhongxin type ethernet mtu 1500 said 100020 state active
Set vlan 22 name Old_Shiyanzhongxin type ethernet mtu 1500 said 100022 state active
Set vlan 23 name CaiZhuan_Jiashuyuan type ethernet mtu 1500 said 100023 state active
Set vlan 1002 name fddi-default type fddi mtu 1500 said 101002 state active
Set vlan 1004 name fddinet-default type fddinet mtu 1500 said 101004 state active stp ieee
Set vlan 1005 name trnet-default type trbrf mtu 1500 said 101005 state active stp IBM
Set vlan 1003 name token-ring-default type trcrf mtu 1500 said 101003 state active mode srbs aremaxhop 0 stemaxhop 0 backupcrf off
!
# Ip
Set interface sc0 17 21x. xxx.17.253/255.255.255.0 21x. xxx. xxx.255
Set interface sl0 down
Set interface me1 down
Set ip route 0.0.0.0/0.0.0.0 21x. xxx. xxx.254
!
# Dns
Set ip dns server 21x. xxx. xxx.2 primary
Set ip dns enable
!
# Syslog
Set logging level cops 2 default
!
# Set boot command
Set boot config-register 0x2
Set boot system flash bootflash: cat4000.6-1-1.bin
!
# Mls
Set mls nde disable
!
# Port channel
Set port channel 3/1-4 636
!
# Module 1: 2-port 1000 BaseX Supervisor
Set udld enable 1/1.
Set trunk 1/1 nonegotiate dot1q 1-1005
Set trunk 1/2 nonegotiate dot1q 1-1005
!
# Module 2: 6-port 1000 BaseX Ethernet
Set vlan 20 2/3
Set port name 2/1 Old_Shiyanzhongxin
Set port name 2/2 Library
Set port name 2/3 New_Shiyanzhongxin
Set port name 2/4 New_Bangong
Set port name 2/5 CaiZhuan_Jiashuyuan
Set port name 2/6 Old_Shiyanzhongxin
Set udld enable 2/6.
Set udld disable 2/3
Set trunk 2/1 nonegotiate dot1q 1-1005
Set trunk 2/2 nonegotiate dot1q 1-1005
Set trunk 2/3 nonegotiate dot1q 1-1005
Set trunk 2/4 nonegotiate dot1q 1-1005
Set trunk 2/5 nonegotiate dot1q 1-1005
Set trunk 2/6 nonegotiate dot1q 1-1005
!
# Module 3: 34-port Router Switch Card
Set vlan 16 3/3-9,3/11-19,3/26-34
Set vlan 17 3/10, 3/20
Set vlan 18 (3/21)
Set vlan 19, 3/22
Set vlan 20 3/23
Set vlan 22 3/24
Set vlan 23 and 3/25
Set port name 3/1 Firewall_Talent
Set trunk 3/1 nonegotiate dot1q 1-1005
Set trunk 3/2 nonegotiate dot1q 1-1005
Set port channel 3/1-2 mode on
!
# Module 4: 34-port 10/100/1000 Ethernet
Set vlan 16 4/5-9,4/11,4/15-34
Set vlan 17 4/3-/12-14
Set trunk 4/1 nonegotiate dot1q 1-1005
Set trunk 4/2 nonegotiate dot1q 1-1005
!
# Module 5 empty
!
# Module 6 empty
!
# Switch port analyzer
Set span 2/1-6, 3/1-34,4/1-34 1/2 both inpkts disable learning enable create
End
CAT4006> (enable)
2. Configuration list of three-layer routing module of WS-X4232-L3
Including VLAN routing, access control list, layer-3 module, and vswitch backplane Channel configuration)
WS-X4232-L3 #
Using 4055 out of 126968 bytes
!
Version 12.0:
No service pad
Service timestamps debug uptime
Service timestamps log uptime
No service password-encryption
!
Hostname WS-X4232-L3
!
Enable secret 5 *****************
Enable password **********
!
Ip subnet-zero
!
!
!
Interface Port-channel1
No ip address
No ip directed-broadcast
Hold-queue 300 in
!
Interface Port-channel1.1
Encapsulation dot1Q 1 native
Ip address 10.10.1.254 255.255.255.0
Ip access-group 110 in
Ip address access-group 110 out
No ip redirects
No ip directed-broadcast
!
Interface Port-channel1.16
Encapsulation dot1Q 16
Ip address 21x. xxx.16.254 255.255.255.0
Ip access-group 110 in
Ip address access-group 110 out
No ip redirects
No ip directed-broadcast
!
Interface Port-channel1.17
Encapsulation dot1Q 17
Ip address 21x. xxx.17.254 255.255.255.0
Ip access-group 110 in
Ip address access-group 110 out
No ip redirects
No ip directed-broadcast
!
Interface Port-channel1.18
Encapsulation dot1Q 18
Ip address 21x. xxx.18.254 255.255.255.0
Ip access-group 110 in
Ip address access-group 110 out
No ip redirects
No ip directed-broadcast
!
Interface Port-channel1.19
Encapsulation dot1Q 19
Ip address 21x. xxx.19.254 255.255.255.0
Ip access-group 110 in
Ip address access-group 110 out
No ip redirects
No ip directed-broadcast
!
Interface Port-channel1.20
Encapsulation dot1Q 20
Ip address 21x. xxx.21.254 255.255.254.0 secondary
Ip address 21x. xxx.255.254 255.255.254.0
Ip access-group 110 in
Ip address access-group 110 out
No ip redirects
No ip directed-broadcast
!
Interface Port-channel1.22
Encapsulation dot1Q 22
Ip address 21x. xxx.22.254 255.255.255.0
Ip access-group 110 in
Ip address access-group 110 out
No ip redirects
No ip directed-broadcast
!
Interface Port-channel1.23
Encapsulation dot1Q 23
Ip address 21x. xxx.23.254 255.255.255.0
Ip access-group 110 in
Ip address access-group 110 out
No ip redirects
No ip directed-broadcast
!
Interface FastEthernet1
No ip address
No ip directed-broadcast
Shutdown
!
Interface GigabitEthernet1
Ip address 21x. xxx 255.255.255.240
Ip access-group 110 in
Ip address access-group 110 out
No ip directed-broadcast
!
Interface GigabitEthernet2
No ip address
No ip directed-broadcast
!
Interface GigabitEthernet3
No ip address
No ip directed-broadcast
No negotiation auto
Channel-group 1
!
Interface GigabitEthernet4
No ip address
No ip directed-broadcast
No negotiation auto
Channel-group 1
!
Ip classless
Ip route 0.0.0.0 0.0.0.0 2xx. xxx
!
Access-list 110 deny tcp any eq echo
Access-list 110 deny tcp any eq chargen
Access-list 110 deny tcp any eq 135
Access-list 110 deny tcp any eq 136
Access-list 110 deny tcp any eq 137
Access-list 110 deny tcp any eq 138
Access-list 110 deny tcp any eq 139
Access-list 110 deny tcp any eq 389
Access-list 110 deny tcp any eq 445
Access-list 110 deny tcp any eq 4444
Access-list 110 deny udp any eq tftp
Access-list 110 deny udp any eq 135
Access-list 110 deny udp any eq 136
Access-list 110 deny udp any eq netbios-ns
Access-list 110 deny udp any eq netbios-dgm
Access-list 110 deny udp any eq netbios-ss
Access-list 110 deny udp any eq 389
Access-list 110 deny udp any eq 445
Access-list 110 deny udp any eq 1434
Access-list 110 deny udp any eq 1433
Access-list 110 deny udp any eq 1025
Access-list 110 deny udp any eq 455
Access-list 110 deny udp any eq 5554
Access-list 110 deny udp any eq 9996
Access-list 110 deny udp any eq 6129
Access-list 110 deny udp any eq 3127
Access-list 110 deny udp any eq 2745
Access-list 110 deny tcp any eq 6669
Access-list 110 deny tcp any eq 1023
Access-list 110 deny tcp any eq 1024
Access-list 110 deny tcp any eq 3332
Access-list 110 deny tcp any eq 69
Access-list 110 deny udp any eq 593
Access-list 110 deny tcp any eq 593
Access-list 110 permit ip any
Arp 127.0.0.2 0005.5e73.9300 ARPA
!
Line con 0
Transport input none
Line aux 0
Line vty 0 4
Password **********
Login
!
End
WS-X4232-L3 #