=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2019.08.29 16:46:42 =~=~=~=~=~=~=~=~=~=~=~= show running-config Building Configuration... version 8.5 hostname "MC-1" clock timezone America/Los_Angeles -07 00 ! location "Building1.floor1" controller config 10 crypto-local pki ServerCert MC1 mpcl.crt crypto-local pki PublicCert mc mpcl.crt ip NAT pool dynamic-srcnat 0.0.0.0 0.0.0.0 ip access-list geolocation global-geolocation-acl ! ip access-list eth validuserethacl permit any ! netservice svc-dhcp udp 67 68 alg dhcp netservice svc-ipp-tcp tcp 631 netservice svc-citrix tcp 2598 netservice svc-pcoip-udp udp 50002 netservice svc-tftp udp 69 alg tftp netservice svc-netbios-ssn tcp 139 netservice svc-papi udp 8211 netservice svc-natt udp 4500 --More-- (q) quit (u) pageup (/) search (n) repeat netservice svc-ica tcp 1494 netservice svc-facetime-tcp tcp 5223 alg facetime netservice svc-msrpc-udp udp 135 139 netservice svc-lpd tcp 515 netservice svc-msrpc-tcp tcp 135 139 netservice svc-microsoft-ds tcp 445 netservice svc-smtp tcp 25 netservice svc-syslog udp 514 netservice svc-http-proxy2 tcp 8080 netservice svc-cfgm-tcp tcp 8211 netservice vnc tcp 5900 5905 netservice svc-telnet tcp 23 netservice svc-http tcp 80 netservice svc-h323-udp udp 1718 1719 alg h323 netservice svc-bootp udp 67 69 netservice svc-web tcp list "80 443" netservice svc-sccp tcp 2000 alg sccp netservice svc-ipp-udp udp 631 netservice svc-vmware-rdp tcp 3389 netservice svc-vocera udp 5002 alg vocera netservice svc-esp 50 netservice svc-noe-oxo udp 5000 alg noe netservice svc-http-proxy1 tcp 3128 --More-- (q) quit (u) pageup (/) search (n) repeat netservice svc-sec-papi udp 8209 netservice svc-gre 47 netservice svc-rtsp tcp 554 alg rtsp netservice svc-l2tp udp 1701 netservice svc-svp 119 alg svp netservice svc-sip-tcp tcp 5060 alg sip netservice svc-snmp udp 161 netservice svc-pptp tcp 1723 netservice svc-icmp 1 netservice svc-smb-tcp tcp 445 netservice svc-pcoip2-tcp tcp 4172 netservice svc-ssh tcp 22 netservice svc-v6-icmp 58 netservice svc-h323-tcp tcp 1720 alg h323 netservice svc-ntp udp 123 netservice svc-pop3 tcp 110 netservice svc-adp udp 8200 netservice svc-netbios-ns udp 137 netservice svc-dns udp 53 alg dns netservice svc-v6-dhcp udp 546 547 netservice svc-netbios-dgm udp 138 netservice svc-http-proxy3 tcp 8888 netservice svc-sip-udp udp 5060 alg sip --More-- (q) quit (u) pageup (/) search (n) repeat netservice svc-kerberos udp 88 netservice svc-sips tcp 5061 alg sips netservice svc-nterm tcp 1026 1028 netservice svc-snmp-trap udp 162 netservice svc-pcoip2-udp udp 4172 netservice svc-pcoip-tcp tcp 50002 netservice svc-ike udp 500 netservice svc-noe udp 32512 alg noe netservice svc-ftp tcp 21 alg ftp netservice svc-https tcp 443 netservice svc-smb-udp udp 445 netdestination6 ipv6-reserved-range invert network 2000::/3 ! netdestination wificalling-block name pub.3gppnetwork.org name vowifi.com ! netexthdr default ! time-range periodic working-hours weekday 08:00 to 18:00 --More-- (q) quit (u) pageup (/) search (n) repeat ! time-range periodic night-hours weekday 18:01 to 23:59 weekday 00:00 to 07:59 ! ip access-list session apprf-switch-logon-sacl ! ip access-list session lab01-it ! ip access-list session apprf-a-guest-guest-logon-sacl ! ip access-list session svp-acl any any svc-svp permit queue high user host 224.0.1.116 any permit ! ip access-list session apprf-stateful-dot1x-sacl ! ip access-list session apprf-lab01-sales-sacl ! ip access-list session apprf-voice-sacl ! ip access-list session logon-control user any udp 68 deny --More-- (q) quit (u) pageup (/) search (n) repeat any any svc-icmp permit any any svc-dns permit any any svc-dhcp permit any any svc-natt permit any network 169.254.0.0 255.255.0.0 any deny any network 240.0.0.0 240.0.0.0 any deny ! ip access-list session apprf-default-vpn-role-sacl ! ip access-list session ap-uplink-acl any any udp 68 permit any any svc-icmp permit any host 224.0.0.251 udp 5353 permit ipv6 any any udp 546 permit ipv6 any any svc-v6-icmp permit ipv6 any host ff02::fb udp 5353 permit ! ip access-list session icmp-acl any any svc-icmp permit ! ip access-list session v6-logon-control ipv6 user any udp 546 deny ipv6 any any svc-v6-icmp permit --More-- (q) quit (u) pageup (/) search (n) repeat ipv6 any any svc-v6-dhcp permit ipv6 any any svc-dns permit ipv6 any network fc00::/7 any permit ipv6 any network fe80::/64 any permit ipv6 any alias ipv6-reserved-range any deny ! ip access-list session http-acl any any svc-http permit ! ip access-list session vocera-acl any any svc-vocera permit queue high ! ip access-list session lab03-it ! ip access-list session v6-http-acl ipv6 any any svc-http permit ! ip access-list session sip-acl any any svc-sip-udp permit queue high any any svc-sip-tcp permit queue high ! ip access-list session citrix-acl any any svc-citrix permit tos 46 dot1p-priority 6 --More-- (q) quit (u) pageup (/) search (n) repeat any any svc-ica permit tos 46 dot1p-priority 6 ! ip access-list session vmware-acl any any svc-vmware-rdp permit tos 46 dot1p-priority 6 any any svc-pcoip-tcp permit tos 46 dot1p-priority 6 any any svc-pcoip-udp permit tos 46 dot1p-priority 6 any any svc-pcoip2-tcp permit tos 46 dot1p-priority 6 any any svc-pcoip2-udp permit tos 46 dot1p-priority 6 ! ip access-list session tftp-acl any any svc-tftp permit ! ip access-list session lab01-finance ! ip access-list session ra-guard ipv6 user any icmpv6 rtr-adv deny ! ip access-list session voip-applications-acl any any app alg-skype4b-audio permit any any app alg-skype4b-video permit any any app alg-skype4b-desktop-sharing permit any any app alg-skype4b-app-sharing permit any any app alg-sip-audio permit --More-- (q) quit (u) pageup (/) search (n) repeat any any app alg-sip-video permit any any app alg-sccp permit any any app alg-vocera permit any any app alg-noe permit any any app alg-h323 permit any any app alg-jabber-audio permit any any app alg-jabber-video permit any any app alg-jabber-desktop-sharing permit any any app alg-facetime permit any any app alg-wifi-calling permit any any app alg-rtp permit ! ip access-list session srcnat user any any src-nat ! ip access-list session global-sacl ! ip access-list session v6-dhcp-acl ipv6 any any svc-v6-dhcp permit ! ip access-list session jabber-acl any any tcp 5222 permit any any tcp 8443 permit --More-- (q) quit (u) pageup (/) search (n) repeat ! ip access-list session wan-uplink-protect-acl any any sys-svc-dhcp permit ipv6 any any sys-svc-v6-dhcp permit any any sys-svc-esp permit any any sys-svc-natt permit any any sys-svc-ike permit any any sys-svc-icmp permit ipv6 any any sys-svc-icmp6 permit ! ip access-list session stateful-dot1x any any svc-dns permit any any svc-dhcp permit ! ip access-list session cplogout user alias controller svc-https dst-nat 8081 ! ip access-list session wificalling-acl any any tcp 443 permit ! ip access-list session apprf-authenticated-sacl ! ip access-list session dns-allow --More-- (q) quit (u) pageup (/) search (n) repeat any host 192.168.30.4 svc-dns permit ! ip access-list session apprf-logon-sacl ! ip access-list session apprf-guest-logon-sacl ! ip access-list session vpnlogon user any svc-ike permit user any svc-esp permit any any svc-l2tp permit any any svc-pptp permit any any svc-gre permit ! ip access-list session allow-diskservices any any svc-netbios-dgm permit any any svc-netbios-ssn permit any any svc-microsoft-ds permit any any svc-netbios-ns permit ! ip access-list session v6-control ipv6 user any udp 546 deny ipv6 any any svc-v6-icmp permit ipv6 any any svc-dns permit --More-- (q) quit (u) pageup (/) search (n) repeat ipv6 any any svc-papi permit ipv6 any any svc-sec-papi permit ipv6 any any svc-cfgm-tcp permit ipv6 any any svc-adp permit ipv6 any any svc-tftp permit ipv6 any any svc-dhcp permit ipv6 any any svc-natt permit ! ip access-list session apprf-sys-switch-role-sacl ! ip access-list session apprf-lab01-finance-sacl ! ip access-list session apprf-guest-sacl ! ip access-list session v6-ap-acl ipv6 any any svc-gre permit ipv6 any any svc-syslog permit ipv6 any user svc-snmp permit ipv6 user any svc-snmp-trap permit ipv6 user any svc-ntp permit ipv6 user any svc-ftp permit ! ip access-list session wificalling-block --More-- (q) quit (u) pageup (/) search (n) repeat any alias wificalling-block any deny ! ip access-list session apprf-default-via-role-sacl ! ip access-list session v6-allowall ipv6 any any any permit ! ip access-list session apprf-default-iap-user-role-sacl ! ip access-list session v6-icmp-acl ipv6 any any svc-v6-icmp permit ! ip access-list session validuser network 127.0.0.0 255.0.0.0 any any deny network 169.254.0.0 255.255.0.0 any any deny network 224.0.0.0 240.0.0.0 any any deny host 255.255.255.255 any any deny network 240.0.0.0 240.0.0.0 any any deny any any any permit ipv6 host fe80:: any any deny ipv6 network fc00::/7 any any permit ipv6 network fe80::/64 any any permit ipv6 alias ipv6-reserved-range any any deny --More-- (q) quit (u) pageup (/) search (n) repeat ipv6 any any any permit ! ip access-list session v6-dns-acl ipv6 any any svc-dns permit ! ip access-list session skype4b-acl any any svc-sips permit any any svc-https permit ! ip access-list session captiveportal user alias controller svc-https dst-nat 8081 user any svc-http dst-nat 8080 user any svc-https dst-nat 8081 user any svc-http-proxy1 dst-nat 8088 user any svc-http-proxy2 dst-nat 8088 user any svc-http-proxy3 dst-nat 8088 ! ip access-list session h323-acl any any svc-h323-tcp permit queue high any any svc-h323-udp permit queue high ! ip access-list session allowall any any any permit --More-- (q) quit (u) pageup (/) search (n) repeat ipv6 any any any permit ! ip access-list session v6-https-acl ipv6 any any svc-https permit ! ip access-list session apprf-sys-ap-role-sacl ! ip access-list session dhcp-acl any any svc-dhcp permit ! ip access-list session facetime-acl any any svc-facetime-tcp permit queue high any any udp 3478 3497 permit any any udp 16384 16387 permit any any udp 16393 16402 permit ! ip access-list session allow-printservices any any svc-lpd permit any any svc-ipp-tcp permit any any svc-ipp-udp permit ! ip access-list session apprf-lab03-it-sacl ! --More-- (q) quit (u) pageup (/) search (n) repeat ip access-list session dns-access ! ip access-list session skinny-acl any any svc-sccp permit queue high ! ip access-list session https-acl any any svc-https permit ! ip access-list session ap-acl any any svc-gre permit any any svc-syslog permit any user svc-snmp permit user any svc-snmp-trap permit user any svc-ntp permit user any svc-ftp permit user any svc-telnet deny ! ip access-list session apprf-lab01-it-sacl ! ip access-list session apprf-ap-role-sacl ! ip access-list session lab01-accounts ! --More-- (q) quit (u) pageup (/) search (n) repeat ip access-list session captiveportal6 ipv6 user alias controller6 svc-https captive ipv6 user any svc-http captive ipv6 user any svc-https captive ipv6 user any svc-http-proxy1 captive ipv6 user any svc-http-proxy2 captive ipv6 user any svc-http-proxy3 captive ! ip access-list session http-traffic user host 192.168.30.4 svc-dns permit user host 192.168.30.201 svc-http permit user host 192.168.30.201 svc-https permit user host 192.168.30.100 svc-https permit user host 192.168.30.100 any permit user any svc-dhcp permit user host 192.168.99.100 any permit user host 192.168.30.201 any permit ! ip access-list session control user any udp 68 deny any any svc-icmp permit any any svc-dns permit any any svc-papi permit --More-- (q) quit (u) pageup (/) search (n) repeat any any svc-sec-papi permit any any svc-cfgm-tcp permit any any svc-adp permit any any svc-tftp permit any any svc-dhcp permit any any svc-natt permit any any tcp 6633 permit ! ip access-list session apprf-lab01-accounts-sacl ! ip access-list session lab01-sales ! ip access-list session noe-acl any any svc-noe permit queue high ! ip access-list session dns-acl any any svc-dns permit ! ip access-list route master-boc-traffic ! ip access-list route uplink-lb-cfg-racl ! vpn-dialer default-dialer --More-- (q) quit (u) pageup (/) search (n) repeat ike authentication PRE-SHARE ****** ! user-role Lab01-IT access-list session global-sacl access-list session apprf-lab01-it-sacl access-list session lab01-it ! user-role default-via-role access-list session global-sacl access-list session apprf-default-via-role-sacl access-list session allowall access-list session v6-allowall ! user-role sys-switch-role ! user-role ap-role no openflow-enable access-list session ra-guard access-list session control access-list session ap-acl access-list session v6-control access-list session v6-ap-acl ! --More-- (q) quit (u) pageup (/) search (n) repeat user-role Lab03-IT access-list session global-sacl access-list session apprf-lab03-it-sacl ! user-role switch-logon ! user-role Lab01-Finance access-list session global-sacl access-list session apprf-lab01-finance-sacl access-list session lab01-finance ! user-role sys-ap-role no openflow-enable ! user-role stateful-dot1x access-list session global-sacl access-list session apprf-stateful-dot1x-sacl ! user-role guest-logon captive-portal "default" access-list session ra-guard access-list session logon-control access-list session captiveportal --More-- (q) quit (u) pageup (/) search (n) repeat access-list session v6-logon-control access-list session captiveportal6 ! user-role voice access-list session global-sacl access-list session apprf-voice-sacl access-list session ra-guard access-list session sip-acl access-list session noe-acl access-list session svp-acl access-list session vocera-acl access-list session skinny-acl access-list session h323-acl access-list session dhcp-acl access-list session tftp-acl access-list session dns-acl access-list session icmp-acl access-list session http-acl access-list session https-acl access-list session skype4b-acl access-list session facetime-acl access-list session jabber-acl access-list session wificalling-acl --More-- (q) quit (u) pageup (/) search (n) repeat access-list session voip-applications-acl ! user-role default-vpn-role access-list session global-sacl access-list session apprf-default-vpn-role-sacl access-list session ra-guard access-list session allowall access-list session v6-allowall ! user-role logon access-list session ra-guard access-list session logon-control access-list session captiveportal access-list session vpnlogon access-list session v6-logon-control access-list session captiveportal6 ! user-role a-guest-guest-logon vlan 99 no captive-portal check-for-accounting captive-portal "a-guest" web-cc disable access-list session global-sacl --More-- (q) quit (u) pageup (/) search (n) repeat access-list session apprf-a-guest-guest-logon-sacl access-list session http-traffic ! user-role authenticated access-list session global-sacl access-list session apprf-authenticated-sacl access-list session ra-guard access-list session allowall access-list session v6-allowall ! user-role Lab01-Accounts access-list session global-sacl access-list session apprf-lab01-accounts-sacl access-list session lab01-accounts ! user-role guest access-list session global-sacl access-list session apprf-guest-sacl access-list session ra-guard access-list session http-acl access-list session https-acl access-list session dhcp-acl access-list session icmp-acl --More-- (q) quit (u) pageup (/) search (n) repeat access-list session dns-acl access-list session v6-http-acl access-list session v6-https-acl access-list session v6-dhcp-acl access-list session v6-icmp-acl access-list session v6-dns-acl ! user-role Lab01-Sales access-list session global-sacl access-list session apprf-lab01-sales-sacl access-list session lab01-sales ! user-role default-iap-user-role access-list session allowall ! ! aaa tacacs-accounting controller-ip vlan 1 no kernel coredump interface mgmt shutdown --More-- (q) quit (u) pageup (/) search (n) repeat ! dialer group evdo_us init-string ATQ0V1E0 dial-string ATDT#777 ! dialer group gsm_us init-string AT+CGDCONT=1,"IP","ISP.CINGULAR" dial-string ATD*99# ! dialer group gsm_asia init-string AT+CGDCONT=1,"IP","internet" dial-string ATD*99***1# ! dialer group vivo_br init-string AT+CGDCONT=1,"IP","zap.vivo.com.br" dial-string ATD*99# ! cellular profile FRANKLIN_WIRELESS_U772 --More-- (q) quit (u) pageup (/) search (n) repeat vendor 1fac product 232 dialer none tty none driver franklin-u772 ! cellular profile ZTE_MF832U vendor 19d2 product 1292 dialer none tty none driver zte-mf-832u ! vlan 99 vlan 110 vlan 120 vlan 130 vlan 140 vlan-name Vlan110 vlan Vlan110 110 --More-- (q) quit (u) pageup (/) search (n) repeat vlan-name Vlan120 vlan Vlan120 120 vlan-name Vlan130 vlan Vlan130 130 vlan-name Vlan140 vlan Vlan140 140 vlan-name Vlan99 vlan Vlan99 99 interface gigabitethernet 0/0/0 trusted trusted vlan 1-4094 no poe switchport mode trunk ! interface gigabitethernet 0/0/1 trusted trusted vlan 1-4094 no poe ! --More-- (q) quit (u) pageup (/) search (n) repeat interface gigabitethernet 0/0/2 trusted trusted vlan 1-4094 no poe ! interface gigabitethernet 0/0/3 trusted trusted vlan 1-4094 no poe ! interface port-channel 0 trusted trusted vlan 1-4094 ! interface port-channel 1 trusted trusted vlan 1-4094 ! interface port-channel 2 --More-- (q) quit (u) pageup (/) search (n) repeat trusted trusted vlan 1-4094 ! interface port-channel 3 trusted trusted vlan 1-4094 ! interface port-channel 4 trusted trusted vlan 1-4094 ! interface port-channel 5 trusted trusted vlan 1-4094 ! interface port-channel 6 trusted trusted vlan 1-4094 ! --More-- (q) quit (u) pageup (/) search (n) repeat interface port-channel 7 trusted trusted vlan 1-4094 ! interface vlan 1 ip address 192.168.30.100 255.255.255.0 ! interface vlan 99 ip address 192.168.99.100 255.255.255.0 no suppress-arp ! interface vlan 110 ip address 192.168.110.100 255.255.255.0 ! interface vlan 120 ip address 192.168.120.100 255.255.255.0 ! --More-- (q) quit (u) pageup (/) search (n) repeat interface vlan 130 ip address 192.168.130.100 255.255.255.0 ! interface vlan 140 ip address 192.168.140.100 255.255.255.0 ! ! ! ip default-gateway 192.168.30.250 ip nexthop-list load-balance-gateways ! ip nexthop-list load-balance-ipsecs ! ip nexthop-list pan-gp-ipsec-map-list ! ip nexthop-list traditional-ipsecs ! crypto isakmp policy 20 encryption aes256 authentication pre-share --More-- (q) quit (u) pageup (/) search (n) repeat ! crypto isakmp policy 10001 authentication pre-share ! crypto isakmp policy 10002 encryption aes256 authentication rsa-sig ! crypto isakmp policy 10003 encryption aes256 authentication pre-share ! crypto isakmp policy 10004 version v2 encryption aes256 authentication rsa-sig ! crypto isakmp policy 10005 --More-- (q) quit (u) pageup (/) search (n) repeat encryption aes256 authentication pre-share ! crypto isakmp policy 10006 version v2 encryption aes128 authentication rsa-sig ! crypto isakmp policy 10007 version v2 encryption aes128 authentication pre-share ! crypto isakmp policy 10008 version v2 encryption aes128 hash sha2-256-128 group 19 authentication ecdsa-256 prf prf-hmac-sha256 --More-- (q) quit (u) pageup (/) search (n) repeat ! crypto isakmp policy 10009 version v2 encryption aes256 hash sha2-384-192 group 20 authentication ecdsa-384 prf prf-hmac-sha384 ! crypto isakmp policy 10012 version v2 encryption aes256 authentication rsa-sig ! crypto isakmp policy 10013 encryption aes256 authentication pre-share ! crypto isakmp policy 10014 --More-- (q) quit (u) pageup (/) search (n) repeat version v2 encryption aes256 hash sha2-256-128 group 14 authentication pre-share prf prf-hmac-sha256 ! crypto ipsec transform-set default-ha-transform esp-3des esp-sha-hmac crypto ipsec transform-set default-boc-bm-transform esp-aes256 esp-sha-hmac crypto ipsec transform-set default-1st-ikev2-transform esp-aes256 esp-sha-hmac crypto ipsec transform-set default-3rd-ikev2-transform esp-aes128 esp-sha-hmac crypto ipsec transform-set default-rap-transform esp-aes256 esp-sha-hmac crypto ipsec transform-set default-aes esp-aes256 esp-sha-hmac crypto dynamic-map default-rap-ipsecmap 10001 version v2 set transform-set "default-gcm256" "default-gcm128" "default-rap-transform" ! crypto dynamic-map default-dynamicmap 10000 set transform-set "default-transform" "default-aes" ! --More-- (q) quit (u) pageup (/) search (n) repeat crypto map GLOBAL-IKEV2-MAP 10000 ipsec-isakmp dynamic default-rap-ipsecmap crypto map GLOBAL-MAP 10000 ipsec-isakmp dynamic default-dynamicmap crypto isakmp eap-passthrough eap-tls crypto isakmp eap-passthrough eap-peap crypto isakmp eap-passthrough eap-mschapv2 vpdn group l2tp ! ip dynamic-dns interval 900 vpdn group pptp ! tunneled-node-address 0.0.0.0 ap-crash-transfer --More-- (q) quit (u) pageup (/) search (n) repeat adp discovery enable adp igmp-join enable adp igmp-vlan-id 0 ap ap-blacklist-time 3600 ap flush-r1-on-new-r0 disable amon msg-buffer-size 1264 amon udp 0 stm mon-update-queue 7248 ssh mgmt-auth public-key ssh mgmt-auth username/password mgmt-user admin root ******************** ntp no database synchronize ip mobile domain default --More-- (q) quit (u) pageup (/) search (n) repeat ! ip igmp ! ipv6 mld ! firewall prohibit-ip-spoofing allow-tri-session attack-rate grat-arp 50 drop session-idle-timeout 16 cp-bandwidth-contract untrusted-ucast 9765 cp-bandwidth-contract untrusted-mcast 3906 cp-bandwidth-contract trusted-ucast 65535 cp-bandwidth-contract trusted-mcast 3906 cp-bandwidth-contract route 976 cp-bandwidth-contract sessmirr 976 cp-bandwidth-contract vrrp 512 cp-bandwidth-contract arp-traffic 3906 cp-bandwidth-contract l2-other 1953 cp-bandwidth-contract auth 976 --More-- (q) quit (u) pageup (/) search (n) repeat amsdu dpi firewall wireless-bridge-aging session-tunnel-fib stall-crash optimize-dad-frames ! ipv6 firewall ext-hdr-parse-len 100 ! ! ! firewall cp ipv6 deny any proto 0 ports 0 65535 ! ip domain lookup ! country CA change-config-node / aaa rfc-3576-server "192.168.30.201" key 6c88f31eb9141d69eef1c8b85ef1c27398659c59ed11af9e --More-- (q) quit (u) pageup (/) search (n) repeat ! aaa authentication mac "default" ! aaa authentication dot1x "a-dot1x" ! aaa authentication dot1x "Aruba-PSK" ! aaa authentication dot1x "default" ! aaa authentication dot1x "default-psk" ! aaa authentication dot1x "lab03-dot1x" server-cert "MC1" ! aaa authentication via global-config ! scheduler-profile "default" queue-weights q0 0 q1 0 q2 0 q3 0 priority-map q0 "6 7" q1 "4 5" q2 "2 3" q3 "0 1" ! aaa authentication-server radius "CPPM1" host "192.168.30.201" key 2c4b6cd6ade96aaee8e7dbfd23f76c242baab54cc61a8682 --More-- (q) quit (u) pageup (/) search (n) repeat ! aaa server-group "a-dot1x" auth-server CPPM1 position 1 set role condition role value-of ! aaa server-group "a-guest" auth-server CPPM1 position 1 ! aaa server-group "CPPM" auth-server CPPM1 position 1 ! aaa server-group "default" auth-server Internal position 1 set role condition role value-of ! aaa server-group "internal" auth-server Internal position 1 set role condition Role value-of ! aaa profile "a-dot1x" authentication-dot1x "a-dot1x" dot1x-default-role "logon" dot1x-server-group "a-dot1x" --More-- (q) quit (u) pageup (/) search (n) repeat ! aaa profile "a-guest" initial-role "a-guest-guest-logon" authentication-mac "default" mac-server-group "CPPM" radius-accounting "CPPM" rfc-3576-server "192.168.30.201" ! aaa profile "Aruba-PSK" initial-role "authenticated" authentication-dot1x "Aruba-PSK" ! aaa profile "default" ! aaa profile "default-dot1x" authentication-dot1x "default" ! aaa profile "default-dot1x-psk" authentication-dot1x "default-psk" ! aaa profile "default-iap-aaa-profile" initial-role "default-iap-user-role" no wired-to-wireless-roam --More-- (q) quit (u) pageup (/) search (n) repeat no devtype-classification ! aaa profile "default-mac-auth" authentication-mac "default" ! aaa profile "default-open" ! aaa profile "default-tunneled-user" initial-role "guest" no wired-to-wireless-roam no devtype-classification ! aaa profile "default-xml-api" ! aaa profile "lab03-dot1x" download-role ! aaa profile "NoAuthAAAProfile" ! aaa authentication captive-portal "a-guest" default-role "a-guest-guest-logon" server-group "CPPM" redirect-pause 2 --More-- (q) quit (u) pageup (/) search (n) repeat login-page "https://cppm2.mpcl.com.pk/guest/guest2.php" no enable-welcome-page white-list "mswitch" ! aaa authentication captive-portal "default" ! aaa authentication wispr "default" ! aaa authentication vpn "default" ! aaa authentication vpn "default-cap" default-role "sys-ap-role" server-group "internal" ! aaa authentication vpn "default-hp-switch" ! aaa authentication vpn "default-iap" ! aaa authentication vpn "default-rap" ! aaa authentication mgmt ! aaa authentication stateful-ntlm "default" --More-- (q) quit (u) pageup (/) search (n) repeat ! aaa authentication stateful-kerberos "default" ! aaa authentication stateful-dot1x ! aaa authentication via auth-profile "default" ! aaa authentication wired ! aaa authentication via connection-profile "default" ! aaa authentication via web-auth "default" ! web-server profile captive-portal-cert "MC1" ! guest-access-email ! aaa password-policy mgmt ! control-plane-security no cpsec-enable ! --More-- (q) quit (u) pageup (/) search (n) repeat ids management-profile ! ids wms-general-profile ! ids wms-local-system-profile ! ids ap-rule-matching ! valid-network-oui-profile ! traceoptions ! activate ! file syncing profile ! ucc skype4b ! ucc rtpa-config ! ucc jabber ! ucc sip --More-- (q) quit (u) pageup (/) search (n) repeat ! ucc h323 ! ucc vocera ! ucc sccp ! ucc noe ! ucc facetime ! ucc ich ! ucc session-idle-timeout ! ucc wificalling ! license-pool-profile-root pefng-licenses-enable ! papi-security ! est profile "default" --More-- (q) quit (u) pageup (/) search (n) repeat ! aruba-central ! wlan sae-profile ! ifmap cppm ! pan profile "default" ! pan-options ! websocket clearpass ! pan active-profile ! openflow-profile no openflow-enable ! dump-collection-profile "default" ! ap regulatory-domain-profile "default" country-code CA valid-11g-channel 1 --More-- (q) quit (u) pageup (/) search (n) repeat valid-11g-channel 6 valid-11g-channel 11 valid-11a-channel 36 valid-11a-channel 40 valid-11a-channel 44 valid-11a-channel 48 valid-11a-channel 52 valid-11a-channel 56 valid-11a-channel 60 valid-11a-channel 64 valid-11a-channel 100 valid-11a-channel 104 valid-11a-channel 108 valid-11a-channel 112 valid-11a-channel 116 valid-11a-channel 132 valid-11a-channel 136 valid-11a-channel 140 valid-11a-channel 144 valid-11a-channel 149 valid-11a-channel 153 valid-11a-channel 157 valid-11a-channel 161 --More-- (q) quit (u) pageup (/) search (n) repeat valid-11a-channel 165 valid-11g-40mhz-channel-pair 1-5 valid-11g-40mhz-channel-pair 7-11 valid-11a-40mhz-channel-pair 36-40 valid-11a-40mhz-channel-pair 44-48 valid-11a-40mhz-channel-pair 52-56 valid-11a-40mhz-channel-pair 60-64 valid-11a-40mhz-channel-pair 100-104 valid-11a-40mhz-channel-pair 108-112 valid-11a-40mhz-channel-pair 132-136 valid-11a-40mhz-channel-pair 140-144 valid-11a-40mhz-channel-pair 149-153 valid-11a-40mhz-channel-pair 157-161 valid-11a-80mhz-channel-group 36-48 valid-11a-80mhz-channel-group 52-64 valid-11a-80mhz-channel-group 100-112 valid-11a-80mhz-channel-group 132-144 valid-11a-80mhz-channel-group 149-161 valid-11a-160mhz-channel-group 36-64 ! ap wired-ap-profile "default" ! ap wired-ap-profile "NoAuthWiredAp" --More-- (q) quit (u) pageup (/) search (n) repeat wired-ap-enable ! ap enet-link-profile "default" ! ap mesh-ht-ssid-profile "default" ! ap lldp med-network-policy-profile "default" ! ap mesh-cluster-profile "default" ! ap wifi-uplink-profile "default" ! ap multizone-profile "default" ! ap system-profile "default" ap-console-password 4d81e8c47281932907ea267c3bf98629d78c395086cf28b1 bkup-passwords 14bba6e76bf4cc8e5e30a630e87b3a54413d3e5981ec2d5d ! ap system-profile "NoAuthApSystem" ap-console-password 806c703dd197ccc950d8b0380ffddc293ddc685e70d75954 ! ap lldp profile "default" ! --More-- (q) quit (u) pageup (/) search (n) repeat ap mesh-radio-profile "default" ! ap wired-port-profile "default" ! ap wired-port-profile "NoAuthWiredPort" wired-ap-profile "NoAuthWiredAp" aaa-profile "NoAuthAAAProfile" ! ap wired-port-profile "shutdown" shutdown ! ids general-profile "default" ! ids rate-thresholds-profile "default" ! ids rate-thresholds-profile "probe-request-response-thresholds" ! ids signature-profile "AirJack" frame-type beacon ssid AirJack ! ids signature-profile "ASLEAP" frame-type beacon ssid asleap ! --More-- (q) quit (u) pageup (/) search (n) repeat ids signature-profile "Deauth-Broadcast" frame-type deauth dst-mac ff:ff:ff:ff:ff:ff ! ids signature-profile "Deauth-Broadcast-From-Valid-AP" frame-type deauth dst-mac ff:ff:ff:ff:ff:ff src-mac valid-ap bssid valid-ap ! ids signature-profile "default" ! ids signature-profile "Disassoc-Broadcast" frame-type disassoc dst-mac ff:ff:ff:ff:ff:ff ! ids signature-profile "Disassoc-Broadcast-From-Valid-AP" frame-type disassoc dst-mac ff:ff:ff:ff:ff:ff src-mac valid-ap bssid valid-ap ! ids signature-profile "Netstumbler Generic" --More-- (q) quit (u) pageup (/) search (n) repeat payload 0x00601d 3 payload 0x0001 6 ! ids signature-profile "Netstumbler Version 3.3.0x" payload 0x00601d 3 payload 0x000102 12 ! ids signature-profile "Null-Probe-Response" frame-type probe-response ssid-length 0 ! ids signature-profile "Wellenreiter" frame-type probe-request ssid this_is_used_for_wellenreiter ! ids impersonation-profile "default" ! ids unauthorized-device-profile "default" ! ids signature-matching-profile "default" ! ids dos-profile "default" ! ids profile "default" ! --More-- (q) quit (u) pageup (/) search (n) repeat rf dot11-60GHz-radio-profile "default" ! rf arm-profile "arm-maintain" assignment maintain no scanning ! rf arm-profile "arm-scan" ! rf arm-profile "default-a" min-tx-power 12 max-tx-power 18 ! rf arm-profile "default-g" min-tx-power 6 max-tx-power 9 free-channel-index 40 ! rf ht-radio-profile "default-a" ! rf ht-radio-profile "default-g" ! rf spectrum-profile "default-a" ! --More-- (q) quit (u) pageup (/) search (n) repeat rf spectrum-profile "default-g" ! rf optimization-profile "default" ! rf event-thresholds-profile "default" ! rf am-scan-profile "default" ! rf dot11a-radio-profile "default" ! rf dot11a-radio-profile "rp-maintain-a" arm-profile "arm-maintain" ! rf dot11a-radio-profile "rp-monitor-a" mode am-mode ! rf dot11a-radio-profile "rp-scan-a" arm-profile "arm-scan" ! rf dot11g-radio-profile "default" ! rf dot11g-radio-profile "rp-maintain-g" arm-profile "arm-maintain" --More-- (q) quit (u) pageup (/) search (n) repeat ! rf dot11g-radio-profile "rp-monitor-g" mode am-mode ! rf dot11g-radio-profile "rp-scan-g" arm-profile "arm-scan" ! wlan rrm-ie-profile "default" ! wlan bcn-rpt-req-profile "default" ! wlan dot11r-profile "default" ! wlan tsm-req-profile "default" ! wlan ht-ssid-profile "default" ! wlan he-ssid-profile "default" ! wlan hotspot anqp-venue-name-profile "default" ! wlan hotspot anqp-nwk-auth-profile "default" ! --More-- (q) quit (u) pageup (/) search (n) repeat wlan hotspot anqp-roam-cons-profile "default" ! wlan hotspot anqp-nai-realm-profile "default" ! wlan hotspot anqp-3gpp-nwk-profile "default" ! wlan hotspot h2qp-operator-friendly-name-profile "default" ! wlan hotspot h2qp-wan-metrics-profile "default" ! wlan hotspot h2qp-conn-capability-profile "default" ! wlan hotspot h2qp-op-cl-profile "default" ! wlan hotspot h2qp-osu-prov-list-profile "default" ! wlan hotspot anqp-ip-addr-avail-profile "default" ! wlan hotspot anqp-domain-name-profile "default" ! wlan edca-parameters-profile station "default" ! wlan edca-parameters-profile ap "default" --More-- (q) quit (u) pageup (/) search (n) repeat ! wlan mu-edca-parameters-profile "default" ! wlan dot11k-profile "default" ! wlan ssid-profile "a-dot1x" essid "a-dot1x" opmode wpa2-aes ! wlan ssid-profile "a-guest" essid "a-guest" ! wlan ssid-profile "Aruba-PSK" essid "Aruba-PSK" wpa-passphrase 57534a07d6a4f816f3c229e0cf07bc373c0217cae563db99 opmode wpa2-psk-aes ! wlan ssid-profile "default" ! wlan hotspot advertisement-profile "default" ! wlan hotspot hs2-profile "default" ! --More-- (q) quit (u) pageup (/) search (n) repeat wlan virtual-ap "a-dot1x" aaa-profile "a-dot1x" vlan 1 ssid-profile "a-dot1x" ! wlan virtual-ap "a-guest" aaa-profile "a-guest" vlan 99 ssid-profile "a-guest" ! wlan virtual-ap "Aruba-PSK" aaa-profile "Aruba-PSK" vlan 1 ssid-profile "Aruba-PSK" ! wlan virtual-ap "default" ! mgmt-server profile "default-acp" stats-enable tag-enable sessions-enable monitored-info-enable monitored-info-del-enable --More-- (q) quit (u) pageup (/) search (n) repeat monitored-info-snapshot-enable wids-event-info-enable misc-enable location-enable uccmonitoring-enable airgroupinfo-enable wan-state ! mgmt-server profile "default-ale" stats-enable tag-enable sessions-enable misc-enable location-enable uccmonitoring-enable ! mgmt-server profile "default-amp" stats-enable tag-enable sessions-enable user-visibility-enable misc-enable location-enable --More-- (q) quit (u) pageup (/) search (n) repeat ! mgmt-server profile "default-controller" stats-enable tag-enable sessions-enable user-visibility-enable misc-enable location-enable uccmonitoring-enable airgroupinfo-enable wan-state ap-stats ! mgmt-server profile "default-niara" no generic-amon-enable sessions-enable no inline-dhcp-stats no inline-ap-stats no inline-auth-stats no inline-dns-stats ! ap authorization-profile "default" ap-authorization-group "NoAuthApGroup" --More-- (q) quit (u) pageup (/) search (n) repeat ! ap provisioning-profile "default" ! rf arm-rf-domain-profile ! ap am-filter-profile "default" ! ap spectrum local-override ! airmatch profile ! ap-lacp-striping-ip ! ap general-profile ! ap deploy-profile ! ap provisioning-rules ! ap-group "Aruba-Demo" virtual-ap "a-dot1x" virtual-ap "a-guest" virtual-ap "Aruba-PSK" --More-- (q) quit (u) pageup (/) search (n) repeat ! ap-group "default" ! ap-group "NoAuthApGroup" enet1-port-profile "NoAuthWiredPort" enet2-port-profile "NoAuthWiredPort" enet3-port-profile "NoAuthWiredPort" enet4-port-profile "NoAuthWiredPort" ap-system-profile "NoAuthApSystem" ! airgroupprofile service "default-airplay" id "_airplay._tcp" id "_appletv-v2._tcp" id "_raop._tcp" description "AirPlay" ! airgroupprofile service "default-airprint" id "_canon-bjnp1._tcp" id "_fax-ipp._tcp" id "_http-alt._tcp" id "_http._tcp" id "_ica-networking._tcp" id "_ica-networking2._tcp" --More-- (q) quit (u) pageup (/) search (n) repeat id "_ipp-tls._tcp" id "_ipp._tcp" id "_ipps._tcp" id "_pdl-datastream._tcp" id "_printer._tcp" id "_ptp._tcp" id "_riousbprint._tcp" description "AirPrint" ! airgroupprofile service "default-allowall" description "Remaining-Services" ! airgroupprofile service "default-amazontv" id "_amzn-wplay._tcp" description "Amazon fire tv" ! airgroupprofile service "default-dial" id "urn:dial-multiscreen-org:device:dial:1" id "urn:dial-multiscreen-org:service:dial:1" description "DIAL supported by Chromecast, FireTV, Roku etc" ! airgroupprofile service "default-dlna-media" id "urn:schemas-upnp-org:device:MediaPlayer:1" --More-- (q) quit (u) pageup (/) search (n) repeat id "urn:schemas-upnp-org:device:MediaRenderer:1" id "urn:schemas-upnp-org:device:MediaRenderer:2" id "urn:schemas-upnp-org:device:MediaRenderer:3" id "urn:schemas-upnp-org:device:MediaServer:1" id "urn:schemas-upnp-org:device:MediaServer:2" id "urn:schemas-upnp-org:device:MediaServer:3" id "urn:schemas-upnp-org:device:MediaServer:4" id "urn:schemas-upnp-org:device:ZonePlayer:1" id "urn:schemas-upnp-org:service:AVTransport:1" id "urn:schemas-upnp-org:service:AlarmClock:1" id "urn:schemas-upnp-org:service:ConnectionManager:1" id "urn:schemas-upnp-org:service:ContentDirectory:1" id "urn:schemas-upnp-org:service:DeviceProperties:1" id "urn:schemas-upnp-org:service:GroupManagement:1" id "urn:schemas-upnp-org:service:GroupRenderingControl:1" id "urn:schemas-upnp-org:service:MusicServices:1" id "urn:schemas-upnp-org:service:RenderingControl:1" id "urn:schemas-upnp-org:service:SystemProperties:1" id "urn:schemas-upnp-org:service:ZoneGroupTopology:1" description "Media" ! airgroupprofile service "default-dlna-print" id "urn:schemas-upnp-org:device:Printer:1" --More-- (q) quit (u) pageup (/) search (n) repeat id "urn:schemas-upnp-org:service:PrintBasic:1" id "urn:schemas-upnp-org:service:PrintEnhanced:1" description "Print" ! airgroupprofile service "default-googlecast" id "_googlecast._tcp" id "_googlezone._tcp" description "GoogleCast supported by Chromecast etc" ! airgroupprofile service "default-itunes" id "_apple-mobdev._tcp" id "_daap._tcp" id "_dacp._tcp" id "_home-sharing._tcp" description "iTunes" ! airgroupprofile service "default-remotemgmt" id "_ftp._tcp" id "_net-assistant._tcp" id "_rfb._tcp" id "_sftp-ssh._tcp" id "_ssh._tcp" id "_telnet._tcp" --More-- (q) quit (u) pageup (/) search (n) repeat description "Remote management" ! airgroupprofile service "default-sharing" id "_afpovertcp._tcp" id "_odisk._tcp" id "_xgrid._tcp" description "Sharing" ! airgroupprofile ipv6 "default" ! airgroupprofile "default" service "default-airplay" service "default-airprint" service "default-dial" disallow-vlan type servers service "" disallow-role "" type servers service "" ! logging security subcat ids level warnings logging security subcat ids-ap level warnings snmp-server enable trap snmp-server trap source 0.0.0.0 snmp-server trap disable wlsxAPBROADCASTSTORM --More-- (q) quit (u) pageup (/) search (n) repeat snmp-server trap disable wlsxAPIPConflict snmp-server trap disable wlsxAPLoopDetected snmp-server trap disable wlsxAPPortDown snmp-server trap disable wlsxAPPortUp snmp-server trap disable wlsxAceUsageThreshold snmp-server trap disable wlsxAdhocNetwork snmp-server trap disable wlsxAdhocNetworkBridgeDetectedAP snmp-server trap disable wlsxAdhocNetworkBridgeDetectedSta snmp-server trap disable wlsxAdhocUsingValidSSID snmp-server trap disable wlsxAuthMaxAclEntries snmp-server trap disable wlsxAuthMaxBWContracts snmp-server trap disable wlsxAuthMaxUserEntries snmp-server trap disable wlsxAuthServerIsUp snmp-server trap disable wlsxAuthServerReqTimedOut snmp-server trap disable wlsxAuthServerTimedOut snmp-server trap disable wlsxCLEARPASSSERVERINVALID snmp-server trap disable wlsxChannelChanged snmp-server trap disable wlsxCoverageHoleDetected snmp-server trap disable wlsxDBCommunicationFailure snmp-server trap disable wlsxDisconnectStationAttack snmp-server trap disable wlsxESIServerDown snmp-server trap disable wlsxESIServerUp snmp-server trap disable wlsxFanAbsent --More-- (q) quit (u) pageup (/) search (n) repeat snmp-server trap disable wlsxFanFailure snmp-server trap disable wlsxFanTrayInserted snmp-server trap disable wlsxFanTrayRemoved snmp-server trap disable wlsxGBICInserted snmp-server trap disable wlsxHaFailoverRequestFromAp snmp-server trap disable wlsxHaFailoverTrigger snmp-server trap disable wlsxHaIntercontrollerHbtMiss snmp-server trap disable wlsxHaStandbyConnectivityState snmp-server trap disable wlsxHaStandbyIpSentFailed snmp-server trap disable wlsxHaState snmp-server trap disable wlsxIpSpoofingDetected snmp-server trap disable wlsxLCInserted snmp-server trap disable wlsxLCRemoved snmp-server trap disable wlsxLicenseExpiry snmp-server trap disable wlsxLowMemory snmp-server trap disable wlsxLowOnFlashSpace snmp-server trap disable wlsxNAceUsageThreshold snmp-server trap disable wlsxNFanAbsent snmp-server trap disable wlsxNWebCCLicenseEnforcement snmp-server trap disable wlsxOutOfRangeTemperature snmp-server trap disable wlsxOutOfRangeVoltage snmp-server trap disable wlsxPowerSupplyFailure snmp-server trap disable wlsxPowerSupplyMissing --More-- (q) quit (u) pageup (/) search (n) repeat snmp-server trap disable wlsxProcessDied snmp-server trap disable wlsxProcessExceedsMemoryLimits snmp-server trap disable wlsxSCInserted snmp-server trap disable wlsxSignatureMatch snmp-server trap disable wlsxStaUnAssociatedFromUnsecureAP snmp-server trap disable wlsxStationAddedToBlackList snmp-server trap disable wlsxStationRemovedFromBlackList snmp-server trap disable wlsxSwitchIPChanged snmp-server trap disable wlsxSwitchRoleChange snmp-server trap disable wlsxUserAuthenticationFailed snmp-server trap disable wlsxUserEntryAuthenticated snmp-server trap disable wlsxUserEntryChanged snmp-server trap disable wlsxUserEntryCreated snmp-server trap disable wlsxUserEntryDeAuthenticated snmp-server trap disable wlsxUserEntryDeleted snmp-server trap disable wlsxVrrpStateChange snmp-server trap disable wlsxWebCCLicenseEnforcement process monitor log ip probe default mode Ping frequency 10 --More-- (q) quit (u) pageup (/) search (n) repeat retries 3 burst-size 5 ! ip probe health-check mode Ping frequency 10 retries 3 burst-size 5 ! ip probe data-vpnc mode Udp frequency 10 retries 3 burst-size 5 jitter ! end (MC-1) [mynode] #