login as: admin admin@167.21.184.101's password: Last login: Thu Jun 15 11:01:28 2017 from 167.21.184.135 (DSU-Wireless-01) >en Password:****** (DSU-Wireless-01) #show running-config Building Configuration... version 6.3 enable secret "******" hostname "DSU-Wireless-01" clock timezone EST -5 location "GrossleyHall" controller config 107 ip NAT pool dynamic-srcnat 0.0.0.0 0.0.0.0 ip access-list eth validuserethacl permit any ! netservice svc-netbios-dgm udp 138 netservice svc-snmp-trap udp 162 netservice svc-pcoip2-tcp tcp 4172 netservice svc-syslog udp 514 netservice svc-l2tp udp 1701 netservice svc-ike udp 500 netservice svc-smb-tcp tcp 445 netservice svc-citrix tcp 2598 netservice svc-dhcp udp 67 68 alg dhcp netservice svc-https tcp 443 netservice svc-pptp tcp 1723 netservice svc-ica tcp 1494 netservice svc-sccp tcp 2000 alg sccp netservice svc-http-accl tcp 88 netservice svc-telnet tcp 23 netservice svc-sec-papi udp 8209 netservice svc-lpd tcp 515 netservice svc-netbios-ssn tcp 139 netservice svc-sip-tcp tcp 5060 netservice svc-kerberos udp 88 netservice svc-tftp udp 69 alg tftp netservice svc-http-proxy3 tcp 8888 netservice svc-noe udp 32512 alg noe netservice svc-cfgm-tcp tcp 8211 netservice svc-adp udp 8200 netservice svc-pop3 tcp 110 netservice svc-pcoip-tcp tcp 50002 netservice svc-pcoip-udp udp 50002 netservice svc-lpd-tcp tcp 631 netservice svc-rtsp tcp 554 alg rtsp netservice svc-msrpc-tcp tcp 135 139 netservice svc-dns udp 53 alg dns netservice svc-h323-udp udp 1718 1719 netservice svc-h323-tcp tcp 1720 netservice svc-vocera udp 5002 alg vocera netservice svc-http tcp 80 netservice vnc tcp 5900 5905 netservice svc-http-proxy2 tcp 8080 netservice svc-sip-udp udp 5060 netservice svc-nterm tcp 1026 1028 netservice svc-noe-oxo udp 5000 alg noe netservice svc-papi udp 8211 netservice svc-natt udp 4500 netservice svc-ftp tcp 21 alg ftp netservice svc-microsoft-ds tcp 445 netservice svc-svp 119 alg svp netservice svc-smtp tcp 25 netservice svc-gre 47 netservice svc-netbios-ns udp 137 netservice svc-sips tcp 5061 alg sips netservice svc-smb-udp udp 445 netservice web tcp list "80 443" netservice svc-ipp-tcp tcp 631 netservice svc-cups tcp 515 netservice svc-esp 50 netservice svc-v6-dhcp udp 546 547 netservice svc-snmp udp 161 netservice svc-bootp udp 67 69 netservice svc-pcoip2-udp udp 4172 netservice svc-msrpc-udp udp 135 139 netservice svc-ntp udp 123 netservice svc-icmp 1 netservice svc-ipp-udp udp 631 netservice svc-ssh tcp 22 netservice svc-lpd-udp udp 631 netservice svc-v6-icmp 58 netservice svc-http-proxy1 tcp 3128 netservice svc-vmware-rdp tcp 3389 netdestination6 ipv6-reserved-range invert network 2000::/3 ! netdestination www.desu.edu name www.desu.edu ! netexthdr default ! time-range night-hours periodic weekday 18:01 to 23:59 weekday 00:00 to 07:59 ! time-range weekend periodic weekend 00:00 to 23:59 ! time-range working-hours periodic weekday 08:00 to 18:00 ! ip access-list session allow-desu-edu user alias www.desu.edu svc-http permit user alias www.desu.edu svc-https permit ! ip access-list session v6-icmp-acl ipv6 any any svc-v6-icmp permit ! ip access-list session control any any svc-papi permit any any svc-sec-papi permit user any udp 68 deny any any svc-icmp permit any any svc-dns permit any any svc-cfgm-tcp permit any any svc-adp permit any any svc-tftp permit any any svc-dhcp permit any any svc-natt permit ! ip access-list session allow-diskservices any any svc-netbios-dgm permit any any svc-netbios-ssn permit any any svc-microsoft-ds permit any any svc-netbios-ns permit ! ip access-list session validuser network 169.254.0.0 255.255.0.0 any any deny network 127.0.0.0 255.0.0.0 any any deny network 224.0.0.0 240.0.0.0 any any deny host 255.255.255.255 any any deny network 240.0.0.0 240.0.0.0 any any deny any any any permit ipv6 host fe80:: any any deny ipv6 network fc00::/7 any any permit ipv6 network fe80::/64 any any permit ipv6 alias ipv6-reserved-range any any deny ipv6 any any any permit ! ip access-list session v6-https-acl ipv6 any any svc-https permit ! ip access-list session vocera-acl any any svc-vocera permit queue high ! ip access-list session vmware-acl ! ip access-list session icmp-acl any any svc-icmp permit ! ip access-list session v6-control ipv6 any any svc-papi permit ipv6 any any svc-sec-papi permit ipv6 user any udp 547 deny ipv6 any any svc-v6-icmp permit ipv6 any any svc-dns permit ipv6 any any svc-cfgm-tcp permit ipv6 any any svc-adp permit ipv6 any any svc-tftp permit ipv6 any any svc-dhcp permit ipv6 any any svc-natt permit ! ip access-list session v6-dhcp-acl ipv6 any any svc-v6-dhcp permit ! ip access-list session captiveportal user alias controller svc-https dst-nat 8081 user any svc-http dst-nat 8080 user any svc-https dst-nat 8081 user any svc-http-proxy1 dst-nat 8088 user any svc-http-proxy2 dst-nat 8088 user any svc-http-proxy3 dst-nat 8088 ! ip access-list session v6-dns-acl ipv6 any any svc-dns permit ! ip access-list session allowall any any any permit ipv6 any any any permit ! ip access-list session lync-acl any any svc-sips permit queue high ! ip access-list session dsu-guest-web-acle user host 167.21.184.18 svc-http permit user host 167.21.184.18 svc-https permit user alias www.desu.edu any permit ! ip access-list session https-acl any any svc-https permit ! ip access-list session sip-acl any any svc-sip-udp permit queue high any any svc-sip-tcp permit queue high ! ip access-list session dns-acl any any svc-dns permit ! ip access-list session citrix-acl ! ip access-list session ra-guard ipv6 user any icmpv6 rtr-adv deny ! ip access-list session v6-allowall ipv6 any any any permit ! ip access-list session tftp-acl any any svc-tftp permit ! ip access-list session skinny-acl any any svc-sccp permit queue high ! ip access-list session srcnat user any any src-nat ! ip access-list session vpnlogon user any svc-ike permit user any svc-esp permit any any svc-l2tp permit any any svc-pptp permit any any svc-gre permit ! ip access-list session logon-control user any udp 68 deny any any svc-icmp permit any any svc-dns permit any any svc-dhcp permit any any svc-natt permit any network 169.254.0.0 255.255.0.0 any deny any network 240.0.0.0 240.0.0.0 any deny ! ip access-list session allow-printservices any any svc-lpd permit any any svc-ipp-tcp permit any any svc-ipp-udp permit ! ip access-list session dsu-secure-logon user any udp 68 deny any any svc-dhcp permit any any svc-natt permit user any tcp 135 permit user any tcp 139 permit user any tcp 389 permit user any udp 389 permit user any tcp 636 permit user any tcp 3268 permit user any tcp 3269 permit user any tcp 88 permit user any udp 88 permit user any tcp 445 permit user any udp 445 permit user any tcp 464 permit user any udp 464 permit user any udp 123 permit user any udp 137 permit user any udp 138 permit user any tcp 53 permit user any udp 53 permit user any tcp 5722 permit user any tcp 9389 permit user any tcp 49152 65535 permit ! ip access-list session cplogout user alias controller svc-https dst-nat 8081 ! ip access-list session v6-http-acl ipv6 any any svc-http permit ! ip access-list session http-acl any any svc-http permit ! ip access-list session dhcp-acl any any svc-dhcp permit ! ip access-list session captiveportal6 ipv6 user alias controller6 svc-https captive ipv6 user any svc-http captive ipv6 user any svc-https captive ipv6 user any svc-http-proxy1 captive ipv6 user any svc-http-proxy2 captive ipv6 user any svc-http-proxy3 captive ! ip access-list session ap-uplink-acl any any udp 68 permit any any svc-icmp permit any host 224.0.0.251 udp 5353 permit ! ip access-list session RDP any any tcp 3389 permit ! ip access-list session dynamic-session-acl any any any src-nat pool dynamic-srcnat ! ip access-list session noe-acl any any svc-noe permit queue high ! ip access-list session svp-acl any any svc-svp permit queue high user host 224.0.1.116 any permit ! ip access-list session ap-acl any any svc-gre permit any any svc-syslog permit any user svc-snmp permit user any svc-snmp-trap permit user any svc-ntp permit user alias controller svc-ftp permit ! ip access-list session v6-ap-acl ipv6 any any svc-gre permit ipv6 any any svc-syslog permit ipv6 any user svc-snmp permit ipv6 user any svc-snmp-trap permit ipv6 user any svc-ntp permit ipv6 user alias controller6 svc-ftp permit ! ip access-list session v6-logon-control ipv6 user any udp 68 deny ipv6 any any svc-v6-icmp permit ipv6 any any svc-v6-dhcp permit ipv6 any any svc-dns permit ipv6 any network fc00::/7 any permit ipv6 any network fe80::/64 any permit ipv6 any alias ipv6-reserved-range any deny ! ip access-list session h323-acl any any svc-h323-tcp permit queue high any any svc-h323-udp permit queue high ! vpn-dialer default-dialer ike authentication PRE-SHARE ****** ! user-role dsu-machine-auth access-list session dsu-secure-logon access-list session RDP ! user-role dsu-guest-logon vlan 741 captive-portal "DSU-Guest" access-list session cplogout access-list session dsu-guest-web-acle access-list session logon-control access-list session captiveportal ! user-role ap-role access-list session ra-guard access-list session control access-list session ap-acl access-list session v6-control access-list session v6-ap-acl ! user-role denyall ! user-role test3-guest-logon access-list session logon-control access-list session captiveportal ! user-role dsu-guest vlan 741 no captive-portal check-for-accounting access-list session allowall access-list session ra-guard access-list session http-acl access-list session https-acl access-list session dhcp-acl access-list session icmp-acl access-list session dns-acl access-list session v6-http-acl access-list session v6-https-acl access-list session v6-dhcp-acl access-list session v6-icmp-acl access-list session v6-dns-acl ! user-role default-vpn-role access-list session ra-guard access-list session allowall access-list session v6-allowall ! user-role cpbase ! user-role voice access-list session ra-guard access-list session sip-acl access-list session noe-acl access-list session svp-acl access-list session vocera-acl access-list session skinny-acl access-list session h323-acl access-list session dhcp-acl access-list session tftp-acl access-list session dns-acl access-list session icmp-acl ! user-role default-via-role access-list session allowall ! user-role dsu-employee vlan 741 access-list session allowall ! user-role guest-logon captive-portal "DSU_Wireless-cp_prof" access-list session ra-guard access-list session logon-control access-list session captiveportal access-list session v6-logon-control access-list session captiveportal6 ! user-role guest no captive-portal check-for-accounting access-list session ra-guard access-list session http-acl access-list session https-acl access-list session dhcp-acl access-list session icmp-acl access-list session dns-acl access-list session v6-http-acl access-list session v6-https-acl access-list session v6-dhcp-acl access-list session v6-icmp-acl access-list session v6-dns-acl ! user-role dsu-student access-list session allowall ! user-role dsu-secure-auth access-list session allowall ! user-role stateful-dot1x ! user-role authenticated access-list session ra-guard access-list session allowall access-list session v6-allowall ! user-role test2-guest-logon captive-portal "test2-cp_prof" access-list session logon-control access-list session captiveportal ! user-role logon access-list session ra-guard access-list session logon-control access-list session captiveportal access-list session vpnlogon access-list session v6-logon-control access-list session captiveportal6 ! ! controller-ip vlan 710 interface mgmt dhcp ip address 167.21.184.101 255.255.255.0 ! dialer group evdo_us init-string ATQ0V1E0 dial-string ATDT#777 ! dialer group gsm_us init-string AT+CGDCONT=1,"IP","ISP.CINGULAR" dial-string ATD*99# ! dialer group gsm_asia init-string AT+CGDCONT=1,"IP","internet" dial-string ATD*99***1# ! dialer group vivo_br init-string AT+CGDCONT=1,"IP","zap.vivo.com.br" dial-string ATD*99# ! vlan 52 vlan 446 vlan 472 vlan 478 vlan 618 vlan 621 vlan 710 vlan 711 vlan 715 vlan 716 vlan 718 vlan 721 vlan 724 vlan 740 vlan 741 vlan 813 vlan-name Admin vlan Admin 711,721 vlan-name Admin2 vlan Admin2 711,716,721 vlan-name dsu-secure assignment even vlan dsu-secure 740 no spanning-tree interface gigabitethernet 0/0 description "GE0/0" trusted trusted vlan 1-4094 switchport mode trunk switchport trunk allowed vlan 52,446,472,478,618,621,710-711,715-716,718,721,724,740-741,813 ! interface gigabitethernet 0/1 description "GE0/1" trusted trusted vlan 1-4094 ! interface gigabitethernet 0/2 description "GE0/2" trusted trusted vlan 1-4094 ! interface gigabitethernet 0/3 description "GE0/3" trusted trusted vlan 1-4094 ! interface gigabitethernet 0/4 description "GE0/4" trusted trusted vlan 1-4094 ! interface gigabitethernet 0/5 description "GE0/5" trusted trusted vlan 1-4094 ! interface gigabitethernet 0/6 description "GE0/6" trusted trusted vlan 1-4094 ! interface gigabitethernet 0/7 description "GE0/7" trusted trusted vlan 1-4094 ! interface gigabitethernet 0/8 description "GE0/8" trusted trusted vlan 1-4094 ! interface gigabitethernet 0/9 description "GE0/9" trusted trusted vlan 1-4094 ! interface gigabitethernet 0/10 description "XG0/10" trusted trusted vlan 1-4094 ! interface gigabitethernet 0/11 description "XG0/11" trusted trusted vlan 1-4094 ! interface vlan 710 ip address 192.168.94.251 255.255.255.0 ! interface vlan 1 ip address 172.16.0.254 255.255.255.0 ! interface vlan 52 ip address 192.168.2.154 255.255.254.0 ! interface vlan 724 ip address 192.168.180.251 255.255.252.0 ip helper-address 192.168.2.23 ! interface vlan 715 ! interface vlan 446 ip address dhcp-client ! interface vlan 716 ! interface vlan 621 ip address 192.168.87.249 255.255.255.0 ! interface vlan 478 ip address dhcp-client ! interface vlan 741 ip address 192.168.243.252 255.255.252.0 no ip routing ! ip default-gateway 192.168.94.1 ip route 167.21.184.0 255.255.255.0 167.21.184.1 uplink disable ap mesh-recovery-profile cluster RecoveryM8U5e1g4kNk8ZdDJ wpa-hexkey 90bfc9d1a6f9e320e31745dc7c8489d5aa27d974cf61a77071b2943333f26acf660a22ced517a821177964879d633b335b5c667dbdaf9e60969ecee0d6ebc4d0e4f5feeec260566d29f82820f23b1f60 crypto isakmp policy 20 encryption aes256 ! crypto ipsec transform-set default-boc-bm-transform esp-3des esp-sha-hmac crypto ipsec transform-set default-rap-transform esp-aes256 esp-sha-hmac crypto ipsec transform-set default-aes esp-aes256 esp-sha-hmac crypto dynamic-map default-dynamicmap 10000 set transform-set "default-transform" "default-aes" ! crypto isakmp eap-passthrough eap-tls crypto isakmp eap-passthrough eap-peap crypto isakmp eap-passthrough eap-mschapv2 vpdn group l2tp ! ! snmp-server community "Feb4dufadreWesTeNAV9kEs9fruRe7" snmp-server community "aruba123" snmp-server community "jg!4rr@ei#1" snmp-server community "test" vpdn group pptp ! tunneled-node-address 0.0.0.0 adp discovery enable adp igmp-join enable adp igmp-vlan 0 voice rtcp-inactivity disable voice alg-based-cac enable voice sip-midcall-req-timeout disable ap ap-blacklist-time 3600 ap flush-r1-on-new-r0 disable no ssh mgmt-auth public-key ssh mgmt-auth username/password mgmt-user admin root 3233820701b83d9b63083f2151e6cd3693aa450ab5a30e0ac9 mgmt-user harryS root 7a365e4001c27984e4f4015af717151942e0b255787458788f mgmt-user jim root a866d122012bfc04f63c0ed7763dd743df0ebd844daeeb37b7 mgmt-user mducote root 86ce1a1b01b2f72295c6b9e27196cf5ced8ae69ede7e8bd064 mgmt-user rweaver root 5fc9ba6e015d42c184560dc6931ba6013e6a6ec578929d8d5d mgmt-user tmata root 7af6211001fd772f60f428e565154e7f1571b8af995180a2a8 mgmt-user wgrimes root 83b52ca10128d06bfe5477d70ef0240b0735efb161da07568d ntp server 192.168.2.11 no database synchronize ip mobile domain default ! ! ! airgroup "enable" ! airgroup location-discovery "enable" ! ! airgroup active-wireless-discovery "disable" ! airgroupservice "airplay" id "_airplay._tcp" id "_raop._tcp" id "_appletv-v2._tcp" description "AirPlay" ! airgroupservice "airprint" id "_ipp._tcp" id "_pdl-datastream._tcp" id "_printer._tcp" id "_scanner._tcp" id "_universal._sub._ipp._tcp" id "_universal._sub._ipps._tcp" id "_printer._sub._http._tcp" id "_http._tcp" id "_http-alt._tcp" id "_ipp-tls._tcp" id "_fax-ipp._tcp" id "_riousbprint._tcp" id "_cups._sub._ipp._tcp" id "_cups._sub._fax-ipp._tcp" id "_ica-networking._tcp" id "_ptp._tcp" id "_canon-bjnp1._tcp" id "_ipps._tcp" id "_ica-networking2._tcp" description "AirPrint" ! airgroupservice "itunes" id "_home-sharing._tcp" id "_apple-mobdev._tcp" id "_daap._tcp" id "_dacp._tcp" description "iTunes" ! airgroupservice "remotemgmt" id "_ssh._tcp" id "_sftp-ssh._tcp" id "_ftp._tcp" id "_telnet._tcp" id "_rfb._tcp" id "_net-assistant._tcp" description "Remote management" ! airgroupservice "sharing" id "_odisk._tcp" id "_afpovertcp._tcp" id "_xgrid._tcp" description "Sharing" ! airgroupservice "chat" id "_presence._tcp" description "Chat" ! airgroupservice "allowall" description "Remaining-Services" ! airgroup service "airplay" enable ! airgroup service "airprint" enable ! airgroup service "itunes" disable ! airgroup service "remotemgmt" disable ! airgroup service "sharing" disable ! airgroup service "chat" disable ! airgroup service "allowall" disable ! ip igmp ! ipv6 mld ! no firewall attack-rate cp 1024 firewall attack-rate grat-arp 50 drop ipv6 firewall ext-hdr-parse-len 100 ! ! firewall cp packet-capture-defaults controlpath other ! ip domain lookup ! ! country US aaa rfc-3576-server "167.21.184.23" ! aaa rfc-3576-server "167.21.184.24" ! aaa rfc-3576-server "167.21.184.25" ! aaa rfc-3576-server "167.21.184.26" ! aaa authentication mac "default" ! aaa authentication dot1x "default" ! aaa authentication dot1x "dot1x_prof-cqs67" machine-authentication machine-default-role "authenticated" machine-authentication user-default-role "authenticated" termination eap-type eap-peap termination inner-eap-type eap-mschapv2 ! aaa authentication dot1x "dot1x_prof-dkm21" ! aaa authentication dot1x "dot1x_prof-ewz79" termination enable termination eap-type eap-peap termination inner-eap-type eap-mschapv2 ! aaa authentication dot1x "dot1x_prof-gov78" termination enable termination eap-type eap-peap termination inner-eap-type eap-mschapv2 ! aaa authentication dot1x "dot1x_prof-kto20" ! aaa authentication dot1x "dot1x_prof-mhb94" termination enable termination eap-type eap-peap termination inner-eap-type eap-mschapv2 ! aaa authentication dot1x "dot1x_prof-mxb34" ! aaa authentication dot1x "dsu-secure-dot1x" termination eap-type eap-tls termination eap-type eap-peap termination inner-eap-type eap-mschapv2 ! aaa authentication-server radius "ADM3" host "192.168.2.125" key 560bbdb2dff4063ca27e7c731d89bb690cc1d62c6173b9c9 ! aaa authentication-server radius "ADMDC3" host "192.168.2.28" key 1c794cff1bde77a0403fe604c510360024fe9ec7407d82a71a3613dd69bbef900bf0fff59520695f1306e004d8928539 ! aaa authentication-server radius "cppm01" host "167.21.184.23" key 72389f34c87c784755812932fc46f551b612f956a1c23941935e614a4f3b33a2b9587675b096c0ec ! aaa authentication-server radius "cppm02" host "167.21.184.24" key d2ff99d86a5735b39475130e4a881a0c96d3d1bac3c0c5487323c4cc407bc7d7d962caaa230daa14 ! aaa authentication-server radius "cppm03" host "167.21.184.25" key 4e6a72da8cb426511972aaa9eb4f9cd4bab448c560759b70b85aeed77136c07d027e0843aea8c605 ! aaa authentication-server radius "cppm04" host "167.21.184.26" key f48e6dd072356460ec396e326c3990954baabeddbc34cf6e8d822214ee2fc502432c07b9ca1f5767 ! aaa authentication-server ldap "Aruba" host 192.168.2.40 admin-dn "CN=bbldap,OU=LDAPAccounts,DC=adminst,DC=desu,DC=edu" admin-passwd fc193841c8c326932b67399fb86d676d42167f3f930e914b allow-cleartext base-dn "Admdc1" key-attribute "samAccountName" preferred-conn-type clear-text ! aaa server-group "cppm" auth-server cppm04 auth-server cppm03 auth-server cppm02 auth-server cppm01 ! aaa server-group "default" auth-server Internal set role condition role value-of ! aaa server-group "DSU_Student_srvgrp-fmp41" auth-server ADM3 ! aaa server-group "test2_srvgrp-ouf69" auth-server Internal ! aaa server-group "test_srvgrp-ezt49" auth-server Aruba ! aaa server-group "test_srvgrp-pkl04" auth-server ADM3 ! aaa server-group "TestOpenHouse_srvgrp-ekr23" auth-server ADM3 ! aaa profile "Admin_Wireless-aaa_prof" initial-role "authenticated" ! aaa profile "default" ! aaa profile "dsu-guest-aaa-prof" initial-role "dsu-guest-logon" authentication-mac "default" mac-default-role "dsu-guest" mac-server-group "cppm" dot1x-default-role "dsu-guest" radius-accounting "cppm" radius-interim-accounting rfc-3576-server "167.21.184.23" rfc-3576-server "167.21.184.24" rfc-3576-server "167.21.184.25" rfc-3576-server "167.21.184.26" ! aaa profile "dsu-secure-aaa-prof" authentication-dot1x "dsu-secure-dot1x" dot1x-server-group "cppm" radius-accounting "cppm" radius-interim-accounting rfc-3576-server "167.21.184.23" rfc-3576-server "167.21.184.24" rfc-3576-server "167.21.184.25" rfc-3576-server "167.21.184.26" ! aaa profile "DSU_Student-aaa_prof" authentication-dot1x "dot1x_prof-mxb34" dot1x-default-role "authenticated" dot1x-server-group "DSU_Student_srvgrp-fmp41" ! aaa profile "DSU_Wireless-aaa_prof" initial-role "authenticated" ! aaa profile "Nursing110-aaa_prof" initial-role "authenticated" ! aaa profile "test-aaa_prof" authentication-dot1x "default" dot1x-default-role "logon" ! aaa profile "test2-aaa_prof" initial-role "test3-guest-logon" ! aaa profile "TestOpenHouse-aaa_prof" authentication-dot1x "dot1x_prof-cqs67" dot1x-default-role "authenticated" dot1x-server-group "TestOpenHouse_srvgrp-ekr23" ! aaa authentication captive-portal "Admin_Wireless-cp_prof" show-acceptable-use-policy ! aaa authentication captive-portal "CP-cp_prof" default-role "guest-logon" default-guest-role "guest-logon" ! aaa authentication captive-portal "default" ! aaa authentication captive-portal "dell-ap-cp_prof" ! aaa authentication captive-portal "DSU-Guest" default-role "dsu-guest" server-group "cppm" redirect-pause 0 no logout-popup-window login-page "https://guest.desu.edu/guest/home.php" welcome-page "https://www.desu.edu" no enable-welcome-page ! aaa authentication captive-portal "DSU_Wireless-cp_prof" no user-logon show-acceptable-use-policy ! aaa authentication captive-portal "test2-cp_prof" ! aaa authentication captive-portal "test3-cp_prof" ! aaa authentication wispr "default" ! aaa authentication vpn "default" ! aaa authentication vpn "default-rap" ! aaa authentication mgmt ! aaa authentication stateful-ntlm "default" ! aaa authentication stateful-kerberos "default" ! aaa authentication stateful-dot1x ! aaa authentication wired ! web-server profile session-timeout 3600 ! guest-access-email ! voice logging ! voice dialplan-profile "default" ! voice real-time-config ! voice sip ! aaa password-policy mgmt ! control-plane-security no cpsec-enable ! ids wms-general-profile poll-retries 3 collect-stats ! ids wms-local-system-profile ! valid-network-oui-profile ! upgrade-profile ! license profile ! activate-service-whitelist ! ifmap cppm ! ap system-profile "default" ! ap regulatory-domain-profile "default" country-code US valid-11g-channel 1 valid-11g-channel 6 valid-11g-channel 11 valid-11a-channel 36 valid-11a-channel 40 valid-11a-channel 44 valid-11a-channel 48 valid-11a-channel 149 valid-11a-channel 153 valid-11a-channel 157 valid-11a-channel 161 valid-11a-channel 165 valid-11g-40mhz-channel-pair 1-5 valid-11g-40mhz-channel-pair 7-11 valid-11a-40mhz-channel-pair 36-40 valid-11a-40mhz-channel-pair 44-48 valid-11a-40mhz-channel-pair 149-153 valid-11a-40mhz-channel-pair 157-161 ! ap wired-ap-profile "default" ! ap enet-link-profile "default" ! ap mesh-ht-ssid-profile "default" ! ap lldp med-network-policy-profile "default" ! ap mesh-cluster-profile "default" ! ap lldp profile "default" ! ap mesh-radio-profile "default" ! ap wired-port-profile "default" ! ids general-profile "default" ! ids unauthorized-device-profile "default" ! ids profile "default" ! rf arm-profile "arm-maintain" assignment maintain no scanning ! rf arm-profile "arm-scan" ! rf arm-profile "default" ! rf optimization-profile "default" ! rf event-thresholds-profile "default" ! rf am-scan-profile "default" ! rf dot11a-radio-profile "default" ! rf dot11a-radio-profile "rp-maintain-a" arm-profile "arm-maintain" ! rf dot11a-radio-profile "rp-monitor-a" mode am-mode ! rf dot11a-radio-profile "rp-scan-a" arm-profile "arm-scan" ! rf dot11g-radio-profile "default" ! rf dot11g-radio-profile "rp-maintain-g" arm-profile "arm-maintain" ! rf dot11g-radio-profile "rp-monitor-g" mode am-mode ! rf dot11g-radio-profile "rp-scan-g" arm-profile "arm-scan" ! wlan handover-trigger-profile "default" ! wlan rrm-ie-profile "default" ! wlan bcn-rpt-req-profile "default" ! wlan dot11r-profile "default" ! wlan tsm-req-profile "default" ! wlan voip-cac-profile "default" ! wlan ht-ssid-profile "Admin_Wireless-htssid_prof" ! wlan ht-ssid-profile "default" ! wlan ht-ssid-profile "DSU-Guest-ht-ssid-profile" ! wlan ht-ssid-profile "dsu-secure-ht-ssid" ! wlan ht-ssid-profile "DSU_Student-htssid_prof" ! wlan ht-ssid-profile "DSU_Wireless-htssid_prof" ! wlan ht-ssid-profile "Nursing110-htssid_prof" ! wlan ht-ssid-profile "test-htssid_prof" ! wlan ht-ssid-profile "test2-htssid_prof" ! wlan ht-ssid-profile "TestOpenHouse-htssid_prof" ! wlan hotspot anqp-venue-name-profile "default" ! wlan hotspot anqp-nwk-auth-profile "default" ! wlan hotspot anqp-roam-cons-profile "default" ! wlan hotspot anqp-nai-realm-profile "default" ! wlan hotspot anqp-3gpp-nwk-profile "default" ! wlan hotspot h2qp-operator-friendly-name-profile "default" ! wlan hotspot h2qp-wan-metrics-profile "default" ! wlan hotspot h2qp-conn-capability-profile "default" ! wlan hotspot h2qp-op-cl-profile "default" ! wlan hotspot anqp-ip-addr-avail-profile "default" ! wlan hotspot anqp-domain-name-profile "default" ! wlan edca-parameters-profile station "default" ! wlan edca-parameters-profile ap "default" ! wlan dot11k-profile "default" ! wlan ssid-profile "Admin_Wireless-ssid_prof" essid "Admin_Wireless" hide-ssid ht-ssid-profile "Admin_Wireless-htssid_prof" ! wlan ssid-profile "default" wmm-vo-dscp "56" wmm-vi-dscp "40" wmm-be-dscp "24" wmm-bk-dscp "8" hide-ssid ! wlan ssid-profile "DSU-Guest-ssid-profile" essid "DSU_Guest" g-basic-rates 11 12 18 24 36 48 54 g-tx-rates 5 6 9 11 12 18 24 36 48 54 hide-ssid mcast-rate-opt ht-ssid-profile "DSU-Guest-ht-ssid-profile" g-beacon-rate 11 ! wlan ssid-profile "dsu-secure-ssid-pro" essid "DSU_Secure" opmode wpa2-aes wmm-vo-dscp "56" wmm-vi-dscp "40" wmm-be-dscp "24" wmm-bk-dscp "8" hide-ssid deny-bcast mcast-rate-opt ht-ssid-profile "dsu-secure-ht-ssid" g-beacon-rate 11 ! wlan ssid-profile "DSU_Student-ssid_prof" essid "DSU_Student" opmode wpa2-aes hide-ssid ht-ssid-profile "DSU_Student-htssid_prof" ! wlan ssid-profile "DSU_Wireless-ssid_prof" essid "DSU_Wireless" wmm-vo-dscp "56" wmm-vi-dscp "40" wmm-be-dscp "24" wmm-bk-dscp "8" ht-ssid-profile "DSU_Wireless-htssid_prof" ! wlan ssid-profile "Nursing110-ssid_prof" essid "Nursing110" hide-ssid ht-ssid-profile "Nursing110-htssid_prof" ! wlan ssid-profile "OpenHouse1" essid "TestOpenHouse" opmode wpa2-aes ! wlan ssid-profile "test-ssid_prof" essid "test" wmm-vo-dscp "56" wmm-vi-dscp "40" wmm-be-dscp "24" wmm-bk-dscp "8" wepkey1 aba5cf949a7d5ea01a22047494764556e39167b79c732b98 ht-ssid-profile "test-htssid_prof" ! wlan ssid-profile "test2-ssid_prof" essid "test3" ht-ssid-profile "test2-htssid_prof" ! wlan ssid-profile "TestOpenHouse-ssid_prof" essid "DSU_Staff" opmode wpa2-aes hide-ssid ht-ssid-profile "TestOpenHouse-htssid_prof" ! wlan hotspot advertisement-profile "default" ! wlan hotspot hs2-profile "default" ! wlan virtual-ap "Admin_Wireless-vap_prof" aaa-profile "default-dot1x" ssid-profile "Admin_Wireless-ssid_prof" vlan 446 ! wlan virtual-ap "default" ! wlan virtual-ap "DSU-Guest-vap-profile" aaa-profile "dsu-guest-aaa-prof" ssid-profile "DSU-Guest-ssid-profile" deny-inter-user-traffic ! wlan virtual-ap "dsu-secure-vap-prof" aaa-profile "dsu-secure-aaa-prof" ssid-profile "dsu-secure-ssid-pro" vlan dsu-secure ! wlan virtual-ap "DSU_Student-vap_prof" aaa-profile "DSU_Student-aaa_prof" ssid-profile "DSU_Student-ssid_prof" vlan Admin2 ! wlan virtual-ap "DSU_Wireless-vap_prof" aaa-profile "DSU_Wireless-aaa_prof" ssid-profile "DSU_Wireless-ssid_prof" vlan Admin2 ! wlan virtual-ap "Nursing110-vap_prof" aaa-profile "Nursing110-aaa_prof" ssid-profile "Nursing110-ssid_prof" vlan 813 ! wlan virtual-ap "test-vap_prof" aaa-profile "test-aaa_prof" ssid-profile "test-ssid_prof" vlan 721 ! wlan virtual-ap "Test1" aaa-profile "test-aaa_prof" ssid-profile "OpenHouse1" vlan 446 ! wlan virtual-ap "test2-vap_prof" aaa-profile "test2-aaa_prof" ssid-profile "test2-ssid_prof" vlan 711 ! wlan virtual-ap "TestOpenHouse-vap_prof" aaa-profile "TestOpenHouse-aaa_prof" ssid-profile "TestOpenHouse-ssid_prof" vlan 478 ! ap provisioning-profile "Admin" ! ap provisioning-profile "default" ! rf arm-rf-domain-profile arm-rf-domain-key "7da18446674573cb69fbe51d59058228" ! ap general-profile ! ap-group "Admin-Public" virtual-ap "DSU_Wireless-vap_prof" virtual-ap "TestOpenHouse-vap_prof" virtual-ap "DSU_Student-vap_prof" virtual-ap "dsu-secure-vap-prof" virtual-ap "DSU-Guest-vap-profile" ! ap-group "Admin1" virtual-ap "TestOpenHouse-vap_prof" virtual-ap "DSU_Wireless-vap_prof" virtual-ap "DSU_Student-vap_prof" ! ap-group "BOA" virtual-ap "DSU_Wireless-vap_prof" virtual-ap "TestOpenHouse-vap_prof" virtual-ap "dsu-secure-vap-prof" virtual-ap "DSU-Guest-vap-profile" ! ap-group "default" virtual-ap "default" ! ap-group "DSU_ITTEST" virtual-ap "test-vap_prof" ! ap-group "Nursing" virtual-ap "Nursing110-vap_prof" virtual-ap "DSU_Wireless-vap_prof" ! airgroup cppm-server aaa ! logging level debugging network subcat dhcp logging level debugging network process dhcpd subcat packet-dump logging level warnings security subcat ids logging level warnings security subcat ids-ap logging level debugging security process authmgr subcat packet-trace logging level debugging user-debug ac:fd:ce:6b:f0:e9 snmp-server enable trap snmp-server host 167.21.184.105 version 2c aruba123 udp-port 162 snmp-server host 167.21.184.63 version 1 aaron1234 udp-port 162 snmp-server host 167.21.184.94 version 2c Feb4dufadreWesTeNAV9kEs9fruRe7 udp-port 162 firewall-visibility process monitor log end (DSU-Wireless-01) #