Table Of Contents
Schools SRA Configuration Supplement
Validated Platforms and Software Versions
Schools SRA Configuration Supplement
Contents
This document, contains the network diagram, and a list of all the platforms and software releases which were validated for the Schools Service Ready Architecture. The last section includes the configurations for each platform (CLI only, no GUI).
Provides a efficient and flexible network architecture for secondary schools, while enabling advanced services, such as security, unified wireless access, unified voice communications services, and presence services. The network is designed to meet the needs of the education environment:
•Academic Excellence
•Administrative Efficiency
•School safety and security
Network Diagram
Figure 1 Physical Topology
Validated Platforms and Software Versions
Network Infrastructure
Emerging Technologies
Configurations
This section contains a copy of the complete configuration for each platform validated in the School Service Ready Architecture validation (only for platforms with CLI configurations, does not include GUI configurations).
Note Externally accessible IP addresses and passwords have been replaced with descriptive text.
District Office
Access
Cr24-2960-DO!! Last configuration change at 22:53:38 EDT Wed Sep 2 2009 by cisco! NVRAM config last updated at 22:53:54 EDT Wed Sep 2 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr24-2960-DO!boot-start-markerboot-end-marker!enable secret 5 $1$XK8W$tZTDCYAq5eBMNKtqjisAw.enable password 7 104D000A0618!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringsystem mtu routing 1500vtp domain District-Officevtp mode transparentip subnet-zero!!ip dhcp snooping vlan 101-110no ip dhcp snooping information optionip dhcp snoopingno ip domain-lookupip arp inspection vlan 101-110ip arp inspection validate src-mac dst-mac ip allow zeros!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!crypto pki trustpoint HTTPS_SS_CERT_KEYPAIRenrollment selfsignedserial-numberrevocation-check nonersakeypair HTTPS_SS_CERT_KEYPAIR!!crypto pki certificate chain HTTPS_SS_CERT_KEYPAIRcertificate self-signed 01 nvram:F9154780host#2E2E.cer!!dot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120port-channel load-balance src-dst-ip!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 101name cr2960_Dept1_VLAN!vlan 102name cr2960_Dept2_VLAN!vlan 103name cr2960_Dept3_VLAN!vlan 104name cr2960_Dept4_VLAN!vlan 105name cr2960_Dept5_VLAN!vlan 106name cr2960_Dept6_VLAN!vlan 107name cr2960_Dept7_VLAN!vlan 108name cr2960_Dept8_VLAN!vlan 109name cr2960_Dept9_VLAN!vlan 110name cr2960_Dept10_VLAN!vlan 201name Guest_VLAN!vlan 802name Hopping_VLAN!vlan 900name Mgmt_VLAN!!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 1000000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 1000000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map Phone+PC-Policyclass VVLAN-VOIPpolice 1000000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 1000000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!interface Loopback0ip address 10.125.100.2 255.255.255.255no ip route-cache!interface Port-channel1description Connected to cr24-4507-DOswitchport trunk native vlan 802switchport trunk allowed vlan 101-110,201,900switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/1description CONNECTED TO UNTRUSTED PCswitchport access vlan 101switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input UnTrusted-PC-Policyip verify source!interface FastEthernet0/2description CONNECTED TO TRUSTED-PCswitchport access vlan 102switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Trusted-PC-Policyip verify source!interface FastEthernet0/3description CONNECTED TO PHONEswitchport mode accessswitchport block unicastswitchport voice vlan 103switchport port-security maximum 2switchport port-security maximum 1 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security violation restrictip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastservice-policy input Phone-Policyip verify source!interface FastEthernet0/4description CONNECTED TO PHONE+PCswitchport access vlan 104switchport mode accessswitchport block unicastswitchport voice vlan 105switchport port-security maximum 3switchport port-security maximum 2 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone+PC-Policyip verify source!interface FastEthernet0/5description CONNECTED TO IPVS 2500 - CAMERAswitchport access vlan 106switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/6description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 107switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/7description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 108switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/8!interface FastEthernet0/9!interface FastEthernet0/10description Connected to IXIA - ALM - 2/1switchport trunk native vlan 802switchport trunk allowed vlan 101-110switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/11description Connected to IXIA - STX - 3/1switchport trunk native vlan 802switchport trunk allowed vlan 101-110switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/12!interface FastEthernet0/13!interface FastEthernet0/14!interface FastEthernet0/15!interface FastEthernet0/16!interface FastEthernet0/17!interface FastEthernet0/18!interface FastEthernet0/19!interface FastEthernet0/20!interface FastEthernet0/21!interface FastEthernet0/22!interface FastEthernet0/23!interface FastEthernet0/24description Connected to FlashNetswitchport mode accessload-interval 30!interface FastEthernet0/25!interface FastEthernet0/26!interface FastEthernet0/27!interface FastEthernet0/28!interface FastEthernet0/29!interface FastEthernet0/30!interface FastEthernet0/31!interface FastEthernet0/32!interface FastEthernet0/33!interface FastEthernet0/34!interface FastEthernet0/35!interface FastEthernet0/36!interface FastEthernet0/37!interface FastEthernet0/38!interface FastEthernet0/39!interface FastEthernet0/40!interface FastEthernet0/41!interface FastEthernet0/42!interface FastEthernet0/43!interface FastEthernet0/44!interface FastEthernet0/45!interface FastEthernet0/46!interface FastEthernet0/47!interface FastEthernet0/48!interface GigabitEthernet0/1description Connected to cr24-4507-DOswitchport trunk native vlan 802switchport trunk allowed vlan 101-110,201,900switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet0/2description Connected to cr24-4507-DOswitchport trunk native vlan 802switchport trunk allowed vlan 101-110,201,900switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet0/3!interface GigabitEthernet0/4!interface Vlan1description Connected to FlashNetip address 172.26.160.188 255.255.254.0no ip redirectsno ip proxy-arpno ip route-cache!interface Vlan900ip address 10.125.34.2 255.255.255.224no ip redirectsno ip unreachablesno ip route-cacheload-interval 30!no ip http serverno ip http secure-server!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255ip access-list standard Deny_PIM_DM_Fallbackdeny 224.0.1.39deny 224.0.1.40permit any!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.31.4 auth-port 1645 acct-port 1646 key 7 01100F1758044A5E731Fradius-server deadtime 1!control-plane!alias exec dsno show ip dhcp snooping bindalias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36028997ntp server 172.26.160.10endCr26-2975-DO!! Last configuration change at 22:53:38 EDT Wed Sep 2 2009 by cisco! NVRAM config last updated at 22:53:54 EDT Wed Sep 2 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr26-2975-DO!boot-start-markerboot-end-marker!enable password 7 094F471A1A0A!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringswitch 1 provision ws-c2975gs-48ps-lswitch 2 provision ws-c2975gs-48ps-lswitch 3 provision ws-c2975gs-48ps-lstack-mac persistent timer 0system mtu routing 1500vtp domain District-Officevtp mode transparentip subnet-zero!!ip dhcp snooping vlan 111-120no ip dhcp snooping information optionip dhcp snoopingno ip domain-lookup!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!!!!dot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery interval 120port-channel load-balance src-dst-ip!spanning-tree mode rapid-pvstspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 2name FlashNet_VLAN!vlan 111-120!vlan 202name Guest_VLAN!vlan 803name Hopping_VLAN!vlan 900name Mgmt_VLAN!!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 32000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map Phone+PC-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!interface Loopback0ip address 10.125.100.3 255.255.255.255!interface Port-channel1description Connected to cr24-4507-DOswitchport trunk native vlan 803switchport trunk allowed vlan 111-120,900switchport mode trunkload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/1description CONNECTED TO UNTRUSTED-PCswitchport access vlan 111switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input UnTrusted-PC-Policy!interface GigabitEthernet1/0/2description CONNECTED TO TRUSTED-PCswitchport access vlan 112switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Trusted-PC-Policy!interface GigabitEthernet1/0/3description CONNECTED TO PHONEswitchport mode accessswitchport block unicastswitchport voice vlan 113switchport port-security maximum 2switchport port-security maximum 1 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security violation restrictload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastservice-policy input Phone-Policy!interface GigabitEthernet1/0/4!interface GigabitEthernet1/0/5!interface GigabitEthernet1/0/6!interface GigabitEthernet1/0/7!interface GigabitEthernet1/0/8!interface GigabitEthernet1/0/9!interface GigabitEthernet1/0/10!interface GigabitEthernet1/0/11!interface GigabitEthernet1/0/12!interface GigabitEthernet1/0/13!interface GigabitEthernet1/0/14!interface GigabitEthernet1/0/15!interface GigabitEthernet1/0/16!interface GigabitEthernet1/0/17!interface GigabitEthernet1/0/18!interface GigabitEthernet1/0/19!interface GigabitEthernet1/0/20!interface GigabitEthernet1/0/21!interface GigabitEthernet1/0/22!interface GigabitEthernet1/0/23!interface GigabitEthernet1/0/24!interface GigabitEthernet1/0/25!interface GigabitEthernet1/0/26!interface GigabitEthernet1/0/27!interface GigabitEthernet1/0/28!interface GigabitEthernet1/0/29!interface GigabitEthernet1/0/30!interface GigabitEthernet1/0/31!interface GigabitEthernet1/0/32!interface GigabitEthernet1/0/33!interface GigabitEthernet1/0/34!interface GigabitEthernet1/0/35!interface GigabitEthernet1/0/36!interface GigabitEthernet1/0/37!interface GigabitEthernet1/0/38!interface GigabitEthernet1/0/39!interface GigabitEthernet1/0/40!interface GigabitEthernet1/0/41!interface GigabitEthernet1/0/42!interface GigabitEthernet1/0/43!interface GigabitEthernet1/0/44!interface GigabitEthernet1/0/45!interface GigabitEthernet1/0/46!interface GigabitEthernet1/0/47!interface GigabitEthernet1/0/48description Connected to FlashNetswitchport access vlan 2switchport mode accessload-interval 30!interface GigabitEthernet1/0/49description Connected to cr24-4507-DOswitchport trunk native vlan 803switchport trunk allowed vlan 111-120,900switchport mode trunkload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode activehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/50!interface GigabitEthernet1/0/51!interface GigabitEthernet1/0/52!interface GigabitEthernet2/0/1!interface GigabitEthernet2/0/2!interface GigabitEthernet2/0/3!interface GigabitEthernet2/0/4!interface GigabitEthernet2/0/5!interface GigabitEthernet2/0/6!interface GigabitEthernet2/0/7!interface GigabitEthernet2/0/8!interface GigabitEthernet2/0/9!interface GigabitEthernet2/0/10!interface GigabitEthernet2/0/11!interface GigabitEthernet2/0/12!interface GigabitEthernet2/0/13!interface GigabitEthernet2/0/14!interface GigabitEthernet2/0/15!interface GigabitEthernet2/0/16!interface GigabitEthernet2/0/17!interface GigabitEthernet2/0/18!interface GigabitEthernet2/0/19!interface GigabitEthernet2/0/20!interface GigabitEthernet2/0/21!interface GigabitEthernet2/0/22!interface GigabitEthernet2/0/23!interface GigabitEthernet2/0/24!interface GigabitEthernet2/0/25!interface GigabitEthernet2/0/26!interface GigabitEthernet2/0/27!interface GigabitEthernet2/0/28!interface GigabitEthernet2/0/29!interface GigabitEthernet2/0/30!interface GigabitEthernet2/0/31!interface GigabitEthernet2/0/32!interface GigabitEthernet2/0/33!interface GigabitEthernet2/0/34!interface GigabitEthernet2/0/35!interface GigabitEthernet2/0/36!interface GigabitEthernet2/0/37!interface GigabitEthernet2/0/38!interface GigabitEthernet2/0/39!interface GigabitEthernet2/0/40!interface GigabitEthernet2/0/41!interface GigabitEthernet2/0/42!interface GigabitEthernet2/0/43!interface GigabitEthernet2/0/44!interface GigabitEthernet2/0/45!interface GigabitEthernet2/0/46!interface GigabitEthernet2/0/47!interface GigabitEthernet2/0/48description Connected to FlashNetswitchport access vlan 2switchport mode accessload-interval 30!interface GigabitEthernet2/0/49!interface GigabitEthernet2/0/50!interface GigabitEthernet2/0/51!interface GigabitEthernet2/0/52!interface GigabitEthernet3/0/1description CONNECTED TO PHONE+PCswitchport access vlan 114switchport mode accessswitchport block unicastswitchport voice vlan 115switchport port-security maximum 3switchport port-security maximum 2 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone+PC-Policy!interface GigabitEthernet3/0/2description CONNECTED TO IPVS 2500 - CAMERAswitchport access vlan 116switchport mode accessswitchport block unicastswitchport port-securityload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet3/0/3description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 117switchport mode accessswitchport block unicastswitchport port-securityload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet3/0/4description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 118switchport mode accessswitchport block unicastswitchport port-securityload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpdot1x mac-auth-bypassdot1x pae authenticatordot1x violation-mode protectstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet3/0/5!interface GigabitEthernet3/0/6!interface GigabitEthernet3/0/7!interface GigabitEthernet3/0/8!interface GigabitEthernet3/0/9!interface GigabitEthernet3/0/10description Connected to IXIA - ALM - 2/2switchport trunk native vlan 202switchport trunk allowed vlan 111-120switchport mode trunkswitchport nonegotiateload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablespanning-tree bpduguard enablespanning-tree guard roothold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet3/0/11description Connected to IXIA - STX - 3/2switchport trunk native vlan 202switchport trunk allowed vlan 111-120switchport mode trunkswitchport nonegotiateload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablespanning-tree bpduguard enablespanning-tree guard roothold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet3/0/12!interface GigabitEthernet3/0/13!interface GigabitEthernet3/0/14!interface GigabitEthernet3/0/15!interface GigabitEthernet3/0/16!interface GigabitEthernet3/0/17!interface GigabitEthernet3/0/18!interface GigabitEthernet3/0/19!interface GigabitEthernet3/0/20!interface GigabitEthernet3/0/21!interface GigabitEthernet3/0/22!interface GigabitEthernet3/0/23!interface GigabitEthernet3/0/24!interface GigabitEthernet3/0/25!interface GigabitEthernet3/0/26!interface GigabitEthernet3/0/27!interface GigabitEthernet3/0/28!interface GigabitEthernet3/0/29!interface GigabitEthernet3/0/30!interface GigabitEthernet3/0/31!interface GigabitEthernet3/0/32!interface GigabitEthernet3/0/33!interface GigabitEthernet3/0/34!interface GigabitEthernet3/0/35!interface GigabitEthernet3/0/36!interface GigabitEthernet3/0/37!interface GigabitEthernet3/0/38!interface GigabitEthernet3/0/39!interface GigabitEthernet3/0/40!interface GigabitEthernet3/0/41!interface GigabitEthernet3/0/42!interface GigabitEthernet3/0/43!interface GigabitEthernet3/0/44!interface GigabitEthernet3/0/45!interface GigabitEthernet3/0/46!interface GigabitEthernet3/0/47!interface GigabitEthernet3/0/48description Connected to FlashNetswitchport access vlan 2switchport mode accessload-interval 30!interface GigabitEthernet3/0/49description Connected to cr24-4507-DOswitchport trunk native vlan 803switchport trunk allowed vlan 111-120,900switchport mode trunkload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode activehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet3/0/50!interface GigabitEthernet3/0/51!interface GigabitEthernet3/0/52!interface Vlan1ip address dhcpshutdown!interface Vlan2description Connected to FlashNet - DO NOT ROUTEip address 172.26.160.190 255.255.254.0no ip redirectsno ip proxy-arpload-interval 30!interface Vlan900description Mgmt_VLANip address 10.125.34.3 255.255.255.224no ip redirectsno ip unreachablesload-interval 30!no ip http serverno ip http secure-server!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255ip access-list standard Deny_PIM_DM_Fallbackdeny 224.0.1.39deny 224.0.1.40permit any!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.31.4 auth-port 1645 acct-port 1646 key 7 094F471A1A0A5B43595Fradius-server deadtime 1!control-plane!alias exec dsno show ip dhcp snooping bindalias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104logging synchronousspeed 115200line vty 0 4exec-timeout 0 0password 7 121A0C041104logging synchronousline vty 5 15exec-timeout 0 0!ntp clock-period 36028631ntp server 172.26.160.10endCr24-3560r-DO!! Last configuration change at 22:53:38 EDT Wed Sep 2 2009 by cisco! NVRAM config last updated at 22:53:54 EDT Wed Sep 2 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr24-3560r-DO!boot-start-markerboot-end-marker!enable secret 5 $1$nwph$/o52o3VuKVOHNwYCaEu/w.enable password 7 13061E010803!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringsystem mtu routing 1500vtp domain District-Officevtp mode transparentip subnet-zeroip routingno ip domain-lookup!!ip dhcp snooping vlan 11-20no ip dhcp snooping information optionip dhcp snoopingip multicast-routing distributedip arp inspection vlan 11-20ip arp inspection validate src-mac dst-mac ip allow zeros!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!key chain eigrp-keykey 1key-string 7 045802150C2E!crypto pki trustpoint TP-self-signed-3151740416enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-3151740416revocation-check nonersakeypair TP-self-signed-3151740416!!crypto pki certificate chain TP-self-signed-3151740416certificate self-signed 01 nvram:IOS-Self-Sig#3636.cerdot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120port-channel load-balance src-dst-ip!!!spanning-tree mode rapid-pvstno spanning-tree optimize bpdu transmissionspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 11-20!vlan 203name Guest_VLAN!ip ftp username nimishguestip ftp password 7 030A5F0C130A3258!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 32000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map Phone+PC-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 32000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!!interface Loopback0ip address 10.125.100.4 255.255.255.255!interface Port-channel1description Connected to cr24-4507-DOno switchportdampeningip address 10.125.32.1 255.255.255.254ip pim sparse-modeip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 out!interface FastEthernet0/1description CONNECTED TO UNTRUSTED-PCswitchport access vlan 11switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input UnTrusted-PC-Policyip verify source!interface FastEthernet0/2description CONNECTED TO TRUSTED-PCswitchport access vlan 12switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Trusted-PC-Policyip verify source!interface FastEthernet0/3description CONNECTED TO PHONEswitchport mode accessswitchport block unicastswitchport voice vlan 13switchport port-security maximum 2switchport port-security maximum 1 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security violation restrictip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastservice-policy input Phone-Policyip verify source!interface FastEthernet0/4description CONNECTED TO PHONE+PCswitchport access vlan 14switchport mode accessswitchport block unicastswitchport voice vlan 15switchport port-security maximum 3switchport port-security maximum 2 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone+PC-Policyip verify source!interface FastEthernet0/5description CONNECTED TO IPVS 2500 - CAMERAswitchport access vlan 16switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/6description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 17switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/7description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 18switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/8no mdix auto!interface FastEthernet0/9switchport access vlan 11switchport mode accessno mdix autospanning-tree portfast!interface FastEthernet0/10description Connected to IXIA - ALM - 2/3switchport trunk encapsulation dot1qswitchport trunk native vlan 203switchport trunk allowed vlan 11-20switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno mdix autono cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/11description Connected to IXIA - STX - 3/3switchport trunk encapsulation dot1qswitchport trunk native vlan 203switchport trunk allowed vlan 11-20switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno mdix autono cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/12no mdix auto!interface FastEthernet0/13no mdix auto!interface FastEthernet0/14no mdix auto!interface FastEthernet0/15no mdix auto!interface FastEthernet0/16no mdix auto!interface FastEthernet0/17no mdix auto!interface FastEthernet0/18no mdix auto!interface FastEthernet0/19no mdix auto!interface FastEthernet0/20no mdix auto!interface FastEthernet0/21no mdix auto!interface FastEthernet0/22no mdix auto!interface FastEthernet0/23no mdix auto!interface FastEthernet0/24no mdix auto!interface FastEthernet0/25no mdix auto!interface FastEthernet0/26no mdix auto!interface FastEthernet0/27no mdix auto!interface FastEthernet0/28no mdix auto!interface FastEthernet0/29no mdix auto!interface FastEthernet0/30no mdix auto!interface FastEthernet0/31no mdix auto!interface FastEthernet0/32no mdix auto!interface FastEthernet0/33no mdix auto!interface FastEthernet0/34no mdix auto!interface FastEthernet0/35no mdix auto!interface FastEthernet0/36no mdix auto!interface FastEthernet0/37no mdix auto!interface FastEthernet0/38no mdix auto!interface FastEthernet0/39no mdix auto!interface FastEthernet0/40no mdix auto!interface FastEthernet0/41no mdix auto!interface FastEthernet0/42no mdix auto!interface FastEthernet0/43no mdix auto!interface FastEthernet0/44no mdix auto!interface FastEthernet0/45no mdix auto!interface FastEthernet0/46no mdix auto!interface FastEthernet0/47no mdix auto!interface FastEthernet0/48no switchportip address 172.26.160.187 255.255.254.0no ip redirectsno ip proxy-arpno mdix auto!interface GigabitEthernet0/1description Connected to cr24-4507-DOno switchportno ip addressload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirablehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet0/2description Connected to cr24-4507-DOno switchportno ip addressload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirablehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet0/3!interface GigabitEthernet0/4!interface Vlan1no ip addressshutdown!interface Vlan11dampeningip address 10.125.11.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan12dampeningip address 10.125.11.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan13dampeningip address 10.125.12.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan14dampeningip address 10.125.12.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan15dampeningip address 10.125.13.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan16dampeningip address 10.125.13.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan17dampeningip address 10.125.14.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan18dampeningip address 10.125.14.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan19dampeningip address 10.125.15.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan20dampeningip address 10.125.15.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!!router eigrp 100passive-interface defaultno passive-interface Port-channel1no auto-summaryeigrp router-id 10.125.100.4eigrp stub connectednetwork 10.125.0.0 0.0.255.255!ip classlessno ip http serverno ip http secure-serverip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255ip access-list standard Deny_PIM_DM_Fallbackdeny 224.0.1.39deny 224.0.1.40permit any!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630!!snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.31.4 auth-port 1645 acct-port 1646 key 7 00071A15075447575D72radius-server deadtime 1!control-plane!alias exec dsno show ip dhcp snooping bindalias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104logging synchronousline vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36028444ntp server 172.26.160.10endCr25-3750-DO!! Last configuration change at 22:53:38 EDT Wed Sep 2 2009 by cisco! NVRAM config last updated at 22:53:54 EDT Wed Sep 2 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr25-3750-DO!boot-start-markerboot-end-marker!enable secret 5 $1$rZnh$VH5sfvkInDxIlKe6HvlHO.enable password 7 094F471A1A0A!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringswitch 1 provision ws-c3750g-24ts-1usystem mtu routing 1500vtp domain District-Officevtp mode transparentip subnet-zerono ip domain-lookup!!ip dhcp snooping vlan 121-130no ip dhcp snooping information optionip dhcp snoopingip multicast-routing distributedip arp inspection vlan 121-130ip arp inspection validate src-mac dst-mac ip allow zeros!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!crypto pki trustpoint TP-self-signed-250233728enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-250233728revocation-check nonersakeypair TP-self-signed-250233728!!crypto pki certificate chain TP-self-signed-250233728certificate self-signed 01 nvram:IOS-Self-Sig#3838.cerdot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120port-channel load-balance src-dst-ip!!!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 121name cr25_3750_Dept21!vlan 122name cr25_3750_Dept22!vlan 123name cr25_3750_Dept23!vlan 124name cr25_3750_Dept24!vlan 125name cr25_3750_Dept25!vlan 126name cr25_3750_Dept26!vlan 127name cr25_3750_Dept27!vlan 128name cr25_3750_Dept28!vlan 129name cr25_3750_Dept29!vlan 130name cr25_3750_Dept30!vlan 204name Guest_VLAN!vlan 804name Hopping_VLAN!vlan 900name Mgmt_VLAN!ip ftp username nimishguestip ftp password 7 0701254B5B0C0A11!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 32000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map Phone+PC-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!!interface Loopback0ip address 10.125.100.5 255.255.255.255!interface Port-channel1description Connected to cr24-4507-DOswitchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130,204,900switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/1description CONNECTED TO UNTRUSTED PCswitchport access vlan 121switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input UnTrusted-PC-Policyip verify source!interface GigabitEthernet1/0/2description CONNECTED TO TRUSTED-PCswitchport access vlan 122switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Trusted-PC-Policyip verify source!interface GigabitEthernet1/0/3description CONNECTED TO PHONEswitchport mode accessswitchport block unicastswitchport voice vlan 123switchport port-security maximum 2switchport port-security maximum 1 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security violation restrictip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastservice-policy input Phone-Policyip verify source!interface GigabitEthernet1/0/4description CONNECTED TO PHONE+PCswitchport access vlan 124switchport mode accessswitchport block unicastswitchport voice vlan 125switchport port-security maximum 3switchport port-security maximum 2 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone+PC-Policyip verify source!interface GigabitEthernet1/0/5description CONNECTED TO IPVS 2500 - CAMERAswitchport access vlan 126switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet1/0/6description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 127switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet1/0/7description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 128switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet1/0/8srr-queue bandwidth share 1 30 35 5priority-queue out!interface GigabitEthernet1/0/9!interface GigabitEthernet1/0/10description Connected to IXIA - ALM - 2/4switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130switchport mode trunkip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/11description Connected to IXIA - STX - 3/4switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130switchport mode trunkip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/12!interface GigabitEthernet1/0/13!interface GigabitEthernet1/0/14!interface GigabitEthernet1/0/15!interface GigabitEthernet1/0/16!interface GigabitEthernet1/0/17!interface GigabitEthernet1/0/18!interface GigabitEthernet1/0/19!interface GigabitEthernet1/0/20!interface GigabitEthernet1/0/21!interface GigabitEthernet1/0/22!interface GigabitEthernet1/0/23!interface GigabitEthernet1/0/24description Flashnet DO NOT ROUTEno switchportip address 172.26.160.200 255.255.254.0no ip proxy-arpduplex full!interface GigabitEthernet1/0/25!interface GigabitEthernet1/0/26!interface GigabitEthernet1/0/27description Connected to cr24-4507-DOswitchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130,204,900switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/28description Connected to cr24-4507-DOswitchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130,204,900switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface Vlan1no ip addressshutdown!interface Vlan900description Mgmt_VLANip address 10.125.34.4 255.255.255.224no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!ip classlessip route 172.26.158.0 255.255.255.0 172.26.160.1no ip http serverno ip http secure-serverip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255ip access-list standard Deny_PIM_DM_Fallbackdeny 224.0.1.39deny 224.0.1.40permit any!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630!!snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.31.4 auth-port 1645 acct-port 1646 key 7 13061E010803487B7977radius-server deadtime 1!control-plane!alias exec dsno show ip dhcp snooping bindalias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36029250ntp server 172.26.160.10endCr26-3750r-DO!! Last configuration change at 22:53:38 EDT Wed Sep 2 2009 by cisco! NVRAM config last updated at 22:53:54 EDT Wed Sep 2 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr26-3750r-DO!boot-start-markerboot-end-marker!enable secret 5 $1$d/Sc$Ha0.t0aRa.T2i2rSdNk7e1enable password 7 05080F1C2243!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringswitch 1 provision ws-c3750e-24pdswitch 2 provision ws-c3750e-24pdswitch 3 provision ws-c3750e-24pdstack-mac persistent timer 0system mtu routing 1500vtp domain District-Officevtp mode transparentip subnet-zeroip routingno ip domain-lookup!!ip dhcp snooping vlan 11-20no ip dhcp snooping information optionip dhcp snoopingip multicast-routing distributedip arp inspection vlan 11-20ip arp inspection validate src-mac dst-mac ip allow zeros!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!key chain eigrp-keykey 1key-string 7 104D000A0618!crypto pki trustpoint TP-self-signed-1384443008enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-1384443008revocation-check nonersakeypair TP-self-signed-1384443008!crypto pki trustpoint TP-self-signed-721582080enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-721582080revocation-check nonersakeypair TP-self-signed-721582080!!crypto pki certificate chain TP-self-signed-1384443008certificate self-signedquitcrypto pki certificate chain TP-self-signed-721582080license boot level ipservices switch 1license boot level ipservices switch 3license boot level ipservicesdot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120!!!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 11-20!vlan 205name Guest_VLAN!vlan 900!!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 32000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map Phone+PC-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!!interface Loopback0ip address 10.125.100.6 255.255.255.255!interface Port-channel1description Connected to cr24-4507-DOno switchportdampeningip address 10.125.32.3 255.255.255.254ip pim sparse-modeip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 out!interface FastEthernet0no ip addressno ip route-cache cefno ip route-cacheno ip mroute-cacheshutdown!interface GigabitEthernet1/0/1description CONNECTED TO UNTRUSTED PCswitchport access vlan 11switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input UnTrusted-PC-Policyip verify source!interface GigabitEthernet1/0/2description CONNECTED TO TRUSTED-PCswitchport access vlan 12switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Trusted-PC-Policyip verify source!interface GigabitEthernet1/0/3description CONNECTED TO PHONEswitchport mode accessswitchport block unicastswitchport voice vlan 13switchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security violation restrictip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastservice-policy input Phone-Policyip verify source!interface GigabitEthernet1/0/4description CONNECTED TO PHONE+PCswitchport access vlan 14switchport mode accessswitchport block unicastswitchport voice vlan 15switchport port-security maximum 3switchport port-security maximum 2 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone+PC-Policyip verify source!interface GigabitEthernet1/0/5description CONNECTED TO IPVS 2500 - CAMERAswitchport access vlan 16switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet1/0/6description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 17switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet1/0/7description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 18switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet1/0/8description Connected to cr24-4507-DOno switchportno ip addressload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscphold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/9description Connected to cr24-4507-DOno switchportno ip addressload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscphold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/10description Connected to IXIA - ALM - 2/5switchport trunk encapsulation dot1qswitchport trunk native vlan 806switchport trunk allowed vlan 11-20switchport mode trunkip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/11description Connected to IXIA - STX - 4/1switchport trunk encapsulation dot1qswitchport trunk native vlan 806switchport trunk allowed vlan 11-20switchport mode trunkip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/12description Connected to FlashNetswitchport access vlan 900switchport mode accessload-interval 30spanning-tree portfast!interface GigabitEthernet1/0/13!interface GigabitEthernet1/0/14!interface GigabitEthernet1/0/15!interface GigabitEthernet1/0/16!interface GigabitEthernet1/0/17!interface GigabitEthernet1/0/18!interface GigabitEthernet1/0/19!interface GigabitEthernet1/0/20!interface GigabitEthernet1/0/21!interface GigabitEthernet1/0/22!interface GigabitEthernet1/0/23!interface GigabitEthernet1/0/24!interface GigabitEthernet1/0/25description Connected to cr24-4507-DOno switchportno ip addressip pim sparse-modeip hold-time eigrp 100 20ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode activehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/26!interface GigabitEthernet1/0/27!interface GigabitEthernet1/0/28!interface TenGigabitEthernet1/0/1!interface TenGigabitEthernet1/0/2!interface GigabitEthernet2/0/1!interface GigabitEthernet2/0/2!interface GigabitEthernet2/0/3!interface GigabitEthernet2/0/4!interface GigabitEthernet2/0/5!interface GigabitEthernet2/0/6!interface GigabitEthernet2/0/7!interface GigabitEthernet2/0/8!interface GigabitEthernet2/0/9!interface GigabitEthernet2/0/10!interface GigabitEthernet2/0/11!interface GigabitEthernet2/0/12description FlashNet - DO NOT ROUTEswitchport access vlan 900switchport mode accessload-interval 30spanning-tree portfast!interface GigabitEthernet2/0/13!interface GigabitEthernet2/0/14!interface GigabitEthernet2/0/15!interface GigabitEthernet2/0/16!interface GigabitEthernet2/0/17!interface GigabitEthernet2/0/18!interface GigabitEthernet2/0/19!interface GigabitEthernet2/0/20!interface GigabitEthernet2/0/21!interface GigabitEthernet2/0/22!interface GigabitEthernet2/0/23!interface GigabitEthernet2/0/24!interface GigabitEthernet2/0/25channel-protocol lacp!interface GigabitEthernet2/0/26!interface GigabitEthernet2/0/27!interface GigabitEthernet2/0/28!interface TenGigabitEthernet2/0/1!interface TenGigabitEthernet2/0/2!interface GigabitEthernet3/0/1!interface GigabitEthernet3/0/2!interface GigabitEthernet3/0/3!interface GigabitEthernet3/0/4!interface GigabitEthernet3/0/5!interface GigabitEthernet3/0/6!interface GigabitEthernet3/0/7!interface GigabitEthernet3/0/8!interface GigabitEthernet3/0/9!interface GigabitEthernet3/0/10!interface GigabitEthernet3/0/11!interface GigabitEthernet3/0/12description FlashNet - DO NOT ROUTEswitchport access vlan 900switchport mode accessload-interval 30spanning-tree portfast!interface GigabitEthernet3/0/13!interface GigabitEthernet3/0/14!interface GigabitEthernet3/0/15!interface GigabitEthernet3/0/16!interface GigabitEthernet3/0/17!interface GigabitEthernet3/0/18!interface GigabitEthernet3/0/19!interface GigabitEthernet3/0/20!interface GigabitEthernet3/0/21!interface GigabitEthernet3/0/22!interface GigabitEthernet3/0/23!interface GigabitEthernet3/0/24!interface GigabitEthernet3/0/25description Connected to cr24-4507-DOno switchportno ip addressload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-group 1 mode activehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet3/0/26!interface GigabitEthernet3/0/27!interface GigabitEthernet3/0/28!interface TenGigabitEthernet3/0/1!interface TenGigabitEthernet3/0/2!interface Vlan1no ip addressshutdown!interface Vlan11dampeningip address 10.125.21.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan12dampeningip address 10.125.21.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan13dampeningip address 10.125.22.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan14dampeningip address 10.125.22.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan15dampeningip address 10.125.23.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan16dampeningip address 10.125.23.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan17dampeningip address 10.125.24.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan18dampeningip address 10.125.24.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan19dampeningip address 10.125.25.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan20dampeningip address 10.125.25.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan900ip address 172.26.158.238 255.255.254.0no ip redirectsno ip proxy-arpload-interval 30!!router eigrp 100passive-interface defaultno passive-interface Port-channel1no auto-summaryeigrp router-id 10.125.100.6eigrp stub connectednetwork 10.125.0.0 0.0.255.255nsf!ip classlessno ip http serverno ip http secure-serverip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255ip access-list standard Deny_PIM_DM_Fallbackdeny 224.0.1.39deny 224.0.1.40permit any!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630!!snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.31.4 auth-port 1645 acct-port 1646 key 7 02050D48080943701E1Dradius-server deadtime 1!control-plane!alias exec dsno show ip dhcp snooping bindalias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36026851ntp server 172.26.158.10endCr25-3750s-DO!! Last configuration change at 22:53:38 EDT Wed Sep 2 2009 by cisco! NVRAM config last updated at 22:53:54 EDT Wed Sep 2 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr25-3750s-DO!boot-start-markerboot-end-marker!enable secret 5 $1$wQrW$jkV1e46Qfbs8PzbR/vO7O/enable password 7 02050D480809!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringswitch 1 provision ws-c3750g-24tsswitch 2 provision ws-c3750g-24tsstack-mac persistent timer 0system mtu routing 1500vtp domain District-Officevtp mode transparentip subnet-zerono ip domain-lookup!!ip dhcp snooping vlan 131-140no ip dhcp snooping information optionip dhcp snoopingip multicast-routing distributedip arp inspection vlan 131-140ip arp inspection validate src-mac dst-mac ip allow zeros!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!crypto pki trustpoint TP-self-signed-1942438528enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-1942438528revocation-check nonersakeypair TP-self-signed-1942438528!!crypto pki certificate chain TP-self-signed-1942438528certificate self-signed 01 nvram:IOS-Self-Sig#3838.cerdot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120port-channel load-balance src-dst-ip!!!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 2name FlashNet_VLAN!vlan 131name cr26_3750s_Dept31!vlan 132name cr26_3750s_Dept32!vlan 133name cr26_3750s_Dept33!vlan 134name cr26_3750s_Dept34!vlan 135name cr26_3750s_Dept35!vlan 136name cr26_3750s_Dept36!vlan 137name cr26_3750s_Dept37!vlan 138name cr26_3750s_Dept38!vlan 139name cr26_3750s_Dept39!vlan 140name cr26_3750s_Dept40!vlan 206name Guest_VLAN!vlan 805name Hopping_VLAN!vlan 900name Mgmt_VLAN!ip ftp username nimishguestip ftp password 7 09424A0E0C000406!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 32000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map Phone+PC-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!!interface Loopback0ip address 10.125.100.7 255.255.255.255!interface Port-channel1description Connected to cr24-4507-DOswitchport trunk encapsulation dot1qswitchport trunk native vlan 805switchport trunk allowed vlan 131-140,900switchport mode trunkip arp inspection trustlogging event bundle-statusload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/1description CONNECTED TO UNTRUSTED PCswitchport access vlan 131switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100storm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input UnTrusted-PC-Policyip verify source!interface GigabitEthernet1/0/2!interface GigabitEthernet1/0/3description CONNECTED TO PHONEswitchport mode accessswitchport block unicastswitchport voice vlan 133switchport port-security maximum 2switchport port-security maximum 1 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone-Policyip verify source!interface GigabitEthernet1/0/4ip arp inspection limit rate 100!interface GigabitEthernet1/0/5description CONNECTED TO IPVS 2500 - CAMERAswitchport access vlan 136switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outauthentication openmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet1/0/6description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 137switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outauthentication openmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet1/0/7description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 138switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outauthentication openmabmls qos trust dscpdot1x pae authenticatorstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet1/0/8!interface GigabitEthernet1/0/9!interface GigabitEthernet1/0/10description Connected to IXIA - ALM - 2/6switchport trunk encapsulation dot1qswitchport trunk native vlan 805switchport trunk allowed vlan 131-140switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/11description Connected to IXIA - STX - 4/2switchport trunk encapsulation dot1qswitchport trunk native vlan 805switchport trunk allowed vlan 131-140switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/12!interface GigabitEthernet1/0/13!interface GigabitEthernet1/0/14!interface GigabitEthernet1/0/15!interface GigabitEthernet1/0/16!interface GigabitEthernet1/0/17!interface GigabitEthernet1/0/18!interface GigabitEthernet1/0/19!interface GigabitEthernet1/0/20!interface GigabitEthernet1/0/21!interface GigabitEthernet1/0/22!interface GigabitEthernet1/0/23!interface GigabitEthernet1/0/24description Flashnet DO NOT ROUTEswitchport access vlan 2switchport mode access!interface GigabitEthernet1/0/25description Connected to cr24-4507-DOswitchport trunk encapsulation dot1qswitchport trunk native vlan 805switchport trunk allowed vlan 131-140,900switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode activehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/26!interface GigabitEthernet1/0/27!interface GigabitEthernet1/0/28!interface GigabitEthernet2/0/1description CONNECTED TO TRUSTED-PCswitchport access vlan 132switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Trusted-PC-Policyip verify source!interface GigabitEthernet2/0/2ip arp inspection limit rate 100!interface GigabitEthernet2/0/3description CONNECTED TO PHONE+PCswitchport access vlan 134switchport mode accessswitchport block unicastswitchport voice vlan 135ip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone+PC-Policyip verify source!interface GigabitEthernet2/0/4ip arp inspection limit rate 100!interface GigabitEthernet2/0/5ip arp inspection limit rate 100!interface GigabitEthernet2/0/6ip arp inspection limit rate 100!interface GigabitEthernet2/0/7ip arp inspection limit rate 100!interface GigabitEthernet2/0/8!interface GigabitEthernet2/0/9!interface GigabitEthernet2/0/10!interface GigabitEthernet2/0/11!interface GigabitEthernet2/0/12!interface GigabitEthernet2/0/13!interface GigabitEthernet2/0/14!interface GigabitEthernet2/0/15!interface GigabitEthernet2/0/16!interface GigabitEthernet2/0/17!interface GigabitEthernet2/0/18!interface GigabitEthernet2/0/19!interface GigabitEthernet2/0/20!interface GigabitEthernet2/0/21!interface GigabitEthernet2/0/22!interface GigabitEthernet2/0/23!interface GigabitEthernet2/0/24description Flashnet DO NOT ROUTEswitchport access vlan 2switchport mode access!interface GigabitEthernet2/0/25description Connected to cr24-4507-DOswitchport trunk encapsulation dot1qswitchport trunk native vlan 805switchport trunk allowed vlan 131-140,900switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode activehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet2/0/26!interface GigabitEthernet2/0/27!interface GigabitEthernet2/0/28!interface Vlan1no ip addressshutdown!interface Vlan2description Flashnet DO NOT ROUTEip address 172.26.160.201 255.255.254.0no ip redirectsno ip proxy-arp!interface Vlan900description Mgmt_VLANip address 10.125.34.5 255.255.255.224no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!ip classlessip route 172.26.158.0 255.255.255.0 172.26.160.1no ip http serverno ip http secure-serverip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255ip access-list standard Deny_PIM_DM_Fallbackdeny 224.0.1.39deny 224.0.1.40permit any!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630!!snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.31.4 auth-port 1645 acct-port 1646 key 7 094F471A1A0A5B43595Fradius-server deadtime 1!control-plane!alias exec dsno show ip dhcp snooping bindalias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36028937ntp server 172.26.160.10endCr26-3750DC-DO!! Last configuration change at 22:53:38 EDT Wed Sep 2 2009 by cisco! NVRAM config last updated at 22:53:54 EDT Wed Sep 2 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr26-3750DC-DO!boot-start-markerboot-end-marker!enable password 7 070C285F4D06!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringswitch 1 provision ws-c3750g-12sswitch 2 provision ws-c3750g-12sswitch 3 provision ws-c3750g-12sstack-mac persistent timer 0system mtu routing 1500vtp domain District-Officevtp mode transparentip subnet-zerono ip domain-lookup!!ip multicast-routing distributed!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!crypto pki trustpoint TP-self-signed-721633024enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-721633024revocation-check nonersakeypair TP-self-signed-721633024!!crypto pki certificate chain TP-self-signed-721633024certificate self-signed 01 nvram:IOS-Self-Sig#3434.cerdot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120port-channel load-balance src-dst-ip!!!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 2name FlashNet_Vlan!vlan 141name cr26_3750s_DC_Group1!vlan 142name cr26_3750s_DC_Group2!vlan 143name cr26_3750s_DC_Group3!vlan 144name cr26_3750s_DC_Group4!vlan 145name cr26_3750s_DC_Group5!vlan 146name cr26_3750s_DC_Group6!vlan 147name cr26_3750s_DC_Group7!vlan 148name cr26_3750s_DC_Group8!vlan 149name cr26_3750s_DC_Group9!vlan 150name cr26_3750s_DC_Grou10!vlan 806name Hopping_Vlan!vlan 900name Mgmt_VLAN!!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 32000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map Phone+PC-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!!interface Loopback0ip address 10.125.100.8 255.255.255.255!interface Port-channel1description Connected to cr24-4507-DOswitchport trunk encapsulation dot1qswitchport trunk native vlan 806switchport trunk allowed vlan 141-150,900switchport mode trunklogging event bundle-statusload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/1!interface GigabitEthernet1/0/2description CONNECTED TO TRUSTED-PCswitchport access vlan 141srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Trusted-PC-Policy!interface GigabitEthernet1/0/3description Connected to IXIA - LSM - 1/3switchport trunk encapsulation dot1qswitchport trunk native vlan 806switchport trunk allowed vlan 142switchport mode trunkswitchport nonegotiateload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control action trapno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablespanning-tree bpduguard enablehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/4description Connected to IXIA - LSM - 1/4switchport trunk encapsulation dot1qswitchport trunk native vlan 806switchport trunk allowed vlan 143switchport mode trunkswitchport nonegotiateload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control action trapno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablespanning-tree bpduguard enablehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/5description Connected to IXIA - LSM - 1/5switchport trunk encapsulation dot1qswitchport trunk native vlan 806switchport trunk allowed vlan 144switchport mode trunkswitchport nonegotiateload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control action trapno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablespanning-tree bpduguard enablehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/6description Connected to IXIA - LSM - 1/6switchport trunk encapsulation dot1qswitchport trunk native vlan 806switchport trunk allowed vlan 145switchport mode trunkswitchport nonegotiateload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control action trapno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablespanning-tree bpduguard enablehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/7description Connected to IXIA - LSM - 1/7switchport access vlan 141srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control action trapspanning-tree portfast trunkspanning-tree bpdufilter enablespanning-tree bpduguard enablehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/8description Connected to cr24-4507-DOswitchport trunk encapsulation dot1qswitchport trunk native vlan 806switchport trunk allowed vlan 141-150,900switchport mode trunkload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode activehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/9description Connected to cr25-w2k-2switchport access vlan 141!interface GigabitEthernet1/0/10switchport access vlan 141!interface GigabitEthernet1/0/11switchport access vlan 141!interface GigabitEthernet1/0/12switchport access vlan 2switchport mode access!interface GigabitEthernet2/0/1switchport access vlan 141!interface GigabitEthernet2/0/2switchport access vlan 141!interface GigabitEthernet2/0/3!interface GigabitEthernet2/0/4!interface GigabitEthernet2/0/5!interface GigabitEthernet2/0/6!interface GigabitEthernet2/0/7!interface GigabitEthernet2/0/8!interface GigabitEthernet2/0/9!interface GigabitEthernet2/0/10!interface GigabitEthernet2/0/11!interface GigabitEthernet2/0/12switchport access vlan 2switchport mode access!interface GigabitEthernet3/0/1description Connected to IXIA - LSM - 1/7switchport access vlan 141switchport trunk encapsulation dot1qswitchport trunk native vlan 806switchport trunk allowed vlan 146switchport mode trunkswitchport nonegotiateload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control action trapno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablespanning-tree bpduguard enablehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet3/0/2description CONNECTED TO PHONEswitchport access vlan 141srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone-Policy!interface GigabitEthernet3/0/3description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 141mls qos trust dscpstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet3/0/4description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 141priority-queue outmls qos trust dscpstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet3/0/5switchport access vlan 141!interface GigabitEthernet3/0/6switchport access vlan 141!interface GigabitEthernet3/0/7switchport access vlan 141!interface GigabitEthernet3/0/8description Connected to cr24-4507-DOswitchport trunk encapsulation dot1qswitchport trunk native vlan 806switchport trunk allowed vlan 141-150,900switchport mode trunkload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode activehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet3/0/9switchport access vlan 141speed 100duplex half!interface GigabitEthernet3/0/10!interface GigabitEthernet3/0/11switchport access vlan 141!interface GigabitEthernet3/0/12switchport access vlan 2switchport mode access!interface Vlan1no ip addressshutdown!interface Vlan2description FlashNet VLANip address 172.26.160.189 255.255.254.0no ip redirectsno ip proxy-arp!interface Vlan900description Mgmt_VLANip address 10.125.34.6 255.255.255.224no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!ip classlessno ip http serverno ip http secure-serverip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255ip access-list standard Deny_PIM_DM_Fallbackdeny 224.0.1.39deny 224.0.1.40permit any!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630!!snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.31.4 auth-port 1645 acct-port 1646 key 7 02050D48080943701E1Dradius-server deadtime 1!control-plane!alias exec dsno show ip dhcp snooping bindalias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36028995ntp server 172.26.160.10endCore/Distribution
Cr24-4507-D!! Last configuration change at 22:53:38 EDT Wed Sep 2 2009! NVRAM config last updated at 22:53:55 EDT Wed Sep 2 2009!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryptionservice compress-config!hostname cr24-4507-DO!boot-start-markerboot system flash slot0:cat4500e-entservicesk9-mz.122-53.SGboot-end-marker!enable secret 5 $1$UMTH$xnQm5GcPPGxmEWdUoGWj7.enable password 7 094F471A1A0A!no aaa new-modelclock timezone EST -5clock summer-time EDT recurringhw-module uplink mode shared-backplanehw-module module 3 port-group 1 select gigabitethernethw-module module 4 port-group 1 select gigabitethernetip subnet-zerono ip domain-lookup!!ip vrf mgmtVrf!ip multicast-routingvtp domain District-Officevtp mode transparent!!table-map WLC-DSCP-COSdefault copy!!key chain eigrp-keykey 1key-string 7 045802150C2E!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery interval 120power redundancy-mode redundant!!!!!!spanning-tree mode rapid-pvstspanning-tree extend system-idspanning-tree vlan 1-4094 priority 24576!redundancymode ssomain-cpuauto-sync standard!process-max-time 20vlan internal allocation policy ascending!vlan 11-20!vlan 101name cr24_2960_Dept1!vlan 102name cr24_2960_Dept2!vlan 103name cr24_2960_Dept3!vlan 104name cr24_2960_Dept4!vlan 105name cr24_2960_Dept5!vlan 106name cr24_2960_Dept6!vlan 107name cr24_2960_Dept7!vlan 108name cr24_2960_Dept8!vlan 109name cr24_2960_Dept9!vlan 110name cr24_2960_Dept10!vlan 111name cr24_3550_Dept11!vlan 112name cr24_3550_Dept12!vlan 113name cr24_3550_Dept13!vlan 114name cr24_3550_Dept14!vlan 115name cr24_3550_Dept15!vlan 116name cr24_3550_Dept16!vlan 117name cr24_3550_Dept17!vlan 118name cr24_3550_Dept18!vlan 119name cr24_3550_Dept19!vlan 120name cr24_3550_Dept20!vlan 121name cr25_3750_Dept21!vlan 122name cr25_3750_Dept22!vlan 123name cr25_3750_Dept23!vlan 124name cr25_3750_Dept24!vlan 125name cr25_3750_Dept25!vlan 126name cr25_3750_Dept26!vlan 127name cr25_3750_Dept27!vlan 128name cr25_3750_Dept28!vlan 129name cr25_3750_Dept29!vlan 130name cr25_3750_Dept30!vlan 131name cr26_3750s_Dept31!vlan 132name cr26_3750s_Dept32!vlan 133name cr26_3750s_Dept33!vlan 134name cr26_3750s_Dept34!vlan 135name cr26_3750s_Dept35!vlan 136name cr26_3750s_Dept36!vlan 137name cr26_3750s_Dept37!vlan 138name cr26_3750s_Dept38!vlan 139name cr26_3750s_Dept39!vlan 140name cr26_3750s_Dept40!vlan 141name cr26_3750s_DC_Group1!vlan 142name cr26_3750s_DC_Group2!vlan 143name cr26_3750s_DC_Group3!vlan 144name cr26_3750s_DC_Group4!vlan 145name cr26_3750s_DC_Group5!vlan 146name cr26_3750s_DC_Group6!vlan 147name cr26_3750s_DC_Group7!vlan 148name cr26_3750s_DC_Group8!vlan 149name cr26_3750s_DC_Group9!vlan 150name cr26_3750s_DC_Grou10!vlan 200name cr24_4507_FW_Inside!vlan 801name cr24_3750DC_Hopping!vlan 802name cr25_3550_Hopping!vlan 803name cr24_2975_Hopping!vlan 804name cr24_3560_Hopping!vlan 805name cr24_3750_Hopping!vlan 806name cr26_3750DC_Hopping!vlan 900name Mgmt_VLAN!ip ftp username nimishguestip ftp password 7 000A1701115E1812!class-map match-all MULTIMEDIA-STREAMING-QUEUEmatch dscp af31 af32 af33class-map match-any CONTROL-MGMT-QUEUEmatch dscp cs7match dscp cs6match dscp cs3match dscp cs2class-map match-all TRANSACTIONAL-DATA-QUEUEmatch dscp af21 af22 af23class-map match-all COPP-CRITICAL-APPLICATIONSmatch access-group name COPP-CRITICAL-APPLICATIONSclass-map match-all COPP-FILE-MANAGEMENTmatch access-group name COPP-FILE-MANAGEMENTclass-map match-all SCAVENGER-QUEUEmatch dscp cs1class-map match-all COPP-MONITORINGmatch access-group name COPP-MONITORINGclass-map match-all MULTIMEDIA-CONFERENCING-QUEUEmatch dscp af41 af42 af43class-map match-all BULK-DATA-QUEUEmatch dscp af11 af12 af13class-map match-all COPP-INTERACTIVE-MANAGEMENTmatch access-group name COPP-INTERACTIVE-MANAGEMENTclass-map match-any PRIORITY-QUEUEmatch dscp efmatch dscp cs5match dscp cs4class-map match-all COPP-UNDESIRABLEmatch access-group name COPP-UNDESIRABLEclass-map match-all COPP-IGPmatch access-group name COPP-IGP!!policy-map EGRESS-POLICYclass PRIORITY-QUEUEpriorityclass CONTROL-MGMT-QUEUEbandwidth remaining percent 10class MULTIMEDIA-CONFERENCING-QUEUEbandwidth remaining percent 10class MULTIMEDIA-STREAMING-QUEUEbandwidth remaining percent 10class TRANSACTIONAL-DATA-QUEUEbandwidth remaining percent 10dblclass BULK-DATA-QUEUEbandwidth remaining percent 4dblclass SCAVENGER-QUEUEbandwidth remaining percent 1class class-defaultbandwidth remaining percent 25dblpolicy-map PQ-POLICERclass PRIORITY-QUEUEpolice cir 300000000conform-action transmitexceed-action droppolicy-map system-cpp-policyclass COPP-IGPpolice cir 300000 bc 3000 be 3000conform-action transmitexceed-action dropviolate-action dropclass COPP-INTERACTIVE-MANAGEMENTpolice cir 500000 bc 5000 be 5000conform-action transmitexceed-action dropviolate-action dropclass COPP-FILE-MANAGEMENTpolice cir 6000000 bc 60000 be 60000conform-action transmitexceed-action dropviolate-action dropclass COPP-MONITORINGpolice cir 900000 bc 9000 be 9000conform-action transmitexceed-action dropviolate-action dropclass COPP-CRITICAL-APPLICATIONSpolice cir 900000 bc 9000 be 9000conform-action transmitexceed-action dropviolate-action dropclass COPP-UNDESIRABLEpolice cir 32000 bc 3000 be 3000conform-action dropexceed-action dropviolate-action dropclass class-defaultpolice cir 500000 bc 5000 be 5000conform-action transmitexceed-action dropviolate-action drop!!!interface Loopback0ip address 10.125.100.1 255.255.255.255!interface Loopback1description RPip address 10.125.100.100 255.255.255.255!interface Port-channel1description Connected to cr24-3750ME-DOdampeningip address 10.125.32.4 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.125.0.0 255.255.0.0 5logging event link-statusload-interval 30carrier-delay msec 0service-policy output PQ-POLICER!interface Port-channel2description Connected to cr24-2851-DOip address 10.125.32.6 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.125.0.0 255.255.0.0 5logging event link-statusload-interval 30carrier-delay msec 0service-policy output PQ-POLICER!interface Port-channel11description Connected to cr24-2960-DOswitchportswitchport trunk native vlan 802switchport trunk allowed vlan 101-110,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0service-policy output PQ-POLICER!interface Port-channel12description Connected to cr24-2975-DOswitchportswitchport trunk native vlan 803switchport trunk allowed vlan 111-120,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0service-policy output PQ-POLICER!interface Port-channel13description Connected to cr24-3560r-DOdampeningip address 10.125.32.0 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.125.0.0 255.255.0.0 5logging event link-statusload-interval 30carrier-delay msec 0service-policy output PQ-POLICER!interface Port-channel14description Connected to cr25-3750-DOswitchportswitchport trunk native vlan 804switchport trunk allowed vlan 121-130,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0service-policy output PQ-POLICER!interface Port-channel15description Connected to cr26-3750r-DOdampeningip address 10.125.32.2 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.125.0.0 255.255.0.0 5logging event link-statusload-interval 30carrier-delay msec 0service-policy output PQ-POLICER!interface Port-channel16description Connected to cr25-3750s-DOswitchportswitchport trunk native vlan 805switchport trunk allowed vlan 131-140,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0service-policy output PQ-POLICER!interface Port-channel17description Connected to cr26-3750DC-DOswitchportswitchport trunk native vlan 806switchport trunk allowed vlan 141-150,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0service-policy output PQ-POLICER!interface FastEthernet1ip vrf forwarding mgmtVrfno ip addressspeed autoduplex auto!interface GigabitEthernet1/1description Connected to cr24-2960-DOswitchport trunk native vlan 802switchport trunk allowed vlan 101-110,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0udld portchannel-protocol pagpchannel-group 11 mode desirablespanning-tree guard rootservice-policy output EGRESS-POLICY!interface GigabitEthernet1/2description Connected to cr24-2975-DOswitchport trunk native vlan 803switchport trunk allowed vlan 111-120,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0udld portchannel-protocol lacpchannel-group 12 mode activespanning-tree guard rootservice-policy output EGRESS-POLICY!interface GigabitEthernet1/3description Connected to cr24-3560r-DOno switchportdampeningno ip addresslogging event link-statusload-interval 30carrier-delay msec 0udld portchannel-group 13 mode desirableservice-policy output EGRESS-POLICY!interface GigabitEthernet1/4description Connected to cr25-3750-DOswitchport trunk native vlan 804switchport trunk allowed vlan 121-130,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0udld portchannel-protocol pagpchannel-group 14 mode desirablespanning-tree guard rootservice-policy output EGRESS-POLICY!interface GigabitEthernet1/5description Connected to cr26-3750-DOno switchportdampeningno ip addresslogging event link-statusload-interval 30carrier-delay msec 0udld portchannel-protocol lacpchannel-group 15 mode activeservice-policy output EGRESS-POLICY!interface GigabitEthernet1/6description Connected to cr26-3750s-DOswitchport trunk native vlan 805switchport trunk allowed vlan 131-140,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0udld portchannel-protocol lacpchannel-group 16 mode activespanning-tree guard rootservice-policy output EGRESS-POLICY!interface GigabitEthernet2/1description Connected to cr24-2960-DOswitchport trunk native vlan 802switchport trunk allowed vlan 101-110,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0udld portchannel-protocol pagpchannel-group 11 mode desirablespanning-tree guard rootservice-policy output EGRESS-POLICY!interface GigabitEthernet2/2description Connected to cr24-2975-DOswitchport trunk native vlan 803switchport trunk allowed vlan 111-120,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0udld portchannel-protocol lacpchannel-group 12 mode activespanning-tree guard rootservice-policy output EGRESS-POLICY!interface GigabitEthernet2/3description Connected to cr24-3560r-DOno switchportdampeningno ip addresslogging event link-statusload-interval 30udld portchannel-group 13 mode desirableservice-policy output EGRESS-POLICY!interface GigabitEthernet2/4description Connected to cr25-3750-DOswitchport trunk native vlan 804switchport trunk allowed vlan 121-130,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0udld portchannel-protocol pagpchannel-group 14 mode desirablespanning-tree guard rootservice-policy output EGRESS-POLICY!interface GigabitEthernet2/5description Connected to cr26-3750-DOno switchportdampeningno ip addresslogging event link-statusload-interval 30carrier-delay msec 0udld portchannel-protocol lacpchannel-group 15 mode activeservice-policy output EGRESS-POLICY!interface GigabitEthernet2/6description Connected to cr26-3750s-DOswitchport trunk native vlan 805switchport trunk allowed vlan 131-140,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0udld portchannel-protocol lacpchannel-group 16 mode activespanning-tree guard rootservice-policy output EGRESS-POLICY!interface TenGigabitEthernet3/1!interface TenGigabitEthernet3/2!interface GigabitEthernet3/3!interface GigabitEthernet3/4no switchportno ip addressload-interval 30!interface GigabitEthernet3/5no switchportno ip addressload-interval 30!interface GigabitEthernet3/6no switchportno ip addressload-interval 30!interface TenGigabitEthernet4/1!interface TenGigabitEthernet4/2!interface GigabitEthernet4/3!interface GigabitEthernet4/4description backup link to cr26-asa5520-DOswitchport access vlan 200switchport mode accessswitchport block unicastload-interval 30spanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet4/5no switchportno ip addressload-interval 30!interface GigabitEthernet4/6no switchportno ip addressload-interval 30!interface GigabitEthernet5/1switchport trunk native vlan 806switchport trunk allowed vlan 141-150,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0udld portchannel-protocol lacpchannel-group 17 mode activespanning-tree guard rootservice-policy output EGRESS-POLICY!interface GigabitEthernet5/2!interface GigabitEthernet5/3description Connected to cr26-asa5520-DOswitchport access vlan 200switchport mode accessswitchport block unicastload-interval 30media-type rj45spanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet5/4no switchportno ip addressload-interval 30shutdownmedia-type rj45service-policy output EGRESS-POLICY!interface GigabitEthernet5/5!interface GigabitEthernet5/6description Connected to cr24-3750ME-DOno switchportdampeningno ip addressload-interval 30carrier-delay msec 0udld portchannel-protocol pagpchannel-group 1 mode desirableservice-policy output EGRESS-POLICY!interface GigabitEthernet6/1switchport trunk native vlan 806switchport trunk allowed vlan 141-150,900switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0udld portchannel-protocol lacpchannel-group 17 mode activespanning-tree guard rootservice-policy output EGRESS-POLICY!interface GigabitEthernet6/2load-interval 30!interface GigabitEthernet6/3description Connects to IronPort WSA T1 (L4TM)media-type rj45speed 1000duplex fullservice-policy output EGRESS-POLICY!interface GigabitEthernet6/4description Connected to IronPortmedia-type rj45service-policy output EGRESS-POLICY!interface GigabitEthernet6/5!interface GigabitEthernet6/6description Connected to cr24-3750ME-DOno switchportdampeningno ip addressload-interval 30carrier-delay msec 0udld portchannel-protocol pagpchannel-group 1 mode desirableservice-policy output EGRESS-POLICY!interface GigabitEthernet7/1description Connected to FlashNet - DO NOT ROUTEno switchportip address 172.26.160.185 255.255.252.0no ip redirectsno ip proxy-arpload-interval 30!interface GigabitEthernet7/2switchport mode trunk!interface GigabitEthernet7/3description Connects to IronPort WSA P1switchport access vlan 200switchport mode accessswitchport block unicastload-interval 30spanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet7/4!interface GigabitEthernet7/5!interface GigabitEthernet7/6!interface GigabitEthernet7/7!interface GigabitEthernet7/8!interface GigabitEthernet7/9!interface GigabitEthernet7/10!interface GigabitEthernet7/11!interface GigabitEthernet7/12!interface GigabitEthernet7/13!interface GigabitEthernet7/14!interface GigabitEthernet7/15!interface GigabitEthernet7/16!interface GigabitEthernet7/17!interface GigabitEthernet7/18!interface GigabitEthernet7/19!interface GigabitEthernet7/20!interface GigabitEthernet7/21!interface GigabitEthernet7/22!interface GigabitEthernet7/23!interface GigabitEthernet7/24!interface GigabitEthernet7/25!interface GigabitEthernet7/26!interface GigabitEthernet7/27!interface GigabitEthernet7/28!interface GigabitEthernet7/29!interface GigabitEthernet7/30!interface GigabitEthernet7/31!interface GigabitEthernet7/32!interface GigabitEthernet7/33!interface GigabitEthernet7/34!interface GigabitEthernet7/35!interface GigabitEthernet7/36!interface GigabitEthernet7/37!interface GigabitEthernet7/38!interface GigabitEthernet7/39!interface GigabitEthernet7/40!interface GigabitEthernet7/41!interface GigabitEthernet7/42!interface GigabitEthernet7/43!interface GigabitEthernet7/44!interface GigabitEthernet7/45!interface GigabitEthernet7/46!interface GigabitEthernet7/47!interface GigabitEthernet7/48!interface Vlan1no ip addressshutdown!interface Vlan101description Connected to cr24_2960_Dept_1_VLANdampeningip address 10.125.1.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan102description Connected to cr24_2960_Dept_2_VLANdampeningip address 10.125.1.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan103description Connected to cr24_2960_Dept_3_VLANdampeningip address 10.125.2.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan104description Connected to cr24_2960_Dept_4_VLANdampeningip address 10.125.2.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan105description Connected to cr24_2960_Dept_5_VLANdampeningip address 10.125.3.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan106description Connected to cr24_2960_Dept_6_VLANdampeningip address 10.125.3.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan107description Connected to cr24_2960_Dept_7_VLANdampeningip address 10.125.4.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan108description Connected to cr24_2960_Dept_8_VLANdampeningip address 10.125.4.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan109description Connected to cr24_2960_Dept_9_VLANdampeningip address 10.125.5.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan110description Connected to cr24_2960_Dept_10_VLANdampeningip address 10.125.5.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan111description Connected to cr24_2975_Dept_11_VLANdampeningip address 10.125.6.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan112description Connected to cr24_2975_Dept_12_VLANdampeningip address 10.125.6.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan113description Connected to cr24_2975_Dept_13_VLANdampeningip address 10.125.7.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan114description Connected to cr24_2975_Dept_14_VLANdampeningip address 10.125.7.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan115description Connected to cr24_2975_Dept_15_VLANdampeningip address 10.125.8.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan116description Connected to cr24_2975_Dept_16_VLANdampeningip address 10.125.8.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan117description Connected to cr24_2975_Dept_17_VLANdampeningip address 10.125.9.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan118description Connected to cr24_2975_Dept_18_VLANdampeningip address 10.125.9.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan119description Connected to cr24_2975_Dept_19_VLANdampeningip address 10.125.10.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan120description Connected to cr24_2975_Dept_20_VLANdampeningip address 10.125.10.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan121description Connected to cr26_3750_Dept_31_VLANdampeningip address 10.125.16.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan122description Connected to cr26_3750_Dept_32_VLANdampeningip address 10.125.16.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan123description Connected to cr26_3750_Dept_33_VLANdampeningip address 10.125.17.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan124description Connected to cr26_3750_Dept_34_VLANdampeningip address 10.125.17.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan125description Connected to cr26_3750_Dept_35_VLANdampeningip address 10.125.18.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan126description Connected to cr26_3750_Dept_36_VLANdampeningip address 10.125.18.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan127description Connected to cr26_3750_Dept_37_VLANdampeningip address 10.125.19.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan128description Connected to cr26_3750_Dept_38_VLANdampeningip address 10.125.19.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan129description Connected to cr26_3750_Dept_39_VLANdampeningip address 10.125.20.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan130description Connected to cr26_3750_Dept_40_VLANdampeningip address 10.125.20.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan131description Connected to cr25_3750s_Dept_31_VLANdampeningip address 10.125.26.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan132description Connected to cr25_3750s_Dept_32_VLANdampeningip address 10.125.26.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan133description Connected to cr25_3750s_Dept_33_VLANdampeningip address 10.125.27.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan134description Connected to cr25_3750s_Dept_34_VLANdampeningip address 10.125.27.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan135description Connected to cr25_3750s_Dept_35_VLANdampeningip address 10.125.28.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan136description Connected to cr25_3750s_Dept_36_VLANdampeningip address 10.125.28.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan137description Connected to cr25_3750s_Dept_37_VLANdampeningip address 10.125.29.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan138description Connected to cr25_3750s_Dept_38_VLANdampeningip address 10.125.29.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan139description Connected to cr25_3750s_Dept_39_VLANdampeningip address 10.125.30.1 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan140description Connected to cr25_3750s_Dept_40_VLANdampeningip address 10.125.30.129 255.255.255.128ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan141dampeningip address 10.125.31.1 255.255.255.240ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan142dampeningip address 10.125.31.17 255.255.255.240ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan143dampeningip address 10.125.31.33 255.255.255.240ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan144dampeningip address 10.125.31.49 255.255.255.240ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan145dampeningip address 10.125.31.65 255.255.255.240ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan146dampeningip address 10.125.31.81 255.255.255.240ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim dr-priority 100ip pim sparse-modeload-interval 30!interface Vlan147dampeningip address 10.125.31.97 255.255.255.240ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan148dampeningip address 10.125.31.113 255.255.255.240ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan149dampeningip address 10.125.31.129 255.255.255.240ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan150dampeningip address 10.125.31.145 255.255.255.240ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan200description Connected to cr24_ASA_Inside_Portdampeningip address 10.125.33.9 255.255.255.0ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.125.0.0 255.255.0.0 5logging event link-statusload-interval 30carrier-delay msec 0!interface Vlan900description Mgmt_VLANdampeningip address 10.125.34.1 255.255.255.224no ip redirectsno ip unreachablesno ip proxy-arpip pim dr-priority 100ip pim sparse-modeip summary-address eigrp 100 10.125.0.0 255.255.0.0 5load-interval 30!!router eigrp 100passive-interface defaultno passive-interface Vlan200no passive-interface GigabitEthernet3/3no passive-interface GigabitEthernet4/3no passive-interface GigabitEthernet4/4no passive-interface GigabitEthernet4/6no passive-interface GigabitEthernet5/4no passive-interface GigabitEthernet5/5no passive-interface GigabitEthernet5/6no passive-interface GigabitEthernet6/2no passive-interface GigabitEthernet6/5no passive-interface GigabitEthernet6/6no passive-interface Port-channel1no passive-interface Port-channel13no passive-interface Port-channel15no passive-interface Port-channel17distribute-list route-map EIGRP_STUB_ROUTES out Vlan200distribute-list route-map EIGRP_STUB_ROUTES out Port-channel13distribute-list route-map EIGRP_STUB_ROUTES out Port-channel15no auto-summaryeigrp router-id 10.125.100.1network 10.125.0.0 0.0.255.255nsf!no ip http serverno ip http secure-server!ip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255ip access-list standard Deny_PIM_DM_Fallbackdeny 224.0.1.39deny 224.0.1.40permit any!ip access-list extended COPP-CRITICAL-APPLICATIONSremark DHCPpermit udp host 0.0.0.0 host 255.255.255.255 eq bootpspermit udp host 10.125.31.2 eq bootps any eq bootpsip access-list extended COPP-FILE-MANAGEMENTremark (initiated) FTP (active and passive)permit tcp 172.26.160.0 0.0.3.255 eq ftp host 172.26.160.185 gt 1023 establishedpermit tcp 172.26.160.0 0.0.3.255 eq ftp-data host 172.26.160.185 gt 1023permit tcp 172.26.160.0 0.0.3.255 gt 1023 host 172.26.160.185 gt 1023 establishedremark (initiated) TFTPpermit udp 172.26.160.0 0.0.3.255 gt 1023 host 172.26.160.185 gt 1023ip access-list extended COPP-IGPremark IGP (EIGRP)permit eigrp any host 224.0.0.10permit eigrp any anyip access-list extended COPP-INTERACTIVE-MANAGEMENTremark RADIUS (return traffic)permit udp host 10.125.31.4 host 10.125.100.2remark SSHpermit tcp 10.124.0.0 0.3.255.255 host 10.125.100.2 eq 22remark SNMPpermit udp host 172.26.160.100 host 10.125.100.2 eq snmpremark NTPpermit udp host 172.26.160.10 host 172.26.160.185 eq ntpip access-list extended COPP-MONITORINGremark PING-ECHOpermit icmp any any echoremark PING-ECHO-REPLYpermit icmp any any echo-replyremark TRACEROUTEpermit icmp any any ttl-exceededpermit icmp any any port-unreachableip access-list extended COPP-UNDESIRABLEremark UNDESIRABLEpermit udp any any eq 1434ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255!access-list 1 permit 0.0.0.0access-list 1 permit 10.126.0.0access-list 1 permit 10.127.0.0access-list 1 permit 10.125.0.0!route-map EIGRP_STUB_ROUTES permit 10match ip address 1!!!control-planeservice-policy input system-cpp-policy!alias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassialias exec dsno show ip dhcp snooping bind!line con 0exec-timeout 0 0password 7 104D000A0618stopbits 1line vty 0 4exec-timeout 0 0password 7 0822455D0A16loginline vty 5 15exec-timeout 0 0login!!monitor session 10 source interface Gi4/4monitor session 10 source interface Gi5/3monitor session 10 filter packet-type good rxmonitor session 10 destination interface Gi6/3ntp clock-period 17181779ntp server 172.26.160.10endWAN Aggregation
Cr24-3750ME-DO!! Last configuration change at 22:59:31 EDT Wed Sep 2 2009! NVRAM config last updated at 22:59:37 EDT Wed Sep 2 2009!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr24-3750ME-DO!boot-start-markerboot-end-marker!enable secret 5 $1$.2Ap$J0k3w04nQHip4UNN28KxX0!no aaa new-modelclock timezone EST -5clock summer-time EDT recurringsystem mtu routing 1500ip subnet-zeroip routing!!no ip domain-lookupip multicast-routing distributedvtp domain District-Officevtp mode transparent!no mpls traffic-eng auto-bw timers frequency 0mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!key chain eigrp-keykey 1key-string 7 02050D480809!crypto pki trustpoint HTTPS_SS_CERT_KEYPAIRenrollment selfsignedserial-numberrevocation-check nonersakeypair HTTPS_SS_CERT_KEYPAIR!!crypto pki certificate chain HTTPS_SS_CERT_KEYPAIRcertificate self-signed 01 nvram:8F1F4D80host#2E2E.cer!!!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause storm-controlerrdisable recovery interval 120port-channel load-balance src-dst-ip!vlan internal allocation policy ascending!vlan 501name School-Site1!vlan 502name School-Site2!vlan 503name School-Site3!vlan 504name School-Site4!vlan 505name School-Site5!vlan 506name School-Site6!vlan 507name School-Site7!vlan 508name School-Site8!vlan 509name School-Site9!vlan 510name School-Site10!vlan 511name School-Site11!vlan 512name School-Site12!vlan 513name School-Site13!vlan 514name School-Site14!vlan 515name School-Site15!vlan 516name School-Site16!vlan 517name School-Site17!vlan 518name School-Site18!vlan 519name School-Site19!vlan 520name School-Site20!vlan 521name School-Site21!vlan 522name School-Site22!vlan 523name School-Site23!vlan 524name School-Site24!vlan 525name School-Site25!vlan 526name School-Site26!vlan 527name School-Site27!vlan 528name School-Site28!vlan 529name School-Site29!vlan 530name School-Site30!vlan 531name School-Site31!vlan 532name School-Site32!vlan 533name School-Site33!vlan 534name School-Site34!vlan 535name School-Site35!vlan 536name School-Site36!vlan 537name School-Site37!vlan 538name School-Site38!vlan 539name School-Site39!vlan 540name School-Site40!vlan 541name School-Site41!vlan 542name School-Site42!vlan 543name School-Site43!vlan 544name School-Site44!vlan 545name School-Site45!vlan 546name School-Site46!vlan 547name School-Site47!vlan 548name School-Site48!vlan 549name School-Site49!vlan 550name School-Site50!vlan 601name School-Site51!vlan 602name School-Site52!vlan 603name School-Site53!vlan 604name School-Site54!vlan 605name School-Site55!vlan 606name School-Site56!vlan 607name School-Site57!vlan 608name School-Site58!vlan 609name School-Site59!vlan 610name School-Site60!vlan 611name School-Site61!vlan 612name School-Site62!vlan 613name School-Site63!vlan 614name School-Site64!vlan 615name School-Site65!vlan 616name School-Site66!vlan 617name School-Site67!vlan 618name School-Site68!vlan 619name School-Site69!vlan 620name School-Site70!vlan 621name School-Site71!vlan 622name School-Site72!vlan 623name School-Site73!vlan 624name School-Site74!vlan 625name School-Site75!vlan 626name School-Site76!vlan 627name School-Site77!vlan 628name School-Site78!vlan 629name School-Site79!vlan 630name School-Site80!vlan 631name School-Site81!vlan 632name School-Site82!vlan 633name School-Site83!vlan 634name School-Site84!vlan 635name School-Site85!vlan 636name School-Site86!vlan 637name School-Site87!vlan 638name School-Site88!vlan 639name School-Site89!vlan 640name School-Site90!vlan 641name School-Site91!vlan 642name School-Site92!vlan 643name School-Site93!vlan 644name School-Site94!vlan 645name School-Site95!vlan 646name School-Site96!vlan 647name School-Site97!vlan 648name School-Site98!vlan 649name School-Site99!vlan 650name School-Site100!vlan 801name MetroE_G1/1/1_Hopping_VLAN!vlan 802name MetroE_G1/1/2_Hopping_VLAN!!class-map match-all GOLDmatch ip dscp cs6match ip dscp cs7match ip dscp cs3match ip dscp cs2class-map match-all SILVERmatch ip dscp af21match ip dscp af22match ip dscp af23match ip dscp af11match ip dscp af12match ip dscp af13match ip dscp af31match ip dscp af32match ip dscp af33match ip dscp af41match ip dscp af42match ip dscp af43class-map match-all School_Site11description 3750-SS11match vlan 511class-map match-all School_Site22description 3750-SS22match vlan 522class-map match-all School_Site33description 3750-SS33match vlan 533class-map match-all School_Site44description 3750-SS44match vlan 544class-map match-all School_Site55description 3750-SS55match vlan 606class-map match-all School_Site66description 3750-SS66match vlan 617class-map match-all School_Site77description 3750-SS77match vlan 628class-map match-all School_Site88description 3750-SS88match vlan 639class-map match-all School_Site99description 3750-SS99match vlan 650class-map match-all School_Site10description 3750-SS10match vlan 510class-map match-all School_Site23description 3750-SS23match vlan 523class-map match-all School_Site32description 3750-SS32match vlan 532class-map match-all School_Site45description 3750-SS45match vlan 545class-map match-all School_Site54description 3750-SS54match vlan 605class-map match-all School_Site67description 3750-SS67match vlan 618class-map match-all School_Site76description 3750-SS76match vlan 627class-map match-all School_Site89description 3750-SS89match vlan 640class-map match-all School_Site98description 3750-SS98match vlan 649class-map match-all School_Site13description 3750-SS13match vlan 513class-map match-all School_Site20description 3750-SS20match vlan 520class-map match-all School_Site31description 3750-SS31match vlan 531class-map match-all School_Site46description 3750-SS46match vlan 546class-map match-all School_Site57description 3750-SS57match vlan 608class-map match-all School_Site64description 3750-SS64match vlan 615class-map match-all School_Site75description 3750-SS75match vlan 626class-map match-all School_Site12description 3750-SS12match vlan 512class-map match-all School_Site21description 3750-SS21match vlan 521class-map match-all School_Site30description 3750-SS30match vlan 530class-map match-all School_Site47description 3750-SS47match vlan 547class-map match-all School_Site56description 3750-SS56match vlan 607class-map match-all School_Site65description 3750-SS65match vlan 616class-map match-all School_Site74description 3750-SS74match vlan 625class-map match-all School_Site15description 3750-SS15match vlan 515class-map match-all School_Site26description 3750-SS26match vlan 526class-map match-all School_Site37description 3750-SS37match vlan 537class-map match-all School_Site40description 3750-SS40match vlan 540class-map match-all School_Site51description 3750-SS51match vlan 602class-map match-all School_Site62description 3750-SS62match vlan 613class-map match-all School_Site73description 3750-SS73match vlan 624class-map match-all School_Site14description 3750-SS14match vlan 514class-map match-all School_Site27description 3750-SS27match vlan 527class-map match-all School_Site36description 3750-SS36match vlan 536class-map match-all School_Site41description 3750-SS41match vlan 541class-map match-all School_Site50description 3750-SS50match vlan 550class-map match-all School_Site63description 3750-SS63match vlan 614class-map match-all School_Site72description 3750-SS72match vlan 623class-map match-all School_Site17description 3750-SS17match vlan 517class-map match-all School_Site24description 3750-SS24match vlan 524class-map match-all School_Site35description 3750-SS35match vlan 535class-map match-all School_Site42description 3750-SS42match vlan 542class-map match-all School_Site53description 3750-SS53match vlan 604class-map match-all School_Site60description 3750-SS60match vlan 611class-map match-all School_Site71description 3750-SS71match vlan 622class-map match-all School_Site16description 3750-SS16match vlan 516class-map match-all School_Site25description 3750-SS25match vlan 525class-map match-all School_Site34description 3750-SS34match vlan 534class-map match-all School_Site43description 3750-SS43match vlan 543class-map match-all School_Site52description 3750-SS52match vlan 603class-map match-all School_Site61description 3750-SS61match vlan 612class-map match-all School_Site70description 3750-SS70match vlan 621class-map match-all School_Site19description 3750-SS19match vlan 519class-map match-all School_Site80description 3750-SS80match vlan 631class-map match-all School_Site91description 3750-SS91match vlan 642class-map match-all School_Site18description 3750-SS18match vlan 518class-map match-all School_Site81description 3750-SS81match vlan 632class-map match-all School_Site90description 3750-SS90match vlan 641class-map match-all School_Site28description 3750-SS28match vlan 528class-map match-all School_Site39description 3750-SS39match vlan 539class-map match-all School_Site82description 3750-SS82match vlan 633class-map match-all School_Site93description 3750-SS93match vlan 644class-map match-all School_Site29description 3750-SS29match vlan 529class-map match-all School_Site38description 3750-SS38match vlan 538class-map match-all School_Site83description 3750-SS83match vlan 634class-map match-all School_Site92description 3750-SS92match vlan 643class-map match-all School_Site48description 3750-SS48match vlan 548class-map match-all School_Site59description 3750-SS59match vlan 610class-map match-all School_Site84description 3750-SS84match vlan 635class-map match-all School_Site95description 3750-SS95match vlan 646class-map match-all School_Site49description 3750-SS49match vlan 549class-map match-all School_Site58description 3750-SS58match vlan 609class-map match-all School_Site85description 3750-SS85match vlan 636class-map match-all School_Site94description 3750-SS94match vlan 645class-map match-all School_Site68description 3750-SS68match vlan 619class-map match-all School_Site79description 3750-SS79match vlan 630class-map match-all School_Site86description 3750-SS86match vlan 637class-map match-all School_Site97description 3750-SS97match vlan 648class-map match-all School_Site69description 3750-SS69match vlan 620class-map match-all School_Site78description 3750-SS78match vlan 629class-map match-all School_Site87description 3750-SS87match vlan 638class-map match-all School_Site96description 3750-SS96match vlan 647class-map match-all REAL_TIMEmatch ip dscp efmatch ip dscp cs5match ip dscp cs4class-map match-all School_Site1description cr2-4507-SS1match vlan 501class-map match-all School_Site100description cr36-3750s-SS100match vlan 650class-map match-all School_Site2description 3750-SS2match vlan 502class-map match-all School_Site3description 3750-SS3match vlan 503class-map match-all School_Site4description 3750-SS4match vlan 504class-map match-all School_Site5description 3750-SS5match vlan 505class-map match-all School_Site6description 3750-SS6match vlan 506class-map match-all School_Site7description 3750-SS7match vlan 507class-map match-all School_Site8description 3750-SS8match vlan 508class-map match-all School_Site9description 3750-SS9match vlan 509!!policy-map School-Child-Policy-Mapclass REAL_TIMEprioritypolice cir percent 30 conform-action set-cos-transmit 5 exceed-action drop violate-action dropset cos 5class GOLDbandwidth percent 5set cos 3class SILVERbandwidth percent 30set cos 2class class-defaultbandwidth percent 35set cos 0policy-map School-51to100-Parent-Policy-Mapclass School_Site100shape average 20000000service-policy School-Child-Policy-Mapclass School_Site51shape average 20000000service-policy School-Child-Policy-Mapclass School_Site52shape average 20000000service-policy School-Child-Policy-Mapclass School_Site53shape average 20000000service-policy School-Child-Policy-Mapclass School_Site54shape average 20000000service-policy School-Child-Policy-Mapclass School_Site55shape average 20000000service-policy School-Child-Policy-Mapclass School_Site56shape average 20000000service-policy School-Child-Policy-Mapclass School_Site57shape average 20000000service-policy School-Child-Policy-Mapclass School_Site58shape average 20000000service-policy School-Child-Policy-Mapclass School_Site59shape average 20000000service-policy School-Child-Policy-Mapclass School_Site60shape average 20000000service-policy School-Child-Policy-Mapclass School_Site61shape average 20000000service-policy School-Child-Policy-Mapclass School_Site62shape average 20000000service-policy School-Child-Policy-Mapclass School_Site63shape average 20000000service-policy School-Child-Policy-Mapclass School_Site64shape average 20000000service-policy School-Child-Policy-Mapclass School_Site65shape average 20000000service-policy School-Child-Policy-Mapclass School_Site66shape average 20000000service-policy School-Child-Policy-Mapclass School_Site67shape average 20000000service-policy School-Child-Policy-Mapclass School_Site68shape average 20000000service-policy School-Child-Policy-Mapclass School_Site69shape average 20000000service-policy School-Child-Policy-Mapclass School_Site70shape average 20000000service-policy School-Child-Policy-Mapclass School_Site71shape average 20000000service-policy School-Child-Policy-Mapclass School_Site72shape average 20000000service-policy School-Child-Policy-Mapclass School_Site73shape average 20000000service-policy School-Child-Policy-Mapclass School_Site74shape average 20000000service-policy School-Child-Policy-Mapclass School_Site75shape average 20000000service-policy School-Child-Policy-Mapclass School_Site76shape average 20000000service-policy School-Child-Policy-Mapclass School_Site77shape average 20000000service-policy School-Child-Policy-Mapclass School_Site78shape average 20000000service-policy School-Child-Policy-Mapclass School_Site79shape average 20000000service-policy School-Child-Policy-Mapclass School_Site80shape average 20000000service-policy School-Child-Policy-Mapclass School_Site81shape average 20000000service-policy School-Child-Policy-Mapclass School_Site82shape average 20000000service-policy School-Child-Policy-Mapclass School_Site83shape average 20000000service-policy School-Child-Policy-Mapclass School_Site84shape average 20000000service-policy School-Child-Policy-Mapclass School_Site85shape average 20000000service-policy School-Child-Policy-Mapclass School_Site86shape average 20000000service-policy School-Child-Policy-Mapclass School_Site87shape average 20000000service-policy School-Child-Policy-Mapclass School_Site88shape average 20000000service-policy School-Child-Policy-Mapclass School_Site89shape average 20000000service-policy School-Child-Policy-Mapclass School_Site90shape average 20000000service-policy School-Child-Policy-Mapclass School_Site91shape average 20000000service-policy School-Child-Policy-Mapclass School_Site92shape average 20000000service-policy School-Child-Policy-Mapclass School_Site93shape average 20000000service-policy School-Child-Policy-Mapclass School_Site94shape average 20000000service-policy School-Child-Policy-Mapclass School_Site95shape average 20000000service-policy School-Child-Policy-Mapclass School_Site96shape average 20000000service-policy School-Child-Policy-Mapclass School_Site97shape average 20000000service-policy School-Child-Policy-Mapclass School_Site98shape average 20000000service-policy School-Child-Policy-Mapclass School_Site99shape average 10000000service-policy School-Child-Policy-Mappolicy-map School-1to50-Parent-Policy-Mapclass School_Site1shape average 20000000service-policy School-Child-Policy-Mapclass School_Site2shape average 20000000service-policy School-Child-Policy-Mapclass School_Site3shape average 20000000service-policy School-Child-Policy-Mapclass School_Site4shape average 20000000service-policy School-Child-Policy-Mapclass School_Site5shape average 20000000service-policy School-Child-Policy-Mapclass School_Site6shape average 20000000service-policy School-Child-Policy-Mapclass School_Site7shape average 20000000service-policy School-Child-Policy-Mapclass School_Site8shape average 20000000service-policy School-Child-Policy-Mapclass School_Site9shape average 20000000service-policy School-Child-Policy-Mapclass School_Site10shape average 20000000service-policy School-Child-Policy-Mapclass School_Site11shape average 20000000service-policy School-Child-Policy-Mapclass School_Site12shape average 20000000service-policy School-Child-Policy-Mapclass School_Site13shape average 20000000service-policy School-Child-Policy-Mapclass School_Site14shape average 20000000service-policy School-Child-Policy-Mapclass School_Site15shape average 20000000service-policy School-Child-Policy-Mapclass School_Site16shape average 20000000service-policy School-Child-Policy-Mapclass School_Site17shape average 20000000service-policy School-Child-Policy-Mapclass School_Site18shape average 20000000service-policy School-Child-Policy-Mapclass School_Site19shape average 20000000service-policy School-Child-Policy-Mapclass School_Site20shape average 20000000service-policy School-Child-Policy-Mapclass School_Site21shape average 20000000service-policy School-Child-Policy-Mapclass School_Site22shape average 20000000service-policy School-Child-Policy-Mapclass School_Site23shape average 20000000service-policy School-Child-Policy-Mapclass School_Site24shape average 20000000service-policy School-Child-Policy-Mapclass School_Site25shape average 20000000service-policy School-Child-Policy-Mapclass School_Site26shape average 20000000service-policy School-Child-Policy-Mapclass School_Site27shape average 20000000service-policy School-Child-Policy-Mapclass School_Site28shape average 20000000service-policy School-Child-Policy-Mapclass School_Site29shape average 20000000service-policy School-Child-Policy-Mapclass School_Site30shape average 20000000service-policy School-Child-Policy-Mapclass School_Site31shape average 20000000service-policy School-Child-Policy-Mapclass School_Site32shape average 20000000service-policy School-Child-Policy-Mapclass School_Site33shape average 20000000service-policy School-Child-Policy-Mapclass School_Site34shape average 20000000service-policy School-Child-Policy-Mapclass School_Site35shape average 20000000service-policy School-Child-Policy-Mapclass School_Site36shape average 20000000service-policy School-Child-Policy-Mapclass School_Site37shape average 20000000service-policy School-Child-Policy-Mapclass School_Site38shape average 20000000service-policy School-Child-Policy-Mapclass School_Site39shape average 20000000service-policy School-Child-Policy-Mapclass School_Site40shape average 20000000service-policy School-Child-Policy-Mapclass School_Site41shape average 20000000service-policy School-Child-Policy-Mapclass School_Site42shape average 20000000service-policy School-Child-Policy-Mapclass School_Site43shape average 20000000service-policy School-Child-Policy-Mapclass School_Site44shape average 20000000service-policy School-Child-Policy-Mapclass School_Site45shape average 20000000service-policy School-Child-Policy-Mapclass School_Site46shape average 20000000service-policy School-Child-Policy-Mapclass School_Site47shape average 20000000service-policy School-Child-Policy-Mapclass School_Site48shape average 20000000service-policy School-Child-Policy-Mapclass School_Site49shape average 20000000service-policy School-Child-Policy-Mapclass School_Site50shape average 10000000service-policy School-Child-Policy-Map!!!!interface Loopback0ip address 10.126.100.1 255.255.255.255!interface Port-channel1description Connected to cr24-4507-DOno switchportdampeningip address 10.125.32.5 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.127.0.0 255.255.0.0 5ip summary-address eigrp 100 10.126.0.0 255.255.0.0 5logging event bundle-statusload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 out!interface FastEthernet1/0/1!interface FastEthernet1/0/2!interface FastEthernet1/0/3!interface FastEthernet1/0/4!interface FastEthernet1/0/5!interface FastEthernet1/0/6!interface FastEthernet1/0/7!interface FastEthernet1/0/8!interface FastEthernet1/0/9!interface FastEthernet1/0/10!interface FastEthernet1/0/11!interface FastEthernet1/0/12!interface FastEthernet1/0/13!interface FastEthernet1/0/14!interface FastEthernet1/0/15!interface FastEthernet1/0/16!interface FastEthernet1/0/17!interface FastEthernet1/0/18!interface FastEthernet1/0/19!interface FastEthernet1/0/20!interface FastEthernet1/0/21!interface FastEthernet1/0/22!interface FastEthernet1/0/23!interface FastEthernet1/0/24description Connected to FlashNetno switchportip address 172.26.160.184 255.255.254.0no ip redirectsno ip proxy-arpload-interval 30!interface GigabitEthernet1/0/1description Connected to cr24-4507-DOno switchportno ip addresslogging event bundle-statusload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirable!interface GigabitEthernet1/0/2description Connected to cr24-4507-DOno switchportno ip addresslogging event bundle-statusload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirable!interface GigabitEthernet1/1/1description Connected to SP-MPLS-Core-cr24-6500-1switchport trunk native vlan 801switchport trunk allowed vlan 501-550switchport mode trunklogging event trunk-statusload-interval 30carrier-delay msec 0priority-queue outmls qos trust dscpspanning-tree portfast trunkspanning-tree bpdufilter enablespanning-tree guard rootservice-policy output School-1to50-Parent-Policy-Maphold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/1/2description Connected to SP-MPLS-Core-cr24-6500-1switchport trunk native vlan 802switchport trunk allowed vlan 601-650switchport mode trunklogging event trunk-statusload-interval 30carrier-delay msec 0priority-queue outmls qos trust dscpspanning-tree portfast trunkspanning-tree bpdufilter enablespanning-tree guard rootservice-policy output School-51to100-Parent-Policy-Maphold-queue 2000 inhold-queue 2000 out!interface Vlan1no ip addressshutdown!interface Vlan501description Connected to cr35-4507-SS1dampeningip address 10.126.0.0 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan502dampeningip address 10.126.0.2 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan503dampeningip address 10.126.0.4 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan504dampeningip address 10.126.0.6 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan505dampeningip address 10.126.0.8 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan506dampeningip address 10.126.0.10 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan507dampeningip address 10.126.0.12 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan508dampeningip address 10.126.0.14 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan509dampeningip address 10.126.0.16 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan510dampeningip address 10.126.0.18 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan511dampeningip address 10.126.0.20 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan512dampeningip address 10.126.0.22 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan513dampeningip address 10.126.0.24 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan514dampeningip address 10.126.0.26 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan515dampeningip address 10.126.0.28 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan516dampeningip address 10.126.0.30 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan517dampeningip address 10.126.0.32 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan518dampeningip address 10.126.0.34 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan519dampeningip address 10.126.0.36 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan520dampeningip address 10.126.0.38 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan521dampeningip address 10.126.0.40 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan522dampeningip address 10.126.0.42 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan523dampeningip address 10.126.0.44 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan524dampeningip address 10.126.0.46 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan525dampeningip address 10.126.0.48 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan526dampeningip address 10.126.0.50 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan527dampeningip address 10.126.0.52 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan528dampeningip address 10.126.0.54 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan529dampeningip address 10.126.0.56 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan530dampeningip address 10.126.0.58 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan531dampeningip address 10.126.0.60 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan532dampeningip address 10.126.0.62 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan533dampeningip address 10.126.0.64 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan534dampeningip address 10.126.0.66 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan535dampeningip address 10.126.0.68 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan536dampeningip address 10.126.0.70 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan537dampeningip address 10.126.0.72 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan538dampeningip address 10.126.0.74 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan539dampeningip address 10.126.0.76 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan540dampeningip address 10.126.0.78 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan541dampeningip address 10.126.0.80 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan542dampeningip address 10.126.0.82 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan543dampeningip address 10.126.0.84 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan544dampeningip address 10.126.0.86 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan545dampeningip address 10.126.0.88 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan546dampeningip address 10.126.0.90 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan547dampeningip address 10.126.0.92 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan548dampeningip address 10.126.0.94 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan549dampeningip address 10.126.0.96 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan550dampeningip address 10.126.0.98 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan601description Connected to cr36-3750-SS2dampeningip address 10.126.1.0 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan602dampeningip address 10.126.1.2 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan603dampeningip address 10.126.1.4 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan604dampeningip address 10.126.1.6 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan605dampeningip address 10.126.1.8 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan606dampeningip address 10.126.1.10 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan607dampeningip address 10.126.1.12 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan608dampeningip address 10.126.1.14 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan609dampeningip address 10.126.1.16 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan610dampeningip address 10.126.1.18 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan611dampeningip address 10.126.1.20 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan612dampeningip address 10.126.1.22 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan613dampeningip address 10.126.1.24 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan614dampeningip address 10.126.1.26 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan615dampeningip address 10.126.1.28 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan616dampeningip address 10.126.1.30 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan617dampeningip address 10.126.1.32 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan618dampeningip address 10.126.1.34 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan619dampeningip address 10.126.1.36 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan620dampeningip address 10.126.1.38 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan621dampeningip address 10.126.1.40 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan622dampeningip address 10.126.1.42 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan623dampeningip address 10.126.1.44 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan624dampeningip address 10.126.1.46 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan625dampeningip address 10.126.1.48 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan626dampeningip address 10.126.1.50 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan627dampeningip address 10.126.1.52 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan628dampeningip address 10.126.1.54 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan629dampeningip address 10.126.1.56 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan630dampeningip address 10.126.1.58 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan631dampeningip address 10.126.1.60 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan632dampeningip address 10.126.1.62 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan633dampeningip address 10.126.1.64 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan634dampeningip address 10.126.1.66 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan635dampeningip address 10.126.1.68 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan636dampeningip address 10.126.1.70 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan637dampeningip address 10.126.1.72 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan638dampeningip address 10.126.1.74 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan639dampeningip address 10.126.1.76 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan640dampeningip address 10.126.1.78 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan641dampeningip address 10.126.1.80 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan642dampeningip address 10.126.1.82 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan643dampeningip address 10.126.1.84 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan644dampeningip address 10.126.1.86 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan645dampeningip address 10.126.1.88 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan646dampeningip address 10.126.1.90 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan647dampeningip address 10.126.1.92 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan648dampeningip address 10.126.1.94 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan649dampeningip address 10.126.1.96 255.255.255.254ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan650dampeningip address 10.126.1.98 255.255.255.254ip hold-time eigrp 100 20ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.124.0.0 255.252.0.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!!router eigrp 100passive-interface defaultno passive-interface Vlan501no passive-interface Vlan502no passive-interface Vlan503no passive-interface Vlan504no passive-interface Vlan505no passive-interface Vlan506no passive-interface Vlan507no passive-interface Vlan508no passive-interface Vlan509no passive-interface Vlan510no passive-interface Vlan511no passive-interface Vlan512no passive-interface Vlan513no passive-interface Vlan514no passive-interface Vlan515no passive-interface Vlan516no passive-interface Vlan517no passive-interface Vlan518no passive-interface Vlan519no passive-interface Vlan520no passive-interface Vlan521no passive-interface Vlan522no passive-interface Vlan523no passive-interface Vlan524no passive-interface Vlan525no passive-interface Vlan526no passive-interface Vlan527no passive-interface Vlan528no passive-interface Vlan529no passive-interface Vlan530no passive-interface Vlan531no passive-interface Vlan532no passive-interface Vlan533no passive-interface Vlan534no passive-interface Vlan535no passive-interface Vlan536no passive-interface Vlan537no passive-interface Vlan538no passive-interface Vlan539no passive-interface Vlan540no passive-interface Vlan541no passive-interface Vlan542no passive-interface Vlan543no passive-interface Vlan544no passive-interface Vlan545no passive-interface Vlan546no passive-interface Vlan547no passive-interface Vlan548no passive-interface Vlan549no passive-interface Vlan550no passive-interface Vlan601no passive-interface Vlan602no passive-interface Vlan603no passive-interface Vlan604no passive-interface Vlan605no passive-interface Vlan606no passive-interface Vlan607no passive-interface Vlan608no passive-interface Vlan609no passive-interface Vlan610no passive-interface Vlan611no passive-interface Vlan612no passive-interface Vlan613no passive-interface Vlan614no passive-interface Vlan615no passive-interface Vlan616no passive-interface Vlan617no passive-interface Vlan618no passive-interface Vlan619no passive-interface Vlan620no passive-interface Vlan621no passive-interface Vlan622no passive-interface Vlan623no passive-interface Vlan624no passive-interface Vlan625no passive-interface Vlan626no passive-interface Vlan627no passive-interface Vlan628no passive-interface Vlan629no passive-interface Vlan630no passive-interface Vlan631no passive-interface Vlan632no passive-interface Vlan633no passive-interface Vlan634no passive-interface Vlan635no passive-interface Vlan636no passive-interface Vlan637no passive-interface Vlan638no passive-interface Vlan639no passive-interface Vlan640no passive-interface Vlan641no passive-interface Vlan642no passive-interface Vlan643no passive-interface Vlan644no passive-interface Vlan645no passive-interface Vlan646no passive-interface Vlan647no passive-interface Vlan648no passive-interface Vlan649no passive-interface Vlan650no passive-interface Port-channel1no auto-summaryeigrp router-id 10.126.100.1network 10.125.0.0 0.0.255.255network 10.126.0.0 0.0.255.255!ip classlessip route 172.26.158.0 255.255.255.0 172.26.160.1!no ip http serverno ip http secure-server!ip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255ip access-list standard Deny_PIM_DM_Fallbackdeny 224.0.1.39deny 224.0.1.40permit any!ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255!!snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12!control-plane!alias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassialias exec dsno show ip dhcp snooping bind!line con 0exec-timeout 0 0password 7 00071A150754line vty 0 4exec-timeout 0 0password 7 02050D480809loginline vty 5 15exec-timeout 0 0no login!ntp clock-period 36028666ntp server 172.26.160.10endCr26-asa5520-DOcr26-asa5520-do# wr t: Saved:ASA Version 8.2(1)!hostname cr26-asa5520-dodomain-name cisco.comenable password 8Ry2YjIyt7RRXU24 encryptedpasswd 2KFQnbNIdI.2KYOU encryptednamesdns-guard!interface GigabitEthernet0/0description Connected to cr24-4507-DOno nameifno security-levelno ip address!interface GigabitEthernet0/1description backup to cr24-4507-DOno nameifno security-levelno ip address!interface GigabitEthernet0/2description Connected to Internet - cr26-6500-1nameif outsidesecurity-level 0ip address 198.133.219.5 255.255.255.0ospf message-digest-key 1 md5 <removed>ospf authentication message-digest!interface GigabitEthernet0/3description School DMZnameif dmzsecurity-level 50ip address 10.25.34.1 255.255.255.0!interface Management0/0nameif managementsecurity-level 100ip address 172.26.160.225 255.255.252.0management-only!interface Redundant1description Connected to cr24-4507-DOmember-interface GigabitEthernet0/0member-interface GigabitEthernet0/1nameif insidesecurity-level 100allow-ssc-mgmtip address 10.125.33.10 255.255.255.0authentication key eigrp 100 <removed> key-id 1authentication mode eigrp 100 md5!boot system disk0:/asa821-k8.binftp mode passivedns server-group DefaultDNSdomain-name cisco.comaccess-list wsa-farm extended permit ip host 10.125.33.8 anyaccess-list proxylist extended deny ip host 10.125.33.8 anyaccess-list proxylist extended permit tcp 10.0.0.0 255.0.0.0 any eq wwwaccess-list proxylist extended permit tcp 10.0.0.0 255.0.0.0 any eq httpsaccess-list Outbound extended permit tcp 10.0.0.0 255.0.0.0 any eq wwwaccess-list Outbound extended permit tcp 10.0.0.0 255.0.0.0 any eq httpsaccess-list Outbound extended permit icmp 10.0.0.0 255.0.0.0 any echoaccess-list Outbound extended permit udp 10.0.0.0 255.0.0.0 host 10.25.34.13 eq domainaccess-list Outbound extended permit tcp 10.0.0.0 255.0.0.0 host 10.25.34.12 eq smtpaccess-list Outbound extended permit tcp 10.0.0.0 255.0.0.0 host 10.25.34.12 eq pop3access-list Outbound extended permit tcp 10.0.0.0 255.0.0.0 host 10.25.34.12 eq imap4access-list Inbound-Routes standard permit host 0.0.0.0access-list DMZ extended permit udp host 10.25.34.13 any eq domainaccess-list DMZ extended permit tcp host 10.25.34.13 any eq domainaccess-list DMZ extended permit tcp host 10.25.34.12 any eq smtpaccess-list DMZ extended permit tcp host 10.25.34.11 any eq wwwaccess-list DMZ extended permit tcp host 10.25.34.11 any eq httpsaccess-list Inbound extended permit udp any host 198.133.219.13 eq domainaccess-list Inbound extended permit tcp any host 198.133.219.13 eq domainaccess-list Inbound extended permit tcp any host 198.133.219.11 eq smtpaccess-list Inbound extended permit tcp any host 198.133.219.10 eq wwwaccess-list Inbound extended permit tcp any host 198.133.219.10 eq httpspager lines 24logging enablelogging console criticallogging buffered debugginglogging asdm informationalmtu outside 1500mtu management 1500mtu inside 1500mtu dmz 1500no failovericmp unreachable rate-limit 1 burst-size 1asdm image disk0:/asdm-507.binno asdm history enablearp timeout 14400global (outside) 10 interfacenat (inside) 10 10.0.0.0 255.0.0.0static (inside,outside) 198.133.219.2 10.125.31.2 netmask 255.255.255.255static (dmz,outside) 198.133.219.10 10.25.34.10 netmask 255.255.255.255static (dmz,outside) 198.133.219.11 10.25.34.11 netmask 255.255.255.255static (dmz,outside) 198.133.219.12 10.25.34.12 netmask 255.255.255.255static (dmz,outside) 198.133.219.13 10.25.34.13 netmask 255.255.255.255static (inside,dmz) 10.0.0.0 10.0.0.0 netmask 255.0.0.0access-group Outbound in interface insideaccess-group DMZ in interface dmzaccess-group Inbound in interface outside!route-map Inbound-EIGRP permit 10match ip address Inbound-Routes!!router eigrp 100no auto-summaryeigrp stub redistributednetwork 10.125.33.0 255.255.255.0passive-interface defaultno passive-interface insideredistribute ospf 200 metric 1000000 2000 255 1 1500 route-map Inbound-EIGRP!router ospf 200network 198.133.219.0 255.255.255.0 area 100area 100 authentication message-digestlog-adj-changes!route management 172.26.0.0 255.255.0.0 172.26.160.1 1timeout xlate 3:00:00timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolutetimeout tcp-proxy-reassembly 0:01:00dynamic-access-policy-record DfltAccessPolicyaaa-server tacacs-servers protocol tacacs+aaa-server tacacs-servers (management) host <tacacs+ server>key <secret key>aaa authentication ssh console tacacs-servers LOCALaaa authentication serial console tacacs-servers LOCALaaa authentication enable console tacacs-servers LOCALaaa authentication http console tacacs-servers LOCALaaa authorization command tacacs-servers LOCALaaa accounting ssh console tacacs-serversaaa accounting serial console tacacs-serversaaa accounting command tacacs-serversaaa accounting enable console tacacs-serversaaa authorization exec authentication-serverhttp server enablehttp 172.26.0.0 255.255.0.0 managementno snmp-server locationno snmp-server contactsnmp-server enable traps snmp authentication linkup linkdown coldstartcrypto ipsec security-association lifetime seconds 28800crypto ipsec security-association lifetime kilobytes 4608000telnet timeout 5ssh 172.26.0.0 255.255.0.0 managementssh timeout 5ssh version 1console timeout 0threat-detection basic-threatthreat-detection statistics access-listno threat-detection statistics tcp-interceptwccp 10 redirect-list proxylist group-list wsa-farm password ciscowccp interface inside 10 redirect inntp authentication-key 10 md5 *ntp authenticatentp trusted-key 10ntp server <NTP Server> source managementwebvpnusername admin password e1z89R3cZe9Kt6Ib encrypted privilege 15!class-map inspection_defaultmatch default-inspection-traffic!!policy-map type inspect dns migrated_dns_map_1parametersmessage-length maximum 512policy-map global_policyclass inspection_defaultinspect dns migrated_dns_map_1inspect ftpinspect h323 h225inspect h323 rasinspect rshinspect rtspinspect esmtpinspect sqlnetinspect skinnyinspect sunrpcinspect xdmcpinspect sipinspect netbiosinspect tftpinspect icmp!service-policy global_policy globalprompt hostname contextCryptochecksum:196fd610af2a2ae145f302e32cc50ab1: end[OK]cr26-asa5520-do#PSTN Edge
DO-ISR#term len 0DO-ISR#sh runBuilding configuration...Current configuration : 7860 bytes!! Last configuration change at 21:32:46 UTC Mon Aug 31 2009 by cisco! NVRAM config last updated at 21:15:27 UTC Mon Aug 31 2009 by cisco!version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname DO-ISR!boot-start-markerboot-end-marker!logging buffered 51200 warnings!no aaa new-modelnetwork-clock-participate wic 0network-clock-participate wic 1ip cef!!!!ip domain name ese.localip name-server 10.33.32.5!multilink bundle-name authenticated!isdn switch-type primary-4essvoice-card 0no dspfarm!!!!!!!!!!!!!!!!voice translation-rule 1rule 1 /^1/ /4445671/!voice translation-rule 2rule 2 /^2/ /2223452/!!voice translation-profile to-s1translate called 1!voice translation-profile to-s2translate called 2!!!crypto pki trustpoint TP-self-signed-1102421159enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-1102421159revocation-check nonersakeypair TP-self-signed-1102421159!!crypto pki certificate chain TP-self-signed-1102421159certificate self-signed 0130820248 308201B1 A0030201 02020101 300D0609 2A864886 F70D0101 0405003031312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 4365727469666963 6174652D 31313032 34323131 3539301E 170D3039 30343033 3233313333315A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 031326494F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 3130323432313135 3930819F 300D0609 2A864886 F70D0101 01050003 818D0030 818902818100B92E A977CB6E 985B7AD1 DAC05B57 8E8C35D7 9E6F16AB 84DE64A5 05B3B8154067A8A8 72B52E2E 16C0CFEC EE0E564B 1068DC76 F67EA152 7421ADC9 17300C81C34282C6 CC622DA1 F4551B71 8E1E0F62 86CB3995 4D265865 74776DE4 C9912ABBC2F527B4 17949311 7C8CA645 19EF813D 3B142D33 3305A1FA B7478C1A 6F29F416F1D10203 010001A3 70306E30 0F060355 1D130101 FF040530 030101FF 301B0603551D1104 14301282 10444F2D 4953522E 6573652E 6C6F6361 6C301F06 03551D2304183016 80140003 33E976A8 DCA4D4EA 6112E18F B0EB88A5 7373301D 0603551D0E041604 14000333 E976A8DC A4D4EA61 12E18FB0 EB88A573 73300D06 092A864886F70D01 01040500 03818100 8E4406BA 63A6B9A1 19A48B05 DED9791B 797018CFA6F177A1 46263C4D 2E6ACA82 2D26071F CA6BC27B 778D19F4 57604A4A C569BEE20AE94456 2EE01342 413C3832 B41F39F3 3F4BC20C 1C07F535 659EB32A 857DE24807DC2667 1ADB1090 81CAA2CD 1E423927 838C1106 6131D3DC 4F31DD88 60B6565F631965CB 3E3563E6 A9056FC0quit!!username cisco privilege 15 secret 5 $1$jjeA$UcUyfEOgP0shCRkl.LGWI.!!controller T1 0/0/0framing esflinecode b8zspri-group timeslots 1-24 service mgcp!controller T1 0/0/1framing esflinecode b8zs!controller T1 0/1/0framing esflinecode b8zs!controller T1 0/1/1framing esflinecode b8zs!!!!!!interface Port-channel3description port-channel to core stackip address 10.40.94.17 255.255.255.0hold-queue 150 in!interface GigabitEthernet0/0description $ETH-LAN$$ETH-SW-LAUNCH$$INTF-INFO-GE 0/0$no ip addressduplex autospeed automedia-type rj45no keepalivechannel-group 3!interface GigabitEthernet0/1no ip addressduplex autospeed automedia-type rj45no keepalivechannel-group 3!interface FastEthernet0/2/0!interface FastEthernet0/2/1!interface FastEthernet0/2/2!interface FastEthernet0/2/3!interface Serial0/0/0:23description to simulated PSTNno ip addressencapsulation hdlcisdn switch-type primary-niisdn incoming-voice voiceisdn bind-l3 ccm-managerno cdp enable!interface Integrated-Service-Engine1/0no ip addressshutdownno keepalive!interface Integrated-Service-Engine2/0no ip addressshutdownno keepalive!interface Vlan1no ip address!ip route 0.0.0.0 0.0.0.0 Port-channel3!!ip http serverip http access-class 23ip http authentication localip http secure-serverip http timeout-policy idle 60 life 86400 requests 10000!access-list 23 permit 10.10.10.0 0.0.0.7!!!!!!control-plane!!!voice-port 0/0/0:23!ccm-manager fallback-mgcpccm-manager mgcpccm-manager music-on-holdccm-manager config server 10.33.32.22ccm-manager config!mgcpmgcp call-agent CUCM7-Pub 2427 service-type mgcp version 0.1mgcp dtmf-relay voip codec all mode out-of-bandmgcp rtp unreachable timeout 1000 action notifymgcp modem passthrough voip mode nsemgcp package-capability rtp-packageno mgcp package-capability res-packagemgcp package-capability sst-packageno mgcp package-capability fxr-packagemgcp package-capability pre-packageno mgcp timer receive-rtcpmgcp sdp simplemgcp rtp payload-type g726r16 staticmgcp bind control source-interface Port-channel3mgcp bind media source-interface Port-channel3!mgcp profile default!!!dial-peer voice 1 potsservice mgcpappincoming called-number .direct-inward-dialport 0/0/0:23forward-digits 10!dial-peer voice 81222 potsdescription SRSTdestination-pattern 81222.......port 0/0/0:23forward-digits 10!dial-peer voice 81333 potsdescription SRSTdestination-pattern 81333.......port 0/0/0:23forward-digits 10!dial-peer voice 81444 potsdescription SRSTdestination-pattern 81444.......port 0/0/0:23forward-digits 10!dial-peer voice 81555 potsdescription SRSTdestination-pattern 81555.......port 0/0/0:23forward-digits 10!dial-peer voice 8456 potsdescription SRST site 1 local dialing (PSTN-router num-exp adds area code)destination-pattern 8456....port 0/0/0:23forward-digits 7!dial-peer voice 1000 potsdescription srst 4 digits to Site 1translation-profile outgoing to-s1destination-pattern 1...port 0/0/0:23forward-digits 10!dial-peer voice 2000 potsdescription srst 4 digits to Site 2translation-profile outgoing to-s2destination-pattern 2...port 0/0/0:23forward-digits 10!dial-peer voice 8911 potsdescription SRSTdestination-pattern 8911port 0/0/0:23forward-digits 4!dial-peer voice 911 potsdescription SRSTdestination-pattern 911port 0/0/0:23forward-digits 3!!!!call-manager-fallbackmax-conferences 12 gain -6transfer-system full-consultip source-address 10.40.63.9 port 2000max-ephones 10max-dn 20dialplan-pattern 1 33345630.. extension-length 4!banner login ^C-----------------------------------------------------------------------Cisco Router and Security Device Manager (SDM) is installed on this device.This feature requires the one-time use of the username "cisco"with the password "cisco". The default username and password have a privilege level of 15.Please change these publicly known initial credentials using SDM or the IOS CLI.Here are the Cisco IOS commands.username <myuser> privilege 15 secret 0 <mypassword>no username ciscoReplace <myuser> and <mypassword> with the username and password you want to use.For more information about SDM please follow the instructions in the QUICK STARTGUIDE for your router or go to http://www.cisco.com/go/sdm-----------------------------------------------------------------------^C!line con 0exec-timeout 0 0login localstopbits 1line aux 0stopbits 1line 66no activation-characterno exectransport preferred nonetransport input alltransport output lat pad telnet rlogin lapb-ta mop udptn v120 sshline 130no activation-characterno exectransport preferred nonetransport input alltransport output lat pad telnet rlogin lapb-ta mop udptn v120 sshline vty 0 4access-class 23 inprivilege level 15login localtransport input telnet sshline vty 5 15access-class 23 inprivilege level 15login localtransport input telnet ssh!scheduler allocate 20000 1000ntp authentication-key 2 md5 00361A03135407021B 7ntp authenticatentp trusted-key 2ntp clock-period 17180344ntp source Port-channel3ntp max-associations 150ntp server 10.33.32.16!endDO-ISR#School 1
Access
Cr35-2960-SS1!! Last configuration change at 13:16:40 EDT Thu Sep 3 2009 by cisco! NVRAM config last updated at 13:18:08 EDT Thu Sep 3 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr35-2960-SS1!boot-start-markerboot-end-marker!enable password 7 070C285F4D06!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringsystem mtu routing 1500vtp domain School-Site-1vtp mode transparentip subnet-zero!!ip dhcp snooping vlan 101-110no ip dhcp snooping information optionip dhcp snoopingno ip domain-lookupip arp inspection vlan 101-110ip arp inspection validate src-mac dst-mac ip allow zeros!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!crypto pki trustpoint HTTPS_SS_CERT_KEYPAIRenrollment selfsignedserial-numberrevocation-check nonersakeypair HTTPS_SS_CERT_KEYPAIR!!crypto pki certificate chain HTTPS_SS_CERT_KEYPAIRcertificate self-signed 01 nvram:F9154580host#2E2E.cer!!dot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120port-channel load-balance src-dst-ip!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 2name FlashNet_VLAN!vlan 101name cr2960_Dept1_VLAN!vlan 102name cr2960_Dept2_VLAN!vlan 103name cr2960_Dept3_VLAN!vlan 104name cr2960_Dept4_VLAN!vlan 105name cr2960_Dept5_VLAN!vlan 106name cr2960_Dept6_VLAN!vlan 107name cr2960_Dept7_VLAN!vlan 108name cr2960_Dept8_VLAN!vlan 109name cr2960_Dept9_VLAN!vlan 110name cr2960_Dept10_VLAN!vlan 201name Guest_VLAN!vlan 802name Hopping_VLAN!ip ftp username nimishguestip ftp password 7 04550F011A245F5A!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 1000000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 1000000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map Phone+PC-Policyclass VVLAN-VOIPpolice 1000000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 1000000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!interface Loopback0ip address 10.126.100.3 255.255.255.255no ip route-cache!interface Port-channel1description Connected to cr35-4507-SS1switchport trunk native vlan 802switchport trunk allowed vlan 101-110,201switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/1description CONNECTED TO UNTRUSTED PCswitchport access vlan 101switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input UnTrusted-PC-Policyip verify source!interface FastEthernet0/2description CONNECTED TO TRUSTED-PCswitchport access vlan 102switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Trusted-PC-Policyip verify source!interface FastEthernet0/3description CONNECTED TO PHONEswitchport mode accessswitchport block unicastswitchport voice vlan 103switchport port-security maximum 2switchport port-security maximum 1 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security violation restrictip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastservice-policy input Phone-Policyip verify source!interface FastEthernet0/4description CONNECTED TO PHONE+PCswitchport access vlan 104switchport mode accessswitchport block unicastswitchport voice vlan 105switchport port-security maximum 3switchport port-security maximum 2 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone+PC-Policyip verify source!interface FastEthernet0/5description CONNECTED TO IPVS 2500 - CAMERAswitchport access vlan 106switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/6description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 107switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/7description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 108switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/8!interface FastEthernet0/9!interface FastEthernet0/10description Connected to IXIA - ALM - 2/7switchport trunk native vlan 802switchport trunk allowed vlan 101-110switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/11description Connected to IXIA - STX - 4/3switchport trunk native vlan 802switchport trunk allowed vlan 101-110switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/12!interface FastEthernet0/13!interface FastEthernet0/14!interface FastEthernet0/15!interface FastEthernet0/16!interface FastEthernet0/17!interface FastEthernet0/18!interface FastEthernet0/19!interface FastEthernet0/20!interface FastEthernet0/21!interface FastEthernet0/22!interface FastEthernet0/23!interface FastEthernet0/24!interface FastEthernet0/25!interface FastEthernet0/26!interface FastEthernet0/27!interface FastEthernet0/28!interface FastEthernet0/29!interface FastEthernet0/30!interface FastEthernet0/31!interface FastEthernet0/32!interface FastEthernet0/33!interface FastEthernet0/34!interface FastEthernet0/35!interface FastEthernet0/36!interface FastEthernet0/37!interface FastEthernet0/38!interface FastEthernet0/39!interface FastEthernet0/40!interface FastEthernet0/41!interface FastEthernet0/42!interface FastEthernet0/43!interface FastEthernet0/44!interface FastEthernet0/45!interface FastEthernet0/46!interface FastEthernet0/47!interface FastEthernet0/48switchport access vlan 2switchport mode accessload-interval 30!interface GigabitEthernet0/1description Connected to cr35-4507-SS1switchport trunk native vlan 802switchport trunk allowed vlan 101-110,201switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet0/2description Connected to cr35-4507-SS1switchport trunk native vlan 802switchport trunk allowed vlan 101-110,201switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet0/3!interface GigabitEthernet0/4!interface Vlan1no ip addressno ip route-cacheshutdown!interface Vlan2description Connected to FlashNet - DO NOT ROUTEip address 172.26.160.192 255.255.254.0no ip redirectsno ip proxy-arpno ip route-cacheload-interval 30!ip default-gateway 172.26.160.1no ip http serverno ip http secure-server!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.31.4 auth-port 1645 acct-port 1646 key 7 0822455D0A1649464058radius-server deadtime 1!control-plane!alias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36029012ntp server 172.26.160.10endCr35-3560-SS1!! Last configuration change at 13:07:51 EDT Thu Sep 3 2009 by cisco! NVRAM config last updated at 13:07:54 EDT Thu Sep 3 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr35-3560-SS1!boot-start-markerboot-end-marker!enable password 7 094F471A1A0A!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringsystem mtu routing 1500vtp domain School-Site-1vtp mode transparentudld enableip subnet-zerono ip domain-lookup!!ip dhcp snooping vlan 111-120no ip dhcp snooping information optionip dhcp snoopingip multicast-routing distributedip arp inspection vlan 111-120ip arp inspection validate src-mac dst-mac ip allow zeros!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!key chain eigrp-keykey 1key-string 7 13061E010803!crypto pki trustpoint TP-self-signed-4313216enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-4313216revocation-check nonersakeypair TP-self-signed-4313216!!crypto pki certificate chain TP-self-signed-4313216certificate self-signed 01 nvram:IOS-Self-Sig#3636.cerdot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120port-channel load-balance src-dst-ip!!!spanning-tree mode rapid-pvstno spanning-tree optimize bpdu transmissionspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 111name cr35_3560_Dept1!vlan 112name cr35_3560_Dept2!vlan 113name cr35_3560_Dept3!vlan 114name cr35_3560_Dept4!vlan 115name cr35_3560_Dept5!vlan 116name cr35_3560_Dept6!vlan 117name cr35_3560_Dept7!vlan 118name cr35_3560_Dept8!vlan 119name cr35_3560_Dept9!vlan 120name cr35_3560_Dept_10!vlan 202name Guest_VLAN!vlan 803name Hopping_VLAN!ip ftp username nimishguestip ftp password 7 1419160C1901393F!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 32000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map Phone+PC-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!!interface Loopback0ip address 10.125.100.4 255.255.255.255!interface Port-channel1description Connected to cr35-4507-SS1switchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/1description CONNECTED TO UNTRUSTED PCswitchport access vlan 111switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input UnTrusted-PC-Policyip verify source!interface FastEthernet0/2description CONNECTED TO TRUSTED-PCswitchport access vlan 112switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Trusted-PC-Policyip verify source!interface FastEthernet0/3description CONNECTED TO PHONEswitchport mode accessswitchport block unicastswitchport voice vlan 113switchport port-security maximum 2switchport port-security maximum 1 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security violation restrictip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastservice-policy input Phone-Policyip verify source!interface FastEthernet0/4description CONNECTED TO PHONE+PCswitchport access vlan 113switchport mode accessswitchport block unicastswitchport voice vlan 114switchport port-security maximum 3switchport port-security maximum 2 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone+PC-Policyip verify source!interface FastEthernet0/5description CONNECTED TO IPVS 2500 - CAMERAswitchport access vlan 115switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/6description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 116switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/7description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 117switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno mdix autostorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/8no mdix auto!interface FastEthernet0/9no mdix auto!interface FastEthernet0/10description Connected to IXIA - ALM - 2/8switchport trunk encapsulation dot1qswitchport trunk native vlan 202switchport trunk allowed vlan 111-120switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno mdix autono cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/11description Connected to IXIA - STX - 4/4switchport trunk encapsulation dot1qswitchport trunk native vlan 202switchport trunk allowed vlan 111-120switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno mdix autono cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/12no mdix auto!interface FastEthernet0/13no mdix auto!interface FastEthernet0/14no mdix auto!interface FastEthernet0/15no mdix auto!interface FastEthernet0/16no mdix auto!interface FastEthernet0/17no mdix auto!interface FastEthernet0/18no mdix auto!interface FastEthernet0/19no mdix auto!interface FastEthernet0/20no mdix auto!interface FastEthernet0/21no mdix auto!interface FastEthernet0/22no mdix auto!interface FastEthernet0/23no mdix auto!interface FastEthernet0/24no mdix auto!interface FastEthernet0/25no mdix auto!interface FastEthernet0/26no mdix auto!interface FastEthernet0/27no mdix auto!interface FastEthernet0/28no mdix auto!interface FastEthernet0/29no mdix auto!interface FastEthernet0/30no mdix auto!interface FastEthernet0/31no mdix auto!interface FastEthernet0/32no mdix auto!interface FastEthernet0/33no mdix auto!interface FastEthernet0/34no mdix auto!interface FastEthernet0/35no mdix auto!interface FastEthernet0/36no mdix auto!interface FastEthernet0/37no mdix auto!interface FastEthernet0/38no mdix auto!interface FastEthernet0/39no mdix auto!interface FastEthernet0/40no mdix auto!interface FastEthernet0/41no mdix auto!interface FastEthernet0/42no mdix auto!interface FastEthernet0/43no mdix auto!interface FastEthernet0/44no mdix auto!interface FastEthernet0/45no mdix auto!interface FastEthernet0/46no mdix auto!interface FastEthernet0/47no mdix auto!interface FastEthernet0/48description Connected to FlashNetno switchportip address 172.26.160.193 255.255.254.0no ip redirectsno ip proxy-arpno ip route-cacheno mdix auto!interface GigabitEthernet0/1description Connected to cr35-4507-SS1switchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet0/2description Connected to cr35-4507-SS1switchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet0/3!interface GigabitEthernet0/4!interface Vlan1no ip addressno ip route-cacheshutdown!ip classlessno ip http serverno ip http secure-serverip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630!!!snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.31.4 auth-port 1645 acct-port 1646 key 7 0822455D0A1649464058radius-server deadtime 1!control-plane!alias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36029222ntp server 172.26.160.10endCr35-3750-SS1!! Last configuration change at 13:07:51 EDT Thu Sep 3 2009 by cisco! NVRAM config last updated at 13:07:53 EDT Thu Sep 3 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr35-3750-SS1!boot-start-markerboot-end-marker!logging buffered 16000no logging consoleenable secret 5 $1$vE3p$UNuh7kbqn0zV3HU1uc/cG0enable password 7 13061E010803!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringswitch 1 provision ws-c3750g-12ssystem mtu routing 1500vtp domain School-Site-1vtp mode transparentip subnet-zerono ip domain-lookup!!ip dhcp snooping vlan 121-130,203no ip dhcp snooping information optionip dhcp snoopingip multicast-routing distributedip arp inspection vlan 121-130,203ip arp inspection validate src-mac dst-mac ip allow zeros!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!crypto pki trustpoint TP-self-signed-721634816enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-721634816revocation-check nonersakeypair TP-self-signed-721634816!!crypto pki certificate chain TP-self-signed-721634816certificate self-signed 01 nvram:IOS-Self-Sig#3636.cerdot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120port-channel load-balance src-dst-ip!!!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 121name cr36_3750_Dept1!vlan 122name cr36_3750_Dept2!vlan 123name cr36_3750_Dept3!vlan 124name cr36_3750_Dept4!vlan 125name cr36_3750_Dept5!vlan 126name cr36_3750_Dept6!vlan 127name cr36_3750_Dept7!vlan 128name cr36_3750_Dept8!vlan 129name cr36_3750_Dept9!vlan 130name cr36_3750_Dept10!vlan 203name Guest_VLAN!vlan 804name Hopping_VLAN!ip ftp username nimishguestip ftp password 7 151C0F0B112F3830!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 32000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map Phone+PC-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!!interface Loopback0ip address 10.126.100.5 255.255.255.255!interface Port-channel1description Connected to cr35-4507-SS1switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/1description CONNECTED TO UNTRUSTED PCswitchport access vlan 121switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input UnTrusted-PC-Policyip verify source!interface GigabitEthernet1/0/2description CONNECTED TO TRUSTED-PCswitchport access vlan 122switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Trusted-PC-Policyip verify source!interface GigabitEthernet1/0/3description CONNECTED TO PHONEswitchport mode accessswitchport block unicastswitchport voice vlan 123switchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security violation restrictip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastservice-policy input Phone-Policyip verify source!interface GigabitEthernet1/0/4description CONNECTED TO PHONE+PCswitchport access vlan 124switchport mode accessswitchport block unicastswitchport voice vlan 125switchport port-security maximum 3switchport port-security maximum 2 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone+PC-Policyip verify source!interface GigabitEthernet1/0/5description CONNECTED TO IPVS 2500 - CAMERAswitchport access vlan 126switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet1/0/6description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 127switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet1/0/7description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 128switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet1/0/8description Connected to FlashNetno switchportip address 172.26.160.194 255.255.254.0no ip redirectsno ip proxy-arp!interface GigabitEthernet1/0/9description Connected to cr35-4507-SS1switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130switchport mode trunkip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/10description Connected to IXIA - ALM - 5/1switchport trunk encapsulation dot1qswitchport trunk native vlan 204switchport trunk allowed vlan 121-130switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno mdix autono cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/11description Connected to IXIA - STX - 6/1switchport trunk encapsulation dot1qswitchport trunk native vlan 204switchport trunk allowed vlan 121-130switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno mdix autono cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/12description Connected to cr35-4507-SS1switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130switchport mode trunkip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol pagpchannel-group 1 mode desirablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface Vlan1ip address dhcpshutdown!ip classlessip route 172.26.158.0 255.255.255.0 172.26.160.1no ip http serverno ip http secure-serverip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630!!snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.31.4 auth-port 1645 acct-port 1646 key 7 1511021F072567757A60radius-server deadtime 1!control-plane!alias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36029518ntp server 172.26.160.10endCr35-3750r-SS1!! Last configuration change at 13:07:51 EDT Thu Sep 3 2009 by cisco! NVRAM config last updated at 13:07:55 EDT Thu Sep 3 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr35-3750r-SS1!boot-start-markerboot-end-marker!enable password 7 0822455D0A16!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringswitch 1 provision ws-c3750-48pswitch 2 provision ws-c3750g-48psstack-mac persistent timer 0system mtu routing 1500vtp domain School-Site-1vtp mode transparentip subnet-zeroip routingno ip domain-lookup!!ip dhcp snooping vlan 11-20no ip dhcp snooping information optionip dhcp snoopingip multicast-routing distributedip arp inspection vlan 11-20ip arp inspection validate src-mac dst-mac ip allow zeros!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!key chain eigrp-keykey 1key-string 7 104D000A0618!crypto pki trustpoint TP-self-signed-1654402816enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-1654402816revocation-check nonersakeypair TP-self-signed-1654402816!!crypto pki certificate chain TP-self-signed-1654402816certificate self-signed 01 nvram:IOS-Self-Sig#3636.cerdot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120port-channel load-balance src-dst-ip!!!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 2name FlashNet_VLAN!vlan 11,13-20!vlan 204name Guest_VLAN!ip ftp username nimishguestip ftp password 7 000A1701115E1812!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 32000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map Phone+PC-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!!interface Loopback0ip address 10.126.100.6 255.255.255.255!interface Port-channel1description Connected to cr35-4507-SS1no switchportdampeningip address 10.127.7.194 255.255.255.192ip pim sparse-modeip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 out!interface FastEthernet1/0/1description CONNECTED TO UNTRUSTED PCswitchport access vlan 11switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input UnTrusted-PC-Policyip verify source!interface FastEthernet1/0/2description CONNECTED TO TRUSTED-PCswitchport access vlan 12switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Trusted-PC-Policyip verify source!interface FastEthernet1/0/3description CONNECTED TO PHONEswitchport access vlan 14switchport mode accessswitchport block unicastswitchport voice vlan 13switchport port-security maximum 3switchport port-security maximum 1 vlanswitchport port-security maximum 2 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone-Policyip verify source!interface FastEthernet1/0/4!interface FastEthernet1/0/5!interface FastEthernet1/0/6!interface FastEthernet1/0/7!interface FastEthernet1/0/8!interface FastEthernet1/0/9!interface FastEthernet1/0/10!interface FastEthernet1/0/11!interface FastEthernet1/0/12!interface FastEthernet1/0/13!interface FastEthernet1/0/14!interface FastEthernet1/0/15!interface FastEthernet1/0/16!interface FastEthernet1/0/17!interface FastEthernet1/0/18!interface FastEthernet1/0/19!interface FastEthernet1/0/20!interface FastEthernet1/0/21!interface FastEthernet1/0/22!interface FastEthernet1/0/23!interface FastEthernet1/0/24!interface FastEthernet1/0/25!interface FastEthernet1/0/26!interface FastEthernet1/0/27!interface FastEthernet1/0/28!interface FastEthernet1/0/29!interface FastEthernet1/0/30!interface FastEthernet1/0/31!interface FastEthernet1/0/32!interface FastEthernet1/0/33!interface FastEthernet1/0/34!interface FastEthernet1/0/35!interface FastEthernet1/0/36!interface FastEthernet1/0/37!interface FastEthernet1/0/38!interface FastEthernet1/0/39!interface FastEthernet1/0/40!interface FastEthernet1/0/41!interface FastEthernet1/0/42!interface FastEthernet1/0/43!interface FastEthernet1/0/44!interface FastEthernet1/0/45!interface FastEthernet1/0/46!interface FastEthernet1/0/47!interface FastEthernet1/0/48description FlashNet - DO NOT ROUTEswitchport access vlan 2load-interval 30!interface GigabitEthernet1/0/1description Connected to cr35-4507-SS1no switchportno ip addresslogging event bundle-statusload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode active!interface GigabitEthernet1/0/2!interface GigabitEthernet1/0/3!interface GigabitEthernet1/0/4!interface GigabitEthernet2/0/1description CONNECTED TO IPVS 2500 - CAMERAswitchport access vlan 16switchport mode accessswitchport block unicastswitchport voice vlan 15switchport port-security maximum 3switchport port-security maximum 2 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone+PC-Policyip verify source!interface GigabitEthernet2/0/2description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 17switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet2/0/3description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 18switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet2/0/4!interface GigabitEthernet2/0/5!interface GigabitEthernet2/0/6!interface GigabitEthernet2/0/7!interface GigabitEthernet2/0/8!interface GigabitEthernet2/0/9!interface GigabitEthernet2/0/10description Connected to IXIA - ALM - 5/2switchport trunk encapsulation dot1qswitchport trunk allowed vlan 11-20switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablespanning-tree bpduguard enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet2/0/11description Connected to IXIA - STX - 6/2switchport trunk encapsulation dot1qswitchport trunk allowed vlan 11-20switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablespanning-tree bpduguard enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet2/0/12!interface GigabitEthernet2/0/13!interface GigabitEthernet2/0/14!interface GigabitEthernet2/0/15!interface GigabitEthernet2/0/16!interface GigabitEthernet2/0/17!interface GigabitEthernet2/0/18!interface GigabitEthernet2/0/19!interface GigabitEthernet2/0/20!interface GigabitEthernet2/0/21!interface GigabitEthernet2/0/22!interface GigabitEthernet2/0/23!interface GigabitEthernet2/0/24!interface GigabitEthernet2/0/25!interface GigabitEthernet2/0/26!interface GigabitEthernet2/0/27!interface GigabitEthernet2/0/28!interface GigabitEthernet2/0/29!interface GigabitEthernet2/0/30!interface GigabitEthernet2/0/31!interface GigabitEthernet2/0/32!interface GigabitEthernet2/0/33!interface GigabitEthernet2/0/34!interface GigabitEthernet2/0/35!interface GigabitEthernet2/0/36!interface GigabitEthernet2/0/37!interface GigabitEthernet2/0/38!interface GigabitEthernet2/0/39!interface GigabitEthernet2/0/40!interface GigabitEthernet2/0/41!interface GigabitEthernet2/0/42!interface GigabitEthernet2/0/43!interface GigabitEthernet2/0/44!interface GigabitEthernet2/0/45!interface GigabitEthernet2/0/46!interface GigabitEthernet2/0/47!interface GigabitEthernet2/0/48!interface GigabitEthernet2/0/49description Connected to cr35-4507-SS1no switchportno ip addresslogging event bundle-statusload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode active!interface GigabitEthernet2/0/50!interface GigabitEthernet2/0/51!interface GigabitEthernet2/0/52!interface Vlan1ip address dhcpshutdown!interface Vlan2description FlashNet - DO NOT ROUTEip address 172.26.160.222 255.255.252.0no ip redirectsno ip proxy-arp!interface Vlan11ip address 10.127.7.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!!router eigrp 100passive-interface defaultno passive-interface Port-channel1no auto-summaryeigrp router-id 10.126.100.6eigrp stub connectednetwork 10.126.0.0 0.1.255.255nsf!ip classlessip route 172.26.158.0 255.255.255.0 172.26.160.1no ip http serverno ip http secure-serverip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630!!snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.31.4 auth-port 1645 acct-port 1646 key 7 121A0C04110440557878radius-server deadtime 1!control-plane!alias exec dsno show ip dhcp snooping bindalias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36028695ntp server 172.26.160.10endCore/Distribution/WAN Edge
Cr35-4507-SS1!! Last configuration change at 13:15:17 EDT Thu Sep 3 2009 by cisco! NVRAM config last updated at 13:15:32 EDT Thu Sep 3 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryptionservice compress-config!hostname cr35-4507-SS1!boot-start-markerboot system flash bootflash:cat4500-entservicesk9-mz.122-50.SGboot-end-marker!enable password 7 110A1016141D!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringqosqos dbl exceed-action ecnqos dbl dscp-based 0-31,33-39,41-45,47-63qos map dscp 0 to tx-queue 2qos map dscp 16 18 20 22 24 26 28 30 to tx-queue 4qos map dscp 34 36 38 to tx-queue 4udld enableip subnet-zerono ip domain-lookup!ip vrf mgmtVrf!ip multicast-routingvtp domain School-Site-1vtp mode transparentcluster run!!key chain eigrp-keykey 1key-string 7 045802150C2E!!dot1x system-auth-controldot1x guest-vlan supplicanterrdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120power redundancy-mode combined!!!!!macro global description system-cpp | system-cpp!spanning-tree mode rapid-pvstspanning-tree extend system-idspanning-tree vlan 1-4094 priority 24576!redundancymode ssomain-cpuauto-sync standard!process-max-time 20vlan internal allocation policy ascending!vlan 101name cr35_2960_Dept1!vlan 102name cr35_2960_Dept2!vlan 103name cr35_2960_Dept3!vlan 104name cr35_2960_Dept4!vlan 105name cr35_2960_Dept5!vlan 106name cr35_2960_Dept6!vlan 107name cr35_2960_Dept7!vlan 108name cr35_2960_Dept8!vlan 109name cr35_2960_Dept9!vlan 110name cr35_2960_Dept10!vlan 111name cr35_3560_Dept11!vlan 112name cr35_3560_Dept12!vlan 113name cr35_3560_Dept13!vlan 114name cr35_3560_Dept14!vlan 115name cr35_3560_Dept15!vlan 116name cr35_3560_Dept16!vlan 117name cr35_3560_Dept17!vlan 118name cr35_3560_Dept18!vlan 119name cr35_3560_Dept19!vlan 120name cr35_3560_Dept20!vlan 121name cr35_3750_Dept21!vlan 122name cr35_3750_Dept22!vlan 123name cr35_3750_Dept23!vlan 124name cr35_3750_Dept24!vlan 125name cr35_3750_Dept25!vlan 126name cr35_3750_Dept26!vlan 127name cr35_3750_Dept27!vlan 128name cr35_3750_Dept28!vlan 129name cr35_3750_Dept29!vlan 130name cr35_3750_Dept30!vlan 501name cr24_3750ME_DO!vlan 801name MetroE_Hopping_VLAN!vlan 802name cr36_2960-Hopping-VL!vlan 803name cr36_3560-Hopping-VL!vlan 804name cr36_3750-Hopping-VL!ip ftp username nimishguestip ftp password 7 000A1701115E1812!class-map match-all COPP-CRITICAL-APPLICATIONSmatch access-group name COPP-CRITICAL-APPLICATIONSclass-map match-all system-cpp-cdpmatch access-group name system-cpp-cdpclass-map match-all system-cpp-pimmatch access-group name system-cpp-pimclass-map match-all COPP-FILE-MANAGEMENTmatch access-group name COPP-FILE-MANAGEMENTclass-map match-all system-cpp-pppoe-discmatch access-group name system-cpp-pppoe-discclass-map match-all COPP-MONITORINGmatch access-group name COPP-MONITORINGclass-map match-all system-cpp-bpdu-rangematch access-group name system-cpp-bpdu-rangeclass-map match-all system-cpp-dhcp-csmatch access-group name system-cpp-dhcp-csclass-map match-all system-cpp-dhcp-scmatch access-group name system-cpp-dhcp-scclass-map match-all system-cpp-all-systems-on-subnetmatch access-group name system-cpp-all-systems-on-subnetclass-map match-all system-cpp-all-routers-on-subnetmatch access-group name system-cpp-all-routers-on-subnetclass-map match-all system-cpp-ripv2match access-group name system-cpp-ripv2class-map match-all system-cpp-mcast-cfmmatch access-group name system-cpp-mcast-cfmclass-map match-all system-cpp-dot1xmatch access-group name system-cpp-dot1xclass-map match-all system-cpp-ucast-cfmmatch access-group name system-cpp-ucast-cfmclass-map match-all system-cpp-dhcp-ssmatch access-group name system-cpp-dhcp-ssclass-map match-all COPP-INTERACTIVE-MANAGEMENTmatch access-group name COPP-INTERACTIVE-MANAGEMENTclass-map match-all system-cpp-sstpmatch access-group name system-cpp-sstpclass-map match-all system-cpp-ospfmatch access-group name system-cpp-ospfclass-map match-all NON-REALTIMEmatch not ip dscp efmatch not ip dscp cs5match not ip dscp cs4class-map match-all system-cpp-lldpmatch access-group name system-cpp-lldpclass-map match-all system-cpp-igmpmatch access-group name system-cpp-igmpclass-map match-all COPP-UNDESIRABLEmatch access-group name COPP-UNDESIRABLEclass-map match-all system-cpp-ip-mcast-linklocalmatch access-group name system-cpp-ip-mcast-linklocalclass-map match-all COPP-IGPmatch access-group name COPP-IGPclass-map match-all system-cpp-cgmpmatch access-group name system-cpp-cgmp!!policy-map WAN-EGRESS-CHILDclass NON-REALTIMEpolice 13200 kbps 1000 byte conform-action transmit exceed-action droppolicy-map DBLclass class-defaultdblpolicy-map WAN-EGRESS-PARENTclass class-defaultpolice 20 mbps 1000 byte conform-action transmit exceed-action dropdblservice-policy WAN-EGRESS-CHILDpolicy-map system-cpp-policyclass system-cpp-dot1xclass system-cpp-lldpclass system-cpp-bpdu-rangeclass system-cpp-cdpclass system-cpp-sstpclass system-cpp-cgmpclass system-cpp-mcast-cfmclass system-cpp-ucast-cfmclass system-cpp-pppoe-discclass system-cpp-ospfclass system-cpp-igmpclass system-cpp-pimclass system-cpp-all-systems-on-subnetclass system-cpp-all-routers-on-subnetclass system-cpp-ripv2class system-cpp-ip-mcast-linklocalclass system-cpp-dhcp-csclass system-cpp-dhcp-scclass system-cpp-dhcp-ssclass COPP-IGPpolice 300000 bps 3000 byte conform-action transmit exceed-action dropclass COPP-INTERACTIVE-MANAGEMENTpolice 500000 bps 5000 byte conform-action transmit exceed-action dropclass COPP-FILE-MANAGEMENTpolice 6000000 bps 60000 byte conform-action transmit exceed-action dropclass COPP-MONITORINGpolice 900000 bps 9000 byte conform-action transmit exceed-action dropclass COPP-CRITICAL-APPLICATIONSpolice 900000 bps 9000 byte conform-action transmit exceed-action dropclass COPP-UNDESIRABLEpolice 32000 bps 3000 byte conform-action drop exceed-action dropclass class-defaultpolice 500000 bps 5000 byte conform-action transmit exceed-action drop!!!interface Loopback0ip address 10.126.100.2 255.255.255.255!interface Port-channel11description Connected to cr35-2960-SS1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 802switchport trunk allowed vlan 101-110switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0qos trust dscp!interface Port-channel12description Connected to cr35-3560-SS1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0qos trust dscp!interface Port-channel13description Connected to cr35-3750-SS1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0qos trust dscp!interface Port-channel14description Connected to cr35-3750r-SS1dampeningip address 10.127.7.193 255.255.255.192ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.127.0.0 255.255.248.0 5load-interval 30carrier-delay msec 0qos trust dscp!interface FastEthernet1ip vrf forwarding mgmtVrfno ip addressspeed autoduplex auto!interface GigabitEthernet1/1description Connected to MetroE-Core-cr25-6500-1switchport trunk encapsulation dot1qswitchport trunk native vlan 801switchport trunk allowed vlan 501switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0qos trust dscpudld port disabletx-queue 1bandwidth 1 mbpstx-queue 2bandwidth 7 mbpstx-queue 3bandwidth 6 mbpspriority hightx-queue 4bandwidth 6 mbpsno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablespanning-tree guard rootservice-policy output WAN-EGRESS-PARENT!interface GigabitEthernet1/2description Connected to cr35_2960_SS1switchport trunk encapsulation dot1qswitchport trunk native vlan 802switchport trunk allowed vlan 101-110switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0qos trust dscptx-queue 1bandwidth percent 5tx-queue 2bandwidth percent 35tx-queue 3bandwidth percent 30priority hightx-queue 4bandwidth percent 30channel-protocol pagpchannel-group 11 mode desirablespanning-tree guard rootservice-policy output DBL!interface GigabitEthernet1/3description Connected to cr35_3560_SS1switchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0qos trust dscptx-queue 1bandwidth percent 5tx-queue 2bandwidth percent 35tx-queue 3bandwidth percent 30priority hightx-queue 4bandwidth percent 30channel-protocol pagpchannel-group 12 mode desirablespanning-tree guard rootservice-policy output DBL!interface GigabitEthernet1/4description Connected to cr35-3750-SS1switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0qos trust dscptx-queue 1bandwidth percent 5tx-queue 2bandwidth percent 35tx-queue 3bandwidth percent 30priority hightx-queue 4bandwidth percent 30channel-protocol pagpchannel-group 13 mode desirablespanning-tree guard rootservice-policy output DBL!interface GigabitEthernet1/5description Connected to cr35-3750r-SS1no switchportdampeningno ip addresslogging event link-statusload-interval 30carrier-delay msec 0qos trust dscptx-queue 1bandwidth percent 5tx-queue 2bandwidth percent 35tx-queue 3bandwidth percent 30priority hightx-queue 4bandwidth percent 30channel-protocol lacpchannel-group 14 mode activespanning-tree guard rootservice-policy output DBL!interface GigabitEthernet1/6switchport trunk encapsulation dot1qswitchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0qos trust dscptx-queue 1bandwidth percent 5tx-queue 2bandwidth percent 35tx-queue 3bandwidth percent 30priority hightx-queue 4bandwidth percent 30spanning-tree guard rootservice-policy output DBL!interface GigabitEthernet2/1switchport trunk encapsulation dot1qswitchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0qos trust dscptx-queue 1bandwidth percent 5tx-queue 2bandwidth percent 35tx-queue 3bandwidth percent 30priority hightx-queue 4bandwidth percent 30spanning-tree guard root!interface GigabitEthernet2/2description Connected to cr35_2960_SS1switchport trunk encapsulation dot1qswitchport trunk native vlan 802switchport trunk allowed vlan 101-110switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0qos trust dscptx-queue 1bandwidth percent 5tx-queue 2bandwidth percent 35tx-queue 3bandwidth percent 30priority hightx-queue 4bandwidth percent 30channel-protocol pagpchannel-group 11 mode desirablespanning-tree guard rootservice-policy output DBL!interface GigabitEthernet2/3description Connected to cr35_3560_SS1switchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0qos trust dscptx-queue 1bandwidth percent 5tx-queue 2bandwidth percent 35tx-queue 3bandwidth percent 30priority hightx-queue 4bandwidth percent 30channel-protocol pagpchannel-group 12 mode desirablespanning-tree guard rootservice-policy output DBL!interface GigabitEthernet2/4description Connected to cr35-3750-SS1switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130switchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0qos trust dscptx-queue 1bandwidth percent 5tx-queue 2bandwidth percent 35tx-queue 3bandwidth percent 30priority hightx-queue 4bandwidth percent 30channel-protocol pagpchannel-group 13 mode desirablespanning-tree guard rootservice-policy output DBL!interface GigabitEthernet2/5description Connected to cr35-3750r-SS1no switchportdampeningno ip addresslogging event link-statusload-interval 30carrier-delay msec 0qos trust dscptx-queue 1bandwidth percent 5tx-queue 2bandwidth percent 35tx-queue 3bandwidth percent 30priority hightx-queue 4bandwidth percent 30channel-protocol lacpchannel-group 14 mode activespanning-tree guard rootservice-policy output DBL!interface GigabitEthernet2/6switchport trunk encapsulation dot1qswitchport mode trunklogging event link-statusload-interval 30carrier-delay msec 0shutdownqos trust dscptx-queue 1bandwidth percent 5tx-queue 2bandwidth percent 35tx-queue 3bandwidth percent 30priority hightx-queue 4bandwidth percent 30spanning-tree guard rootservice-policy output DBL!interface TenGigabitEthernet3/1!interface TenGigabitEthernet3/2!interface GigabitEthernet3/3!interface GigabitEthernet3/4!interface GigabitEthernet3/5!interface GigabitEthernet3/6!interface TenGigabitEthernet4/1!interface TenGigabitEthernet4/2!interface GigabitEthernet4/3!interface GigabitEthernet4/4!interface GigabitEthernet4/5!interface GigabitEthernet4/6!interface GigabitEthernet6/1description Connected to FlashNetno switchportip address 172.26.160.191 255.255.254.0no ip redirectsno ip proxy-arpload-interval 30!interface GigabitEthernet6/2switchport trunk encapsulation dot1qswitchport trunk allowed vlan 101switchport mode trunk!interface GigabitEthernet6/3!interface GigabitEthernet6/4!interface GigabitEthernet6/5!interface GigabitEthernet6/6!interface GigabitEthernet6/7!interface GigabitEthernet6/8!interface GigabitEthernet6/9!interface GigabitEthernet6/10!interface GigabitEthernet6/11!interface GigabitEthernet6/12!interface GigabitEthernet6/13!interface GigabitEthernet6/14!interface GigabitEthernet6/15!interface GigabitEthernet6/16!interface GigabitEthernet6/17!interface GigabitEthernet6/18!interface GigabitEthernet6/19!interface GigabitEthernet6/20!interface GigabitEthernet6/21!interface GigabitEthernet6/22!interface GigabitEthernet6/23!interface GigabitEthernet6/24!interface GigabitEthernet6/25!interface GigabitEthernet6/26!interface GigabitEthernet6/27!interface GigabitEthernet6/28!interface GigabitEthernet6/29!interface GigabitEthernet6/30!interface GigabitEthernet6/31!interface GigabitEthernet6/32!interface GigabitEthernet6/33!interface GigabitEthernet6/34!interface GigabitEthernet6/35!interface GigabitEthernet6/36!interface GigabitEthernet6/37!interface GigabitEthernet6/38!interface GigabitEthernet6/39!interface GigabitEthernet6/40!interface GigabitEthernet6/41!interface GigabitEthernet6/42!interface GigabitEthernet6/43!interface GigabitEthernet6/44!interface GigabitEthernet6/45!interface GigabitEthernet6/46!interface GigabitEthernet6/47!interface GigabitEthernet6/48!interface Vlan1no ip addressshutdown!interface Vlan101description Connected to cr35_2960_Dept_1_VLANdampeningip address 10.127.0.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan102description Connected to cr35_2960_Dept_2_VLANdampeningip address 10.127.0.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan103description Connected to cr35_2960_Dept_3_VLANdampeningip address 10.127.0.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan104description Connected to cr35_2960_Dept_4_VLANdampeningip address 10.127.0.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan105description Connected to cr35_2960_Dept_5_VLANdampeningip address 10.127.1.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan106description Connected to cr35_2960_Dept_6_VLANdampeningip address 10.127.1.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan107description Connected to cr35_2960_Dept_7_VLANdampeningip address 10.127.1.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan108description Connected to cr35_2960_Dept_8_VLANdampeningip address 10.127.1.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan109description Connected to cr35_2960_Dept_9_VLANdampeningip address 10.127.2.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan110description Connected to cr35_2960_Dept_10_VLANdampeningip address 10.127.2.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan111description Connected to cr35_3560_Dept_1_VLANdampeningip address 10.127.2.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan112description Connected to cr35_3560_Dept_2_VLANdampeningip address 10.127.2.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan113description Connected to cr35_3560_Dept_3_VLANdampeningip address 10.127.3.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan114description Connected to cr35_3560_Dept_4_VLANdampeningip address 10.127.3.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan115description Connected to cr35_3560_Dept_5_VLANdampeningip address 10.127.3.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan116description Connected to cr35_3560_Dept_6_VLANdampeningip address 10.127.3.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan117description Connected to cr35_3560_Dept_7_VLANdampeningip address 10.127.4.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan118description Connected to cr35_3560_Dept_8_VLANdampeningip address 10.127.4.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan119description Connected to cr35_3560_Dept_9_VLANdampeningip address 10.127.4.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan120description Connected to cr35_3560_Dept_10_VLANdampeningip address 10.127.4.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan121description Connected to cr35_3750_Dept_1_VLANdampeningip address 10.127.5.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan122description Connected to cr35_3750_Dept_2_VLANdampeningip address 10.127.5.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan123description Connected to cr35_3750_Dept_3_VLANdampeningip address 10.127.5.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan124description Connected to cr35_3750_Dept_4_VLANdampeningip address 10.127.5.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan125description Connected to cr35_3750_Dept_5_VLANdampeningip address 10.127.6.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan126description Connected to cr35_3750_Dept_6_VLANdampeningip address 10.127.6.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan127description Connected to cr35_3750_Dept_7_VLANdampeningip address 10.127.6.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan128description Connected to cr35_3750_Dept_8_VLANdampeningip address 10.127.6.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan129description Connected to cr35_3750_Dept_9_VLANdampeningip address 10.127.7.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan130description Connected to cr35_3750_Dept_10_VLANdampeningip address 10.127.7.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan501description Connected to cr24-3750ME-DOdampeningip address 10.126.0.1 255.255.255.254no ip redirectsno ip unreachablesip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip pim sparse-modeip summary-address eigrp 100 10.127.0.0 255.255.248.0 5load-interval 30!!router eigrp 100passive-interface defaultno passive-interface Vlan501no passive-interface Port-channel14distribute-list route-map EIGRP_STUB_ROUTES out Port-channel14no auto-summaryeigrp router-id 10.126.100.2network 10.126.0.0 0.1.255.255nsf!ip route 172.26.158.0 255.255.255.0 172.26.160.1no ip http serverno ip http secure-server!!ip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255!ip access-list extended COPP-CRITICAL-APPLICATIONSremark DHCPpermit udp host 0.0.0.0 host 255.255.255.255 eq bootpspermit udp host 10.125.31.2 eq bootps any eq bootpsip access-list extended COPP-FILE-MANAGEMENTremark (initiated) FTP (active and passive)permit tcp 172.26.160.0 0.0.3.255 eq ftp host 172.26.160.191 gt 1023 establishedpermit tcp 172.26.160.0 0.0.3.255 eq ftp-data host 172.26.160.191 gt 1023permit tcp 172.26.160.0 0.0.3.255 gt 1023 host 172.26.160.191 gt 1023 establishedremark (initiated) TFTPpermit udp 172.26.160.0 0.0.3.255 gt 1023 host 172.26.160.191 gt 1023ip access-list extended COPP-IGPremark IGP (EIGRP)permit eigrp any host 224.0.0.10permit eigrp any anyip access-list extended COPP-INTERACTIVE-MANAGEMENTremark RADIUS (return traffic)permit udp host 10.125.31.4 host 10.126.100.2remark SSHpermit tcp 10.124.0.0 0.3.255.255 host 10.126.100.2 eq 22remark SNMPpermit udp host 172.26.160.100 host 10.126.100.2 eq snmpremark NTPpermit udp host 172.26.160.10 host 172.26.160.191 eq ntpip access-list extended COPP-MONITORINGremark PING-ECHOpermit icmp any any echoremark PING-ECHO-REPLYpermit icmp any any echo-replyremark TRACEROUTEpermit icmp any any ttl-exceededpermit icmp any any port-unreachableip access-list extended COPP-UNDESIRABLEremark UNDESIRABLEpermit udp any any eq 1434ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255!access-list 1 permit 0.0.0.0access-list 1 permit 10.127.0.0access-list 1 permit 10.124.0.0!route-map EIGRP_STUB_ROUTES permit 10match ip address 1!!snmp-server engineID local 800000090300001D45735179snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.31.4 auth-port 1645 acct-port 1646 key 7 104D000A06185E5A5E57radius-server deadtime 1!control-planeservice-policy input system-cpp-policy!alias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104stopbits 1line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 17180908ntp server 172.26.160.10endPSTN Edge
School2-B1L#term len 0School2-B1L#wriBuilding configuration...[OK]School2-B1L#sh runBuilding configuration...Current configuration : 9069 bytes!! Last configuration change at 16:54:51 UTC Tue Sep 8 2009! NVRAM config last updated at 16:55:16 UTC Tue Sep 8 2009!version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname School2-B1L!boot-start-markerboot system flash:c3825-advipservicesk9-mz.124-15.T1.binboot-end-marker!card type t1 2 0logging buffered 4096!no aaa new-model!monitor session 1 destination interface Fa1/15no network-clock-participate slot 2no network-clock-participate wic 0no ip dhcp use vrf connectedip dhcp excluded-address 10.41.51.0 10.41.51.49ip dhcp excluded-address 10.41.51.100 10.41.51.255!ip dhcp pool SRSTnetwork 10.41.51.0 255.255.255.0option 150 ip 10.33.32.20default-router 10.41.51.1!!ip cef!!ip domain name ese.localip name-server 10.33.32.5!multilink bundle-name authenticated!isdn switch-type primary-nivoice-card 0no dspfarm!voice-card 2no dspfarm!!!key chain eigrp-chainkey 100key-string cisco!!!!!!!!!!!!!!voice translation-rule 1rule 1 /^222345/ /8222/!voice translation-rule 10rule 1 /^84441/ /4445671/rule 2 /^83331/ /3334561/!!voice translation-profile S2-SRST-intranslate called 1!voice translation-profile S2-SRST-outtranslate called 10!!!applicationglobalservice alternate default!!!crypto pki trustpoint TP-self-signed-3021612211enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-3021612211revocation-check nonersakeypair TP-self-signed-3021612211!!crypto pki certificate chain TP-self-signed-3021612211certificate self-signed 0130820245 308201AE A0030201 02020101 300D0609 2A864886 F70D0101 0405003031312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 4365727469666963 6174652D 33303231 36313232 3131301E 170D3039 30363131 3232323134305A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 031326494F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 3032313631323231 3130819F 300D0609 2A864886 F70D0101 01050003 818D0030 818902818100952E 74B22996 55A51E37 8DA60200 0590F983 0375EFFE 60E9A360 AEAEEC7466F6C188 2ADFFE99 D7A5CAA3 4E55140F 91E6C706 F6107740 8551210F DD0B47CFC0801EEA 80CF9456 66CFAC2D 8B2C2EC0 762D92E7 A0E62EA9 F8D406F3 D39070600D4E8053 70E8EE96 AD39C98C 04B365C6 4E57BDF3 A2B43190 B02939E0 DF0C0B10A8270203 010001A3 6D306B30 0F060355 1D130101 FF040530 030101FF 30180603551D1104 11300F82 0D62316C 2E657365 2E6C6F63 616C301F 0603551D 23041830168014B2 D0D56B23 AD137366 E12C01FB A052FB71 9CE48630 1D060355 1D0E04160414B2D0 D56B23AD 137366E1 2C01FBA0 52FB719C E486300D 06092A86 4886F70D01010405 00038181 0029B1C4 FBF3A9EA C044C909 5641CE13 BE7BB985 C705847A7BCB2E46 2C151D24 DBB1296D 0F13B937 EC22F0D0 57C815CE 5FCA28F3 2ADFA571BF450B05 92BD038B 4948882B E455759A BD282100 7681C58B DFA5EB51 48E156111EC4EB13 3853A6BA 5009AB43 372620A1 71D5B283 4BD1BF8A 822CB1E1 E1AA8CD542028C49 CE83A384 A5quit!!!!username cisco secret 5 $1$lbdn$P7ro8OilCa9puLAhNkMrF0username Cisc0123 secret 5 $1$ssbG$.ASxHSEZHbNxPhJch8pcx1username admin secret 5 $1$UFHA$Ij/BzRhF91OsTvvRxeTNF0archivelog confighidekeys!!controller T1 2/0/0framing esflinecode b8zspri-group timeslots 1-24 service mgcp!controller T1 2/0/1framing esflinecode b8zspri-group timeslots 1-24 service mgcp!!!!!interface Loopback1ip address 10.33.9.23 255.255.255.0!interface Port-channel3description port-channel to core stackip address 10.40.79.9 255.255.255.252hold-queue 150 in!interface GigabitEthernet0/0description $ETH-LAN$$ETH-SW-LAUNCH$$INTF-INFO-GE 0/0$no ip addressduplex autospeed automedia-type rj45no keepalivechannel-group 3!interface GigabitEthernet0/1no ip addressduplex autospeed automedia-type rj45no keepalivechannel-group 3!interface Serial0/0/0description serial link from B1R to A1Rip address 10.33.4.5 255.255.255.254load-interval 30carrier-delay msec 0clock rate 2016000!interface Serial0/0/1no ip addressshutdownclock rate 2016000!interface Serial0/0/2no ip addressshutdownclock rate 2016000!interface Serial0/0/3no ip addressshutdownclock rate 2016000!interface FastEthernet1/0switchport trunk native vlan 50switchport mode trunk!interface FastEthernet1/1!interface FastEthernet1/2!interface FastEthernet1/3switchport access vlan 41!interface FastEthernet1/4!interface FastEthernet1/5!interface FastEthernet1/6!interface FastEthernet1/7!interface FastEthernet1/8!interface FastEthernet1/9!interface FastEthernet1/10!interface FastEthernet1/11!interface FastEthernet1/12!interface FastEthernet1/13!interface FastEthernet1/14!interface FastEthernet1/15!interface Serial2/0/0:23no ip addressencapsulation hdlcisdn switch-type primary-niisdn incoming-voice voiceno cdp enable!interface Serial2/0/1:23no ip addressencapsulation hdlcisdn switch-type primary-niisdn incoming-voice voiceno cdp enable!interface Vlan1no ip address!interface Vlan50ip address 10.41.50.1 255.255.255.0!interface Vlan51ip address 10.41.51.1 255.255.255.0!ip route 0.0.0.0 0.0.0.0 10.33.4.4ip route 0.0.0.0 0.0.0.0 Port-channel3!!ip http serverip http access-class 23ip http authentication localip http secure-serverip http timeout-policy idle 60 life 86400 requests 10000!access-list 23 permit 10.10.10.0 0.0.0.7!!!!!!control-plane!!!voice-port 2/0/0:23!voice-port 2/0/1:23!ccm-manager fallback-mgcpccm-manager mgcpccm-manager music-on-holdccm-manager config server 10.33.32.22ccm-manager config!mgcpmgcp call-agent CUCM7-Pub 2427 service-type mgcp version 0.1mgcp dtmf-relay voip codec all mode out-of-bandmgcp rtp unreachable timeout 1000 action notifymgcp modem passthrough voip mode nsemgcp package-capability rtp-packagemgcp package-capability sst-packagemgcp package-capability pre-packageno mgcp package-capability res-packageno mgcp package-capability fxr-packageno mgcp timer receive-rtcpmgcp sdp simplemgcp rtp payload-type g726r16 staticmgcp bind control source-interface Port-channel3mgcp bind media source-interface Port-channel3!mgcp profile default!!!dial-peer voice 1 potsdescription srst incomingtranslation-profile incoming S2-SRST-inservice mgcpappincoming called-number .direct-inward-dialport 2/0/1:23forward-digits 8!dial-peer voice 91 potsdescription SRST; Any long distance numberdestination-pattern 91..........port 2/0/1:23forward-digits 10!dial-peer voice 91444 potsdescription SRST; PSTN School2 to School1destination-pattern 91444.......port 2/0/1:23forward-digits 10!dial-peer voice 91333 potsdescription SRST; PSTN School2 to District Officedestination-pattern 91333.......port 2/0/1:23forward-digits 10!dial-peer voice 91222 potsdescription SRST; School2 local dialing with area codedestination-pattern 91222.......port 2/0/1:23forward-digits 10!dial-peer voice 9345 potsdescription SRST; School2 local dialing (PSTN-router num-exp adds area code)destination-pattern 9345....port 2/0/1:23forward-digits 7!dial-peer voice 911 potsdescription SRST; Emergency call without External access codedestination-pattern 911port 2/0/1:23forward-digits 3!dial-peer voice 84441 potsdescription SRST; translate calls to School1 using internal number formattranslation-profile outgoing S2-SRST-outdestination-pattern 84441...port 2/0/1:23forward-digits 10!dial-peer voice 83331 potsdescription SRST; translate calls to District office using internal number ftranslation-profile outgoing S2-SRST-outdestination-pattern 83331...port 2/0/1:23forward-digits 10!dial-peer voice 9911 potsdescription SRST; Emergency call with External access codedestination-pattern 9911port 2/0/1:23forward-digits 3!!!!call-manager-fallbackmax-conferences 12 gain -6transfer-system full-consultip source-address 10.40.79.9 port 2000max-ephones 10max-dn 20dialplan-pattern 1 82221... extension-length 8!banner exec ^CC-----------------------------------------------------------------------This is Router B1L-----------------------------------------------------------------------^Cbanner login ^CC-----------------------------------------------------------------------This is Router B1L-----------------------------------------------------------------------^Calias exec run sh run | beginalias exec int sh ip int brief!line con 0exec-timeout 0 0length 0stopbits 1line aux 0stopbits 1line vty 0 4access-class 23 inprivilege level 15login localtransport input noneline vty 5 15access-class 23 inprivilege level 15login localtransport input telnet ssh!scheduler allocate 20000 1000ntp authentication-key 2 md5 15200209132527203C 7ntp authenticatentp trusted-key 2ntp clock-period 17180073ntp source Port-channel3ntp max-associations 150ntp server 10.40.94.17 key 2!webvpn cef!endSchool2-B1L#School 100
Access
Cr36-2960-SS100!! Last configuration change at 13:39:58 EDT Thu Sep 3 2009 by cisco! NVRAM config last updated at 13:39:58 EDT Thu Sep 3 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr36-2960-SS100!boot-start-markerboot-end-marker!enable password 7 121A0C041104!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringsystem mtu routing 1500vtp domain School-Sitevtp mode transparentip subnet-zero!!ip dhcp snooping vlan 101-110,201no ip dhcp snooping information optionip dhcp snoopingno ip domain-lookupip arp inspection vlan 101-110ip arp inspection validate src-mac dst-mac ip allow zeros!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!crypto pki trustpoint HTTPS_SS_CERT_KEYPAIRenrollment selfsignedserial-numberrevocation-check nonersakeypair HTTPS_SS_CERT_KEYPAIR!!crypto pki certificate chain HTTPS_SS_CERT_KEYPAIRcertificate self-signed 01 nvram:F9406600host#2E2E.cer!!dot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 2name FlashNet_VLAN!vlan 101-110!vlan 201name Guest_VLAN!vlan 802name Hopping_VLAN!ip ftp username nimishguestip ftp password 7 04550F011A245F5A!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 1000000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 1000000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map Phone+PC-Policyclass VVLAN-VOIPpolice 1000000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 1000000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!interface Loopback0ip address 10.126.100.107 255.255.255.255no ip route-cache!interface Port-channel1description Connected to cr36-3750-Core-SS2switchport trunk native vlan 802switchport trunk allowed vlan 101-110switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/1description CONNECTED TO UNTRUSTED PCswitchport access vlan 101switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30duplex fullsrr-queue bandwidth share 1 30 35 5priority-queue outstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input UnTrusted-PC-Policyip verify source!interface FastEthernet0/2description CONNECTED TO TRUSTED-PCswitchport access vlan 102switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100duplex fullsrr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableip verify source!interface FastEthernet0/3description CONNECTED TO PHONEswitchport mode accessswitchport block unicastswitchport voice vlan 103switchport port-security maximum 2switchport port-security maximum 1 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security violation restrictip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastservice-policy input Phone-Policyip verify source!interface FastEthernet0/4description CONNECTED TO PHONE+PCswitchport access vlan 104switchport mode accessswitchport block unicastswitchport voice vlan 105switchport port-security maximum 3switchport port-security maximum 2 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone+PC-Policyip verify source!interface FastEthernet0/5description CONNECTED TO IPVS 2500 - CAMERAswitchport access vlan 106switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100duplex fullsrr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/6description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 107switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/7description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 108switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet0/8!interface FastEthernet0/9!interface FastEthernet0/10description Connected to IXIA - ALM - 5/3switchport trunk native vlan 802switchport trunk allowed vlan 101-110switchport mode trunkip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/11description Connected to IXIA - STX - 6/3switchport trunk native vlan 802switchport trunk allowed vlan 101-110switchport mode trunkip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0/12!interface FastEthernet0/13!interface FastEthernet0/14!interface FastEthernet0/15!interface FastEthernet0/16!interface FastEthernet0/17!interface FastEthernet0/18!interface FastEthernet0/19!interface FastEthernet0/20!interface FastEthernet0/21!interface FastEthernet0/22!interface FastEthernet0/23!interface FastEthernet0/24!interface FastEthernet0/25!interface FastEthernet0/26!interface FastEthernet0/27!interface FastEthernet0/28!interface FastEthernet0/29!interface FastEthernet0/30!interface FastEthernet0/31!interface FastEthernet0/32!interface FastEthernet0/33!interface FastEthernet0/34!interface FastEthernet0/35!interface FastEthernet0/36!interface FastEthernet0/37!interface FastEthernet0/38!interface FastEthernet0/39!interface FastEthernet0/40!interface FastEthernet0/41!interface FastEthernet0/42!interface FastEthernet0/43!interface FastEthernet0/44!interface FastEthernet0/45!interface FastEthernet0/46!interface FastEthernet0/47!interface FastEthernet0/48description Connected to FlashNetswitchport access vlan 2switchport mode accessload-interval 30!interface GigabitEthernet0/1description Connected to cr36-3750-Core-SS2switchport trunk native vlan 802switchport trunk allowed vlan 101-110switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode activeip dhcp snooping trust!interface GigabitEthernet0/2description Connected to cr36-3750-Core-SS2switchport trunk native vlan 802switchport trunk allowed vlan 101-110switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode activeip dhcp snooping trust!interface GigabitEthernet0/3!interface GigabitEthernet0/4!interface Vlan1no ip addressno ip route-cacheshutdown!interface Vlan2description Connected to FlashNetip address 172.26.160.196 255.255.254.0no ip redirectsno ip proxy-arpno ip route-cache!no ip http serverno ip http secure-server!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.34.4 auth-port 1645 acct-port 1646 key 7 1511021F072567757A60radius-server deadtime 1!control-plane!alias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36028943ntp server 172.26.160.10endCr36-3560-SS100!! Last configuration change at 13:38:21 EDT Thu Sep 3 2009 by cisco! NVRAM config last updated at 13:38:44 EDT Thu Sep 3 2009 by cisco!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr36-3560-SS100!boot-start-markerboot-end-marker!enable password 7 030752180500!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringsystem mtu routing 1500vtp domain School-Sitevtp mode transparentip subnet-zeroip routingno ip domain-lookup!!ip dhcp snooping vlan 111-120,202no ip dhcp snooping information optionip dhcp snoopingip multicast-routing distributedip arp inspection vlan 111-120,202ip arp inspection validate src-mac dst-mac ip allow zeros!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!crypto pki trustpoint HTTPS_SS_CERT_KEYPAIRenrollment selfsignedserial-numberrevocation-check nonersakeypair HTTPS_SS_CERT_KEYPAIR!!crypto pki certificate chain HTTPS_SS_CERT_KEYPAIRcertificate self-signed 01 nvram:5597A00hostn#2E2E.cerdot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120!!!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 2name FlashNet_VLAN!vlan 111-120!vlan 202name Guest_VLAN!vlan 803name Hopping_VLAN!ip ftp username nimishguestip ftp password 7 082F48491C1C1603!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 32000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map Phone+PC-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!!interface Loopback0ip address 10.126.100.108 255.255.255.255!interface Port-channel1description Connected to cr36-3750-Core-SS2switchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120,202switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet0no ip addressno ip route-cache cefno ip route-cacheno ip mroute-cacheshutdown!interface GigabitEthernet0/1description CONNECTED TO UNTRUSTED PCswitchport access vlan 111switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30duplex fullsrr-queue bandwidth share 1 30 35 5priority-queue outstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input UnTrusted-PC-Policyip verify source!interface GigabitEthernet0/2description CONNECTED TO TRUSTED-PCswitchport access vlan 112switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100duplex fullsrr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableip verify source!interface GigabitEthernet0/3description CONNECTED TO PHONEswitchport mode accessswitchport block unicastswitchport voice vlan 113switchport port-security maximum 2switchport port-security maximum 1 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security violation restrictip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastservice-policy input Phone-Policyip verify source!interface GigabitEthernet0/4description CONNECTED TO PHONE+PCswitchport access vlan 114switchport mode accessswitchport block unicastswitchport voice vlan 115switchport port-security maximum 3switchport port-security maximum 2 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input Phone+PC-Policyip verify source!interface GigabitEthernet0/5description CONNECTED TO IPVS 2500 - CAMERAswitchport access vlan 116switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100duplex fullsrr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet0/6description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 117switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100duplex fullsrr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet0/7description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 118switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface GigabitEthernet0/8!interface GigabitEthernet0/9!interface GigabitEthernet0/10description Connected to IXIA - ALM - 5/4switchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120switchport mode trunkip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet0/11description Connected to IXIA - STX - 6/4switchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120switchport mode trunkip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet0/12!interface GigabitEthernet0/13!interface GigabitEthernet0/14!interface GigabitEthernet0/15!interface GigabitEthernet0/16!interface GigabitEthernet0/17!interface GigabitEthernet0/18!interface GigabitEthernet0/19!interface GigabitEthernet0/20!interface GigabitEthernet0/21!interface GigabitEthernet0/22!interface GigabitEthernet0/23!interface GigabitEthernet0/24!interface GigabitEthernet0/25!interface GigabitEthernet0/26!interface GigabitEthernet0/27!interface GigabitEthernet0/28!interface GigabitEthernet0/29!interface GigabitEthernet0/30!interface GigabitEthernet0/31!interface GigabitEthernet0/32!interface GigabitEthernet0/33!interface GigabitEthernet0/34!interface GigabitEthernet0/35!interface GigabitEthernet0/36!interface GigabitEthernet0/37!interface GigabitEthernet0/38!interface GigabitEthernet0/39!interface GigabitEthernet0/40!interface GigabitEthernet0/41!interface GigabitEthernet0/42!interface GigabitEthernet0/43!interface GigabitEthernet0/44!interface GigabitEthernet0/45!interface GigabitEthernet0/46!interface GigabitEthernet0/47!interface GigabitEthernet0/48description Connected to FlashNetno switchportip address 172.26.160.197 255.255.255.0no ip redirectsno ip proxy-arp!interface GigabitEthernet0/49description Connected to cr36-3750-Core-SS2switchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120,202switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode activeip dhcp snooping trust!interface GigabitEthernet0/50description Connected to cr36-3750-Core-SS2switchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120,202switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode activeip dhcp snooping trust!interface GigabitEthernet0/51!interface GigabitEthernet0/52!interface TenGigabitEthernet0/1!interface TenGigabitEthernet0/2!interface Vlan1no ip addressshutdown!ip classlessip route 172.26.158.0 255.255.255.0 172.26.160.1no ip http serverno ip http secure-serverip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630!!snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server host 10.125.34.4 auth-port 1645 acct-port 1646 key 7 060506324F4145485744radius-server deadtime 1!control-plane!alias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36028803ntp server 172.26.160.10endCr36-3750-SS100!! Last configuration change at 13:40:57 EDT Thu Sep 3 2009! NVRAM config last updated at 13:41:35 EDT Thu Sep 3 2009!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryptionno service dhcp!hostname cr36-3750-SS100!boot-start-markerboot-end-marker!enable password 7 104D000A0618!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringswitch 1 provision ws-c3750-24tssystem mtu routing 1500vtp domain School-Sitevtp mode transparentip subnet-zeroip routingno ip domain-lookup!!ip dhcp snooping vlan 121-130no ip dhcp snooping information optionip dhcp snoopingip multicast-routing distributedip arp inspection vlan 121-130ip arp inspection validate src-mac dst-mac ip allow zeros!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!!dot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120port-channel load-balance src-dst-ip!!!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 121-130!vlan 203name Guest_VLAN!vlan 804name Hopping_VLAN!ip ftp username nimishguestip ftp password 7 011D02034E0E151B!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 32000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map PhonePolicyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!!interface Loopback0ip address 10.126.100.109 255.255.255.255!interface Port-channel1description Conneted to cr36-3750-Core-SS2switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0ip dhcp snooping trust!interface FastEthernet1/0/1description CONNECTED TO UNTRUSTED PCswitchport access vlan 121switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100load-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input UnTrusted-PC-Policyip verify source!interface FastEthernet1/0/2description CONNECTED TO TRUSTED-PCswitchport access vlan 122switchport mode accessswitchport block unicastswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableip verify source!interface FastEthernet1/0/3description CONNECTED TO PHONEswitchport mode accessswitchport block unicastswitchport voice vlan 123switchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security violation restrictip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastservice-policy input Phone-Policyip verify source!interface FastEthernet1/0/4description CONNECTED TO PHONEswitchport access vlan 124switchport mode accessswitchport block unicastswitchport voice vlan 125switchport port-security maximum 3switchport port-security maximum 2 vlan accessswitchport port-security maximum 1 vlan voiceswitchport port-securityswitchport port-security aging time 5switchport port-security violation restrictswitchport port-security aging type inactivityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust device cisco-phonemls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enableservice-policy input PhonePolicyip verify source!interface FastEthernet1/0/5description CONNECTED TO IPVS 2500 - CAMERAswitchport access vlan 126switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet1/0/6description CONNECTED TO IPVS 4500 - CAMERAswitchport access vlan 127switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet1/0/7description CONNECTED TO DIGITAL MEDIA PLAYERswitchport access vlan 128switchport mode accessswitchport block unicastswitchport port-securityip arp inspection limit rate 100srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpstorm-control broadcast level pps 1kstorm-control multicast level pps 2kstorm-control action trapspanning-tree portfastspanning-tree bpduguard enable!interface FastEthernet1/0/8!interface FastEthernet1/0/9!interface FastEthernet1/0/10description Connected to IXIA - ALM - 5/5switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet1/0/11description Connected to IXIA - STX - 7/1switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet1/0/12!interface FastEthernet1/0/13!interface FastEthernet1/0/14!interface FastEthernet1/0/15!interface FastEthernet1/0/16!interface FastEthernet1/0/17!interface FastEthernet1/0/18!interface FastEthernet1/0/19!interface FastEthernet1/0/20!interface FastEthernet1/0/21!interface FastEthernet1/0/22!interface FastEthernet1/0/23!interface FastEthernet1/0/24no switchportip address 172.26.160.198 255.255.254.0no ip redirectsno ip proxy-arp!interface GigabitEthernet1/0/1description Conneted to cr36-3750-Core-SS2switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-group 1 mode activehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface GigabitEthernet1/0/2description Conneted to cr36-3750-Core-SS2switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130switchport mode trunkip arp inspection trustload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-group 1 mode activehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface Vlan1no ip addressshutdown!ip classlessip route 172.26.158.0 255.255.255.0 172.26.160.1no ip http serverno ip http secure-serverip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630!!snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server deadtime 1!control-plane!alias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36029151ntp server 172.26.160.10endCr36-3750r-SS100!! Last configuration change at 13:44:09 EDT Thu Sep 3 2009! NVRAM config last updated at 13:45:28 EDT Thu Sep 3 2009!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr36-3750r-SS100!boot-start-markerboot-end-marker!enable password 7 00071A150754!no aaa new-modelclock timezone EST -5clock summer-time EDT recurringswitch 1 provision ws-c3750-24tsswitch 2 provision ws-c3750-24tsstack-mac persistent timer 0system mtu routing 1500vtp domain School-Sitevtp mode transparentip subnet-zeroip routingno ip domain-lookup!!ip multicast-routing distributed!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!key chain eigrp-keykey 1key-string 7 14141B180F0B!!!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120port-channel load-balance src-dst-ip!!!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 2name FlashNet_VLAN!vlan 11!ip ftp username nimishguestip ftp password 7 000A1701115E1812!class-map match-all BULK-DATAmatch access-group name BULK-DATAclass-map match-all VVLAN-SIGNALINGmatch ip dscp cs3class-map match-all MULTIMEDIA-CONFERENCINGmatch access-group name MULTIMEDIA-CONFERENCINGclass-map match-all DEFAULTmatch access-group name DEFAULTclass-map match-all SCAVENGERmatch access-group name SCAVENGERclass-map match-all SIGNALINGmatch access-group name SIGNALINGclass-map match-all VVLAN-VOIPmatch ip dscp efclass-map match-all TRANSACTIONAL-DATAmatch access-group name TRANSACTIONAL-DATA!!policy-map Phone-Policyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3policy-map UnTrusted-PC-Policyclass class-defaultpolice 10000000 8000 exceed-action dropset dscp defaultpolicy-map Trusted-PC-Policyclass MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 32000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmitpolicy-map PhonePolicyclass VVLAN-VOIPpolice 128000 8000 exceed-action dropset dscp efclass VVLAN-SIGNALINGpolice 32000 8000 exceed-action dropset dscp cs3class MULTIMEDIA-CONFERENCINGset dscp af41police 5000000 8000 exceed-action dropclass SIGNALINGset dscp cs3police 1000000 8000 exceed-action dropclass TRANSACTIONAL-DATAset dscp af21police 10000000 8000 exceed-action policed-dscp-transmitclass BULK-DATAset dscp af11police 10000000 8000 exceed-action policed-dscp-transmitclass SCAVENGERset dscp cs1police 10000000 8000 exceed-action dropclass DEFAULTset dscp defaultpolice 10000000 8000 exceed-action policed-dscp-transmit!!!!interface Loopback0ip address 10.126.100.110 255.255.255.255!interface Port-channel1description Connected to cr36-3750s-SS100no switchportdampeningip address 10.127.119.194 255.255.255.192ip pim sparse-modeip hold-time eigrp 100 20ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 out!interface FastEthernet1/0/1!interface FastEthernet1/0/2!interface FastEthernet1/0/3!interface FastEthernet1/0/4!interface FastEthernet1/0/5!interface FastEthernet1/0/6!interface FastEthernet1/0/7!interface FastEthernet1/0/8!interface FastEthernet1/0/9!interface FastEthernet1/0/10description Connected to IXIA - ALM - 5/6switchport trunk encapsulation dot1qswitchport trunk allowed vlan 11switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet1/0/11description Connected to IXIA - STX - 7/2switchport trunk encapsulation dot1qswitchport trunk allowed vlan 11switchport mode trunkswitchport nonegotiateip arp inspection trustload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 outip dhcp snooping trust!interface FastEthernet1/0/12!interface FastEthernet1/0/13!interface FastEthernet1/0/14!interface FastEthernet1/0/15!interface FastEthernet1/0/16!interface FastEthernet1/0/17!interface FastEthernet1/0/18!interface FastEthernet1/0/19!interface FastEthernet1/0/20!interface FastEthernet1/0/21!interface FastEthernet1/0/22!interface FastEthernet1/0/23!interface FastEthernet1/0/24description FlashNet - DO NOT ROUTEswitchport access vlan 2switchport mode accessload-interval 30spanning-tree portfast!interface GigabitEthernet1/0/1description Connected to cr36-3750s-SS100no switchportdampeningno ip addressload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode activehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/2!interface FastEthernet2/0/1!interface FastEthernet2/0/2!interface FastEthernet2/0/3!interface FastEthernet2/0/4!interface FastEthernet2/0/5!interface FastEthernet2/0/6!interface FastEthernet2/0/7!interface FastEthernet2/0/8!interface FastEthernet2/0/9!interface FastEthernet2/0/10!interface FastEthernet2/0/11!interface FastEthernet2/0/12!interface FastEthernet2/0/13!interface FastEthernet2/0/14!interface FastEthernet2/0/15!interface FastEthernet2/0/16!interface FastEthernet2/0/17!interface FastEthernet2/0/18!interface FastEthernet2/0/19!interface FastEthernet2/0/20!interface FastEthernet2/0/21!interface FastEthernet2/0/22!interface FastEthernet2/0/23!interface FastEthernet2/0/24description FlashNet - DO NOT ROUTEswitchport access vlan 2switchport mode accessload-interval 30spanning-tree portfast!interface GigabitEthernet2/0/1description Connected to cr36-3750s-SS100no switchportdampeningno ip addressload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 1 mode activehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet2/0/2!interface Vlan1ip address dhcpshutdown!interface Vlan2description FlashNet - DO NOT ROUTEip address 172.26.160.221 255.255.254.0no ip redirectsno ip proxy-arp!interface Vlan11dampeningip address 10.127.119.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!!router eigrp 100passive-interface defaultno passive-interface Port-channel1no auto-summaryeigrp router-id 10.126.100.110eigrp stub connectednetwork 10.127.0.0 0.0.255.255nsf!ip classlessip route 172.26.158.0 255.255.255.0 172.26.160.1no ip http serverno ip http secure-serverip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630!!snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12!control-plane!alias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104loginline vty 5 15exec-timeout 0 0no login!ntp clock-period 36029246ntp server 172.26.160.10endCore/Distribution/WAN Edge
Cr36-3750s-SS100!! Last configuration change at 13:37:04 EDT Thu Sep 3 2009! NVRAM config last updated at 13:37:12 EDT Thu Sep 3 2009!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeservice password-encryption!hostname cr36-3750s-SS100!boot-start-markerboot-end-marker!enable password 7 01100F175804!aaa new-model!!aaa authentication login default group radius enable lineaaa authentication dot1x default group radius!!!aaa session-id commonclock timezone EST -5clock summer-time EDT recurringswitch 1 provision ws-c3750e-48pdswitch 2 provision ws-c3750e-48pdswitch 3 provision ws-c3750e-48pdstack-mac persistent timer 0system mtu routing 1500vtp domain School-Sitevtp mode transparentip subnet-zeroip routingno ip domain-lookup!!ip multicast-routing distributed!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 56mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22 26 28 30 34mls qos srr-queue output dscp-map queue 2 threshold 1 36 38mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 56mls qos srr-queue output dscp-map queue 3 threshold 3 0mls qos srr-queue output dscp-map queue 4 threshold 1 8mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 2 80 90 100 100mls qos queue-set output 1 threshold 4 60 100 100 100mls qos!key chain eigrp-keykey 1key-string 7 05080F1C2243!crypto pki trustpoint TP-self-signed-3197398400enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-3197398400revocation-check nonersakeypair TP-self-signed-3197398400!!crypto pki certificate chain TP-self-signed-3197398400certificate self-signed 01 nvram:IOS-Self-Sig#3030.cerdot1x system-auth-controldot1x guest-vlan supplicant!!!errdisable recovery cause udlderrdisable recovery cause bpduguarderrdisable recovery cause dhcp-rate-limiterrdisable recovery cause storm-controlerrdisable recovery cause arp-inspectionerrdisable recovery interval 120port-channel load-balance src-dst-ip!!!spanning-tree mode rapid-pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-id!vlan internal allocation policy ascending!vlan 2name FlashNet_VLAN!vlan 101name cr36_2960_Dept1!vlan 102name cr36_2960_Dept2!vlan 103name cr36_2960_Dept3!vlan 104name cr36_2960_Dept4!vlan 105name cr36_2960_Dept5!vlan 106name cr36_2960_Dept6!vlan 107name cr36_2960_Dept7!vlan 108name cr36_2960_Dept8!vlan 109name cr36_2960_Dept9!vlan 110name cr36_2960_Dept10!vlan 111name cr36_3560_Dept11!vlan 112name cr36_3560_Dept12!vlan 113name cr36_3560_Dept13!vlan 114name cr36_3560_Dept14!vlan 115name cr36_3560_Dept15!vlan 116name cr36_3560_Dept16!vlan 117name cr36_3560_Dept17!vlan 118name cr36_3560_Dept18!vlan 119name cr36_3560_Dept19!vlan 120name cr36_3560_Dept20!vlan 121name cr36_3750_Dept21!vlan 122name cr36_3750_Dept22!vlan 123name cr36_3750_Dept23!vlan 124name cr36_3750_Dept24!vlan 125name cr36_3750_Dept25!vlan 126name cr36_3750_Dept26!vlan 127name cr36_3750_Dept27!vlan 128name cr36_3750_Dept28!vlan 129name cr36_3750_Dept29!vlan 130name cr36_3750_Dept30!vlan 650name cr24_3750ME_DO!vlan 801name MetroE_Hopping_VLAN!vlan 802name cr36_2960_Hopping_VLAN!vlan 803name cr36_3560_Hopping_VLAN!vlan 804name cr36_3750_Hopping_VLAN!vlan 900name Mgmt_VLAN!ip ftp username nimishguestip ftp password 7 000A1701115E1812!!!interface Loopback0ip address 10.126.100.106 255.255.255.255!interface Port-channel11description Connected to cr36-2960-SS2switchport trunk encapsulation dot1qswitchport trunk native vlan 802switchport trunk allowed vlan 101-110,900switchport mode trunkload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 out!interface Port-channel12description Connected to cr36-3560-SS2switchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120,900switchport mode trunkload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 out!interface Port-channel13description Connected to cr36-3750-SS2switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130,900switchport mode trunkload-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 out!interface Port-channel14description Connected to cr36-3750r-SS2no switchportdampeningip address 10.127.119.193 255.255.255.192ip pim sparse-modeip hold-time eigrp 100 20ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip summary-address eigrp 100 10.127.112.0 255.255.248.0 5load-interval 30carrier-delay msec 0hold-queue 2000 inhold-queue 2000 out!interface FastEthernet0no ip addressno ip route-cache cefno ip route-cacheno ip mroute-cacheshutdown!interface GigabitEthernet1/0/1!interface GigabitEthernet1/0/2description Connected to MetroE-Core-cr24-6500-1switchport trunk encapsulation dot1qswitchport trunk native vlan 801switchport trunk allowed vlan 650switchport mode trunkload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/3!interface GigabitEthernet1/0/4!interface GigabitEthernet1/0/5!interface GigabitEthernet1/0/6!interface GigabitEthernet1/0/7!interface GigabitEthernet1/0/8!interface GigabitEthernet1/0/9!interface GigabitEthernet1/0/10!interface GigabitEthernet1/0/11!interface GigabitEthernet1/0/12!interface GigabitEthernet1/0/13!interface GigabitEthernet1/0/14!interface GigabitEthernet1/0/15!interface GigabitEthernet1/0/16!interface GigabitEthernet1/0/17!interface GigabitEthernet1/0/18!interface GigabitEthernet1/0/19!interface GigabitEthernet1/0/20!interface GigabitEthernet1/0/21!interface GigabitEthernet1/0/22!interface GigabitEthernet1/0/23!interface GigabitEthernet1/0/24!interface GigabitEthernet1/0/25!interface GigabitEthernet1/0/26!interface GigabitEthernet1/0/27!interface GigabitEthernet1/0/28!interface GigabitEthernet1/0/29!interface GigabitEthernet1/0/30!interface GigabitEthernet1/0/31!interface GigabitEthernet1/0/32!interface GigabitEthernet1/0/33!interface GigabitEthernet1/0/34!interface GigabitEthernet1/0/35!interface GigabitEthernet1/0/36!interface GigabitEthernet1/0/37!interface GigabitEthernet1/0/38!interface GigabitEthernet1/0/39!interface GigabitEthernet1/0/40!interface GigabitEthernet1/0/41!interface GigabitEthernet1/0/42!interface GigabitEthernet1/0/43!interface GigabitEthernet1/0/44!interface GigabitEthernet1/0/45!interface GigabitEthernet1/0/46!interface GigabitEthernet1/0/47!interface GigabitEthernet1/0/48description Connected to FlashNetswitchport access vlan 2switchport mode accessload-interval 30!interface GigabitEthernet1/0/49description Connected to cr36-2960-SS100switchport trunk encapsulation dot1qswitchport trunk native vlan 802switchport trunk allowed vlan 101-110,900switchport mode trunkload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 11 mode activespanning-tree guard roothold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/50description Connected to cr36-3560-SS2switchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120,900switchport mode trunkload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 12 mode activehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/51description Connected to cr36-3750-SS2switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130,900switchport mode trunkload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 13 mode activehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet1/0/52description Connected to cr36-3750r-SS100no switchportdampeningno ip addressload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 14 mode activehold-queue 2000 inhold-queue 2000 out!interface TenGigabitEthernet1/0/1!interface TenGigabitEthernet1/0/2!interface GigabitEthernet2/0/1srr-queue bandwidth share 1 30 35 5priority-queue outmls qos trust dscp!interface GigabitEthernet2/0/2description Connected to MetroE-Core-cr24-6500-1switchport trunk encapsulation dot1qswitchport trunk native vlan 801switchport trunk allowed vlan 650switchport mode trunkload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5srr-queue bandwidth shape 35 15 25 25srr-queue bandwidth limit 10priority-queue outmls qos trust dscpno cdp enablespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet2/0/3!interface GigabitEthernet2/0/4!interface GigabitEthernet2/0/5!interface GigabitEthernet2/0/6!interface GigabitEthernet2/0/7!interface GigabitEthernet2/0/8!interface GigabitEthernet2/0/9!interface GigabitEthernet2/0/10!interface GigabitEthernet2/0/11!interface GigabitEthernet2/0/12!interface GigabitEthernet2/0/13!interface GigabitEthernet2/0/14!interface GigabitEthernet2/0/15!interface GigabitEthernet2/0/16!interface GigabitEthernet2/0/17!interface GigabitEthernet2/0/18!interface GigabitEthernet2/0/19!interface GigabitEthernet2/0/20!interface GigabitEthernet2/0/21!interface GigabitEthernet2/0/22!interface GigabitEthernet2/0/23!interface GigabitEthernet2/0/24!interface GigabitEthernet2/0/25!interface GigabitEthernet2/0/26!interface GigabitEthernet2/0/27!interface GigabitEthernet2/0/28!interface GigabitEthernet2/0/29!interface GigabitEthernet2/0/30!interface GigabitEthernet2/0/31!interface GigabitEthernet2/0/32!interface GigabitEthernet2/0/33!interface GigabitEthernet2/0/34!interface GigabitEthernet2/0/35!interface GigabitEthernet2/0/36!interface GigabitEthernet2/0/37!interface GigabitEthernet2/0/38!interface GigabitEthernet2/0/39!interface GigabitEthernet2/0/40!interface GigabitEthernet2/0/41!interface GigabitEthernet2/0/42!interface GigabitEthernet2/0/43!interface GigabitEthernet2/0/44!interface GigabitEthernet2/0/45!interface GigabitEthernet2/0/46!interface GigabitEthernet2/0/47!interface GigabitEthernet2/0/48description Connected to FlashNetswitchport access vlan 2switchport mode accessload-interval 30!interface GigabitEthernet2/0/49!interface GigabitEthernet2/0/50!interface GigabitEthernet2/0/51!interface GigabitEthernet2/0/52!interface TenGigabitEthernet2/0/1!interface TenGigabitEthernet2/0/2!interface GigabitEthernet3/0/1!interface GigabitEthernet3/0/2!interface GigabitEthernet3/0/3!interface GigabitEthernet3/0/4!interface GigabitEthernet3/0/5!interface GigabitEthernet3/0/6!interface GigabitEthernet3/0/7!interface GigabitEthernet3/0/8!interface GigabitEthernet3/0/9!interface GigabitEthernet3/0/10!interface GigabitEthernet3/0/11!interface GigabitEthernet3/0/12!interface GigabitEthernet3/0/13!interface GigabitEthernet3/0/14!interface GigabitEthernet3/0/15!interface GigabitEthernet3/0/16!interface GigabitEthernet3/0/17!interface GigabitEthernet3/0/18!interface GigabitEthernet3/0/19!interface GigabitEthernet3/0/20!interface GigabitEthernet3/0/21!interface GigabitEthernet3/0/22!interface GigabitEthernet3/0/23!interface GigabitEthernet3/0/24!interface GigabitEthernet3/0/25!interface GigabitEthernet3/0/26!interface GigabitEthernet3/0/27!interface GigabitEthernet3/0/28!interface GigabitEthernet3/0/29!interface GigabitEthernet3/0/30!interface GigabitEthernet3/0/31!interface GigabitEthernet3/0/32!interface GigabitEthernet3/0/33!interface GigabitEthernet3/0/34!interface GigabitEthernet3/0/35!interface GigabitEthernet3/0/36!interface GigabitEthernet3/0/37!interface GigabitEthernet3/0/38!interface GigabitEthernet3/0/39!interface GigabitEthernet3/0/40!interface GigabitEthernet3/0/41!interface GigabitEthernet3/0/42!interface GigabitEthernet3/0/43!interface GigabitEthernet3/0/44!interface GigabitEthernet3/0/45!interface GigabitEthernet3/0/46!interface GigabitEthernet3/0/47!interface GigabitEthernet3/0/48description Connected to FlashNetswitchport access vlan 2switchport mode accessload-interval 30!interface GigabitEthernet3/0/49description Connected to cr36-2960-SS100switchport trunk encapsulation dot1qswitchport trunk native vlan 802switchport trunk allowed vlan 101-110,900switchport mode trunkload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 11 mode activehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet3/0/50description Connected to cr36-3560-SS2switchport trunk encapsulation dot1qswitchport trunk native vlan 803switchport trunk allowed vlan 111-120,900switchport mode trunkload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 12 mode activehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet3/0/51description Connected to cr36-3750-SS2switchport trunk encapsulation dot1qswitchport trunk native vlan 804switchport trunk allowed vlan 121-130,900switchport mode trunkload-interval 30carrier-delay msec 0srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 13 mode activehold-queue 2000 inhold-queue 2000 out!interface GigabitEthernet3/0/52description Connected to cr36-3750r-SS100no switchportdampeningno ip addressload-interval 30srr-queue bandwidth share 1 30 35 5priority-queue outudld portmls qos trust dscpchannel-protocol lacpchannel-group 14 mode activespanning-tree portfast trunkspanning-tree bpdufilter enablehold-queue 2000 inhold-queue 2000 out!interface TenGigabitEthernet3/0/1!interface TenGigabitEthernet3/0/2!interface Vlan1no ip addressshutdown!interface Vlan2description Connected to FlashNetip address 172.26.160.195 255.255.254.0no ip redirectsno ip proxy-arpload-interval 30!interface Vlan101description Connected to cr36_2960_Dept_1_VLANdampeningip address 10.127.112.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan102description Connected to cr36_2960_Dept_2_VLANdampeningip address 10.127.112.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan103description Connected to cr36_2960_Dept_3_VLANdampeningip address 10.127.112.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan104description Connected to cr36_2960_Dept_4_VLANdampeningip address 10.127.112.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan105description Connected to cr36_2960_Dept_5_VLANdampeningip address 10.127.113.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan106description Connected to cr36_2960_Dept_6_VLANdampeningip address 10.127.113.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan107description Connected to cr36_2960_Dept_7_VLANdampeningip address 10.127.113.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan108description Connected to cr36_2960_Dept_8_VLANdampeningip address 10.127.113.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan109description Connected to cr36_2960_Dept_9_VLANdampeningip address 10.127.114.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan110description Connected to cr36_2960_Dept_10_VLANdampeningip address 10.127.114.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan111description Connected to cr36_3560_Dept_1_VLANdampeningip address 10.127.114.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan112description Connected to cr36_3560_Dept_2_VLANdampeningip address 10.127.114.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan113description Connected to cr36_3560_Dept_3_VLANdampeningip address 10.127.115.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan114description Connected to cr36_3560_Dept_4_VLANdampeningip address 10.127.115.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan115description Connected to cr36_3560_Dept_5_VLANdampeningip address 10.127.115.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan116description Connected to cr36_3560_Dept_6_VLANdampeningip address 10.127.115.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan117description Connected to cr36_3560_Dept_7_VLANdampeningip address 10.127.116.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan118description Connected to cr36_3560_Dept_8_VLANdampeningip address 10.127.116.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan119description Connected to cr36_3560_Dept_9_VLANdampeningip address 10.127.116.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan120description Connected to cr36_3560_Dept_10_VLANdampeningip address 10.127.116.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan121description Connected to cr36_3750_Dept_1_VLANdampeningip address 10.127.117.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan122description Connected to cr36_3750_Dept_2_VLANdampeningip address 10.127.117.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan123description Connected to cr36_3750_Dept_3_VLANdampeningip address 10.127.117.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan124description Connected to cr36_3750_Dept_4_VLANdampeningip address 10.127.117.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan125description Connected to cr36_3750_Dept_5_VLANdampeningip address 10.127.118.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan126description Connected to cr36_3750_Dept_6_VLANdampeningip address 10.127.118.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan127description Connected to cr36_3750_Dept_7_VLANdampeningip address 10.127.118.129 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan128description Connected to cr36_3750_Dept_8_VLANdampeningip address 10.127.118.193 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan129description Connected to cr36_3750_Dept_9_VLANdampeningip address 10.127.119.1 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan130description Connected to cr36_3750_Dept_10_VLANdampeningip address 10.127.119.65 255.255.255.192ip helper-address 10.125.31.2no ip redirectsno ip unreachablesip pim sparse-modeload-interval 30!interface Vlan650dampeningip address 10.126.1.99 255.255.255.254no ip redirectsno ip unreachablesip pim sparse-modeip hold-time eigrp 100 20ip authentication mode eigrp 100 md5ip authentication key-chain eigrp 100 eigrp-keyip summary-address eigrp 100 10.127.112.0 255.255.248.0 5load-interval 30hold-queue 2000 inhold-queue 2000 out!interface Vlan900no ip address!!router eigrp 100passive-interface defaultno passive-interface Vlan650no passive-interface GigabitEthernet1/0/52no passive-interface GigabitEthernet3/0/52no passive-interface Port-channel14distribute-list route-map EIGRP_STUB_ROUTES out GigabitEthernet1/0/52distribute-list route-map EIGRP_STUB_ROUTES out GigabitEthernet3/0/52distribute-list route-map EIGRP_STUB_ROUTES out Port-channel14no auto-summaryeigrp router-id 10.126.100.106network 10.126.0.0 0.1.255.255network 11.1.0.0 0.0.255.255nsf!ip classlessip route 172.26.158.0 255.255.255.0 172.26.160.1no ip http serverno ip http secure-serverip pim rp-address 10.125.100.100 Allowed_MCAST_Groups overrideip pim spt-threshold infinityip pim accept-register list PERMIT-SOURCES!!ip access-list standard Allowed_MCAST_Groupspermit 224.0.1.39permit 224.0.1.40permit 239.192.0.0 0.0.255.255!ip access-list extended BULK-DATAremark FTPpermit tcp any any eq ftppermit tcp any any eq ftp-dataremark SSH/SFTPpermit tcp any any eq 22remark SMTP/SECURE SMTPpermit tcp any any eq smtppermit tcp any any eq 465remark IMAP/SECURE IMAPpermit tcp any any eq 143permit tcp any any eq 993remark POP3/SECURE POP3permit tcp any any eq pop3permit tcp any any eq 995remark CONNECTED PC BACKUPpermit tcp any eq 1914 anyip access-list extended DEFAULTremark EXPLICIT CLASS-DEFAULTpermit ip any anyip access-list extended MULTIMEDIA-CONFERENCINGremark RTPpermit udp any any range 16384 32767ip access-list extended PERMIT-SOURCESpermit ip 10.125.31.80 0.0.0.15 239.192.0.0 0.0.255.255ip access-list extended PXEpermit tcp any any establishedpermit udp any any eq bootpspermit udp any host 10.125.31.11 eq domainpermit udp any host 10.125.31.12 eq tftpip access-list extended SCAVENGERremark KAZAApermit tcp any any eq 1214permit udp any any eq 1214remark MICROSOFT DIRECT X GAMINGpermit tcp any any range 2300 2400permit udp any any range 2300 2400remark APPLE ITUNES MUSIC SHARINGpermit tcp any any eq 3689permit udp any any eq 3689remark BITTORRENTpermit tcp any any range 6881 6999remark YAHOO GAMESpermit tcp any any eq 11999remark MSN GAMING ZONEpermit tcp any any range 28800 29100ip access-list extended SIGNALINGremark SCCPpermit tcp any any range 2000 2002remark SIPpermit tcp any any range 5060 5061permit udp any any range 5060 5061ip access-list extended TRANSACTIONAL-DATAremark HTTPSpermit tcp any any eq 443remark ORACLE-SQL*NETpermit tcp any any eq 1521permit udp any any eq 1521remark ORACLEpermit tcp any any eq 1526permit udp any any eq 1526permit tcp any any eq 1575permit udp any any eq 1575permit tcp any any eq 1630!access-list 1 permit 0.0.0.0access-list 1 permit 10.127.112.0access-list 1 permit 10.124.0.0route-map EIGRP_STUB_ROUTES permit 10match ip address 1!!snmp-server community public ROsnmp-server community k12 RWsnmp-server trap-source Loopback0snmp-server host 172.26.158.251 version 2c k12radius-server dead-criteria time 15 tries 3radius-server deadtime 1!control-plane!alias exec ct config talias exec srb sh run | beginalias exec sri sh run intalias exec cl clear loggalias exec rib show ip routealias exec ec sh etherchannelalias exec cc clea countalias exec sac sh access-listalias exec cpu show proc c s | inc CPUalias exec sin show ip int brief | ex unassi!line con 0exec-timeout 0 0password 7 121A0C041104line vty 0 4exec-timeout 0 0password 7 121A0C041104line vty 5 15exec-timeout 0 0!ntp clock-period 36028897ntp server 172.26.160.10endPSTN Edge
School1-B1R#term len 0School1-B1R#sh runBuilding configuration...Current configuration : 8585 bytes!! Last configuration change at 16:52:10 UTC Tue Sep 8 2009! NVRAM config last updated at 16:52:12 UTC Tue Sep 8 2009!version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname School1-B1R!boot-start-markerboot system flash:c3825-advipservicesk9-mz.124-15.T1.binboot-end-marker!card type t1 2 1logging buffered 51200 warnings!no aaa new-modelno network-clock-participate slot 2no network-clock-participate wic 0!!ip cef!!no ip domain lookupip domain name ese.localip name-server 10.33.32.5!multilink bundle-name authenticated!isdn switch-type primary-nivoice-card 0no dspfarm!voice-card 2no dspfarm!!!key chain eigrp-chainkey 100key-string cisco!!!!!!!!!!!!!!voice translation-rule 1rule 1 /^444567/ /8444/!voice translation-rule 10rule 1 /^82221/ /2223451/rule 2 /^83331/ /3334561/!!voice translation-profile S1-SRST-intranslate called 1!voice translation-profile S1-SRST-outtranslate called 10!voice translation-profile S1-SRTS-intranslate called 1!voice translation-profile S1-SRTS-outtranslate called 10!!!applicationglobalservice alternate default!!!crypto pki trustpoint TP-self-signed-2533920657enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-2533920657revocation-check nonersakeypair TP-self-signed-2533920657!!crypto pki certificate chain TP-self-signed-2533920657certificate self-signed 0130820245 308201AE A0030201 02020101 300D0609 2A864886 F70D0101 0405003031312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 4365727469666963 6174652D 32353333 39323036 3537301E 170D3039 30333233 3030333235325A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 031326494F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 3533333932303635 3730819F 300D0609 2A864886 F70D0101 01050003 818D0030 818902818100C4CF 56547BED 94F2C7CB F804CFE3 4EF4E717 D4F45158 0323CDC6 15D57A1CEEF6E208 A638F3CF 68E3ED79 6A5A2599 3535A184 142D2FB8 9F90BFC6 688DA8850F01452F CB77727F 49E88D22 EBE8C8FE 79C603B4 400036EC A7E46F95 67556DB7418CC9C9 855452C1 7A1F43D5 FC517ECE D2A016A2 D22469A7 B04F29D6 2D1F7D6ACD170203 010001A3 6D306B30 0F060355 1D130101 FF040530 030101FF 30180603551D1104 11300F82 0D623172 2E657365 2E6C6F63 616C301F 0603551D 2304183016801462 21F5D80D A391D7D8 81DEBE96 EAC85A83 1D5FC830 1D060355 1D0E041604146221 F5D80DA3 91D7D881 DEBE96EA C85A831D 5FC8300D 06092A86 4886F70D01010405 00038181 00682E54 6D74F19D BC8642C5 D73A980A 977C2BD7 6FEC7C5D6B78D63E B60E5EA3 00D8B281 EAD97996 71EC669E C2CD1B53 A8FA35FE 69A431E7434C76AB 69C7AD8C 75125C78 D1B59887 BA744878 7CBF83D1 9E947524 DB4F0A2E760C4DF3 8D72E317 FDD224C2 55FC2B1F 737A4F6E 72E5D6A2 BBF56AD5 49587E492807367C E83C477F A7quit!!!!username cisco secret 5 $1$80Id$RaudGd7tcWPCMbRIK0jlQ0username Cisc0123 secret 5 $1$p0S6$1mALRMHiKoDpH5w3V5CqO1username admin secret 5 $1$dOZk$BZ75VO488cehdyLDZiRjI1archivelog confighidekeys!!controller T1 2/0framing esflinecode b8zspri-group timeslots 1-24 service mgcp!controller T1 2/1framing esflinecode b8zs!!!!!interface Loopback0ip address 10.40.63.1 255.255.255.255!interface Loopback1ip address 10.33.9.22 255.255.255.0!interface Port-channel1no ip addresshold-queue 0 in!interface Port-channel3description port-channel to core stackip address 10.40.63.9 255.255.255.252hold-queue 150 in!interface GigabitEthernet0/0description $ETH-LAN$$ETH-SW-LAUNCH$$INTF-INFO-GE 0/0$no ip addressduplex autospeed automedia-type rj45no keepalivechannel-group 3!interface GigabitEthernet0/1no ip addressduplex autospeed automedia-type rj45no keepalivechannel-group 3!interface Serial0/0/0description serial link from B1R to A1Rip address 10.33.4.3 255.255.255.254load-interval 30carrier-delay msec 0clock rate 2016000!interface Serial0/0/1no ip addressshutdownclock rate 2016000!interface Serial0/0/2no ip addressshutdownclock rate 2016000!interface Serial0/0/3no ip addressshutdownclock rate 2016000!interface FastEthernet1/0!interface FastEthernet1/1!interface FastEthernet1/2!interface FastEthernet1/3!interface FastEthernet1/4!interface FastEthernet1/5!interface FastEthernet1/6!interface FastEthernet1/7!interface FastEthernet1/8!interface FastEthernet1/9!interface FastEthernet1/10!interface FastEthernet1/11!interface FastEthernet1/12!interface FastEthernet1/13!interface FastEthernet1/14!interface FastEthernet1/15!interface Serial2/0:23description to simulated PSTNno ip addressencapsulation hdlcisdn switch-type primary-niisdn incoming-voice voiceisdn bind-l3 ccm-managerno cdp enable!interface Vlan1no ip address!ip route 0.0.0.0 0.0.0.0 Port-channel3!!ip http serverip http access-class 23ip http authentication localip http secure-serverip http timeout-policy idle 60 life 86400 requests 10000!access-list 23 permit 10.10.10.0 0.0.0.7!!!!!!control-plane!!!voice-port 2/0:23!ccm-manager fallback-mgcpccm-manager mgcpccm-manager music-on-holdccm-manager config server 10.33.32.22ccm-manager config!mgcpmgcp call-agent CUCM7-Pub 2427 service-type mgcp version 0.1mgcp dtmf-relay voip codec all mode out-of-bandmgcp rtp unreachable timeout 1000 action notifymgcp modem passthrough voip mode nsemgcp package-capability rtp-packagemgcp package-capability sst-packagemgcp package-capability pre-packageno mgcp package-capability res-packageno mgcp package-capability fxr-packageno mgcp timer receive-rtcpmgcp sdp simplemgcp rtp payload-type g726r16 staticmgcp bind control source-interface Port-channel3mgcp bind media source-interface Port-channel3!mgcp profile default!!!dial-peer voice 83331 potsdescription SRST; translate calls to District office using internal number ftranslation-profile outgoing S1-SRTS-outdestination-pattern 83331...port 2/0:23forward-digits 10!dial-peer voice 1 potsdescription srst incomingtranslation-profile incoming S1-SRTS-inservice mgcpappincoming called-number .direct-inward-dialport 2/0:23forward-digits 8!dial-peer voice 91 potsdescription SRST; Any long distance numberdestination-pattern 91..........port 2/0:23forward-digits 10!dial-peer voice 91222 potsdescription SRST; PSTN School1 to School2destination-pattern 91222.......port 2/0:23forward-digits 10!dial-peer voice 91333 potsdescription SRST; PSTN School1 to District Officedestination-pattern 91333.......port 2/0:23forward-digits 10!dial-peer voice 91444 potsdescription SRST; School1 local dialing with area codedestination-pattern 91444.......port 2/0:23forward-digits 10!dial-peer voice 9567 potsdescription SRST; School1 local dialing (PSTN-router num-exp adds area code)destination-pattern 9567....port 2/0:23forward-digits 7!dial-peer voice 911 potsdescription SRST; Emergency call without External access codedestination-pattern 911port 2/0:23forward-digits 3!dial-peer voice 82221 potsdescription SRST; translate calls to School2 using internal number formattranslation-profile outgoing S1-SRTS-outdestination-pattern 82221...port 2/0:23forward-digits 10!dial-peer voice 9911 potsdescription SRST; Emergency call with External access codedestination-pattern 9911port 2/0:23forward-digits 3!!!!call-manager-fallbackmax-conferences 12 gain -6transfer-system fSep 8 16:52:37.667: %ISDN-6-LAYER2DOWN: Layer 2 for Interface Se2/0:23, TEI 0 changed to downull-consultip source-address 10.40.63.9 port 2000max-ephones 10max-dn 20!banner exec ^CC-----------------------------------------------------------------------This is Router B1R-----------------------------------------------------------------------^Cbanner login ^CC-----------------------------------------------------------------------This is Router B1R-----------------------------------------------------------------------^Calias exec run sh run | beginalias exec int sh ip int brief!line con 0exec-timeout 0 0length 0stopbits 1line aux 0stopbits 1line vty 0 4access-class 23 inprivilege level 15login localtransport input telnet sshline vty 5 15access-class 23 inprivilege level 15login localtransport input telnet ssh!scheduler allocate 20000 1000ntp authentication-key 2 md5 04690203182E404A1D 7ntp authenticatentp trusted-key 2ntp clock-period 17179727ntp max-associations 150ntp server 10.40.94.17 key 2!webvpn cef!endSchool1-B1R#