=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2015.09.18 13:21:02 =~=~=~=~=~=~=~=~=~=~=~= *************************************************************************** This is a private system operated by Northgate-IS company business. Authorization from Northgate-IS management is required to use this system. The Northgate-IS Standards of Business Conduct and all Northgate-IS Information Security policies and standards must be strictly followed. Use by unauthorized persons is prohibited and may result in civil and/or criminal NTC_Core_3750#show running-config Building configuration... Current configuration : 28544 bytes ! ! Last configuration change at 13:03:42 BST Fri Sep 18 2015 by GGR ! version 12.2 no service pad service tcp-keepalives-in service tcp-keepalives-out service timestamps debug datetime localtime service timestamps log datetime localtime service password-encryption ! hostname NTC_Core_3750 ! ! aaa new-model aaa group server radius ACS server 10.73.208.10 auth-port 1645 acct-port 1646 server 10.73.208.14 auth-port 1645 acct-port 1646 --More--  ! aaa authentication login ACS-AUTH group ACS local enable aaa authorization exec default group ACS local ! aaa session-id common clock timezone GMT 0 clock summer-time BST recurring last Sun Mar 2:00 last Sun Oct 2:00 switch 1 provision ws-c3750g-24ts-1u switch 2 provision ws-c3750g-12s system mtu routing 1500 ! track 1 ip route 192.168.250.255 255.255.255.255 reachability ip subnet-zero ip routing ip cef load-sharing algorithm universal 5B1258F2 ip dhcp excluded-address 10.73.208.129 ip dhcp excluded-address 10.73.208.253 10.73.208.254 ! ip multicast-routing distributed ! mls qos map cos-dscp 0 8 16 26 32 46 48 56 mls qos srr-queue input bandwidth 90 10 mls qos srr-queue input threshold 1 8 16 --More--  mls qos srr-queue input threshold 2 34 66 mls qos srr-queue input buffers 67 33 mls qos srr-queue input cos-map queue 1 threshold 2 1 mls qos srr-queue input cos-map queue 1 threshold 3 0 mls qos srr-queue input cos-map queue 2 threshold 1 2 mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7 mls qos srr-queue input cos-map queue 2 threshold 3 3 5 mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15 mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7 mls qos srr-queue input dscp-map queue 1 threshold 3 32 mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23 mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48 mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56 mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63 mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31 mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47 mls qos srr-queue output cos-map queue 1 threshold 3 5 mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7 mls qos srr-queue output cos-map queue 3 threshold 3 2 4 mls qos srr-queue output cos-map queue 4 threshold 2 1 mls qos srr-queue output cos-map queue 4 threshold 3 0 mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47 mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31 --More--  mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55 mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63 mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23 mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39 mls qos srr-queue output dscp-map queue 4 threshold 1 8 mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15 mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7 mls qos queue-set output 1 threshold 1 138 138 92 138 mls qos queue-set output 1 threshold 2 138 138 92 400 mls qos queue-set output 1 threshold 3 36 77 100 318 mls qos queue-set output 1 threshold 4 20 50 67 400 mls qos queue-set output 2 threshold 1 149 149 100 149 mls qos queue-set output 2 threshold 2 118 118 100 235 mls qos queue-set output 2 threshold 3 41 68 100 272 mls qos queue-set output 2 threshold 4 42 72 100 242 mls qos queue-set output 1 buffers 10 10 26 54 mls qos queue-set output 2 buffers 16 6 17 61 mls qos ! ! errdisable recovery interval 600 no file verify auto ! --More--  spanning-tree mode pvst spanning-tree extend system-id spanning-tree vlan 1-2,99-100,200,300-308,400,500,600,700,800 priority 24576 spanning-tree vlan 900 priority 24576 ! vlan internal allocation policy ascending ! ! interface Port-channel1 description PortChannel to WLC switchport trunk encapsulation dot1q switchport trunk native vlan 600 switchport trunk allowed vlan 40-43,600 switchport mode trunk ! interface Port-channel2 description PortChannel to DC01 switchport access vlan 100 switchport mode access spanning-tree portfast spanning-tree bpduguard enable ! interface Port-channel3 --More--   description PortChannel to FM01 switchport access vlan 100 switchport mode access spanning-tree portfast spanning-tree bpduguard enable ! interface Port-channel4 description PortChannel to FP01 switchport access vlan 100 switchport mode access spanning-tree portfast spanning-tree bpduguard enable ! interface Port-channel5 description PortChannel to MIS01 switchport access vlan 100 switchport mode access spanning-tree portfast spanning-tree bpduguard enable ! interface Port-channel6 description PortChannel to PRT01 switchport access vlan 100 --More--   switchport mode access spanning-tree portfast spanning-tree bpduguard enable ! interface Port-channel7 description PortChannel to SYS01 switchport access vlan 100 switchport mode access spanning-tree portfast spanning-tree bpduguard enable ! interface Port-channel8 description PortChannel to SQL Server switchport access vlan 100 switchport mode access spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/1 description ***Reserved DC Server Port*** switchport access vlan 100 switchport mode access channel-group 2 mode on --More--   spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/2 description ***Reserved DC Server Port*** switchport access vlan 100 switchport mode access channel-group 2 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/3 description ***Reserved FM Server Port*** switchport access vlan 100 switchport mode access channel-group 3 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/4 description ***Reserved FM Server Port*** switchport access vlan 100 switchport mode access --More--   channel-group 3 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/5 description ***Reserved F&P Server Port*** switchport access vlan 100 switchport mode access channel-group 4 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/6 description ***Reserved F&P Server Port*** switchport access vlan 100 switchport mode access channel-group 4 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/7 description ***Reserved F&P Server Port*** switchport access vlan 100 --More--   switchport mode access channel-group 4 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/8 description ***Reserved F&P Server Port*** switchport access vlan 100 switchport mode access channel-group 4 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/9 description ***Reserved MIS Server Port*** switchport access vlan 100 switchport mode access channel-group 5 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/10 description ***Reserved MIS Server Port*** --More--   switchport access vlan 100 switchport mode access channel-group 5 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/11 description ***Reserved PRT Server Port*** switchport access vlan 100 switchport mode access channel-group 6 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/12 description ***Reserved PRT Server Port*** switchport access vlan 100 switchport mode access channel-group 6 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/13 --More--   description ***Reserved SYS Server Port*** switchport access vlan 100 switchport mode access channel-group 7 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/14 description ***Reserved SYS Server Port*** switchport access vlan 100 switchport mode access channel-group 7 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/15 description ***Reserved Server Port*** switchport access vlan 100 switchport mode access channel-group 8 mode on spanning-tree portfast spanning-tree bpduguard enable ! --More--  interface GigabitEthernet1/0/16 description ***Reserved Server Port*** switchport access vlan 100 switchport mode access channel-group 8 mode on spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/17 description Client_PC_Vlan_302_900 switchport access vlan 301 switchport trunk encapsulation dot1q switchport trunk native vlan 301 switchport mode trunk switchport voice vlan 900 srr-queue bandwidth share 10 10 60 20 srr-queue bandwidth shape 10 0 0 0 queue-set 2 priority-queue out mls qos trust device cisco-phone mls qos trust cos auto qos voip cisco-phone spanning-tree portfast --More--  ! interface GigabitEthernet1/0/18 description ***Reserved Server Port*** switchport access vlan 100 switchport mode access spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/19 description Client_PC_Vlan_301 switchport access vlan 100 switchport mode access spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/20 description ** UPS Management Card ** switchport access vlan 100 switchport mode access spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/21 --More--   description *Websense_Proxy_Server* switchport access vlan 100 switchport mode access spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/22 description Link to NTC-2851-01 port Gi0/0 switchport access vlan 900 switchport mode access spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/23 description Link to NTC-1841-01 port Fa0/0 switchport trunk encapsulation dot1q switchport trunk native vlan 99 switchport trunk allowed vlan 47,99,100 switchport mode trunk spanning-tree portfast spanning-tree bpduguard enable ! interface GigabitEthernet1/0/24 --More--   description Link to KCC WAN switchport access vlan 999 ! interface GigabitEthernet1/0/25 description Link to WLC-NTC-01 switchport trunk encapsulation dot1q switchport trunk native vlan 600 switchport trunk allowed vlan 40-43,600 switchport mode trunk channel-group 1 mode on ! interface GigabitEthernet1/0/26 description Link to WLC-NTC-01 switchport trunk encapsulation dot1q switchport trunk native vlan 600 switchport trunk allowed vlan 40-43,600 switchport mode trunk channel-group 1 mode on ! interface GigabitEthernet1/0/27 description Link to WLC-NTC-01 switchport trunk encapsulation dot1q switchport trunk native vlan 600 --More--   switchport trunk allowed vlan 40-43,600 switchport mode trunk channel-group 1 mode on ! interface GigabitEthernet1/0/28 description Link to WLC-NTC-01 switchport trunk encapsulation dot1q switchport trunk native vlan 600 switchport trunk allowed vlan 40-43,600 switchport mode trunk channel-group 1 mode on ! interface GigabitEthernet2/0/1 description Link to NTC_CL1_01 port Gi0/23 switchport trunk encapsulation dot1q switchport trunk native vlan 99 switchport mode trunk ! interface GigabitEthernet2/0/2 description Link to NTC_CL5_01 port Gi0/23 switchport trunk encapsulation dot1q switchport trunk native vlan 99 switchport mode trunk --More--  ! interface GigabitEthernet2/0/3 description Link to NTC_CL6_01 port Gi0/23 switchport trunk encapsulation dot1q switchport trunk native vlan 99 switchport mode trunk ! interface GigabitEthernet2/0/4 description Link to NTC_CL2_01 port Gi0/23 switchport trunk encapsulation dot1q switchport trunk native vlan 99 switchport mode trunk ! interface GigabitEthernet2/0/5 description Link to NTC_CL3_01 port Gi0/23 switchport trunk encapsulation dot1q switchport trunk native vlan 99 switchport mode trunk ! interface GigabitEthernet2/0/6 description Link to NTC_CL4_01 port Gi0/23 switchport trunk encapsulation dot1q switchport trunk native vlan 99 --More--   switchport mode trunk ! interface GigabitEthernet2/0/7 description Link to NTC_CL8_01 port Gi0/23 switchport trunk encapsulation dot1q switchport trunk native vlan 99 switchport mode trunk ! interface GigabitEthernet2/0/8 description Link to NTC_CL7_01 port Gi0/23 switchport trunk encapsulation dot1q switchport trunk native vlan 99 switchport mode trunk ! interface GigabitEthernet2/0/9 description NVP SPAN Port switchport access vlan 100 ! interface GigabitEthernet2/0/10 switchport trunk encapsulation dot1q switchport trunk native vlan 99 switchport mode trunk shutdown --More--  ! interface GigabitEthernet2/0/11 switchport trunk encapsulation dot1q switchport trunk native vlan 99 switchport mode trunk shutdown ! interface GigabitEthernet2/0/12 switchport access vlan 100 switchport trunk encapsulation dot1q switchport trunk native vlan 99 switchport mode access ! interface Vlan1 no ip address shutdown ! interface Vlan40 description *BSFguest_209.0/24* ip address 10.73.52.1 255.255.252.0 ip access-group 100 in ip helper-address 10.73.208.10 ip helper-address 10.73.208.14 --More--  ! interface Vlan41 description *BSFManaged_220.0/22* ip address 10.73.220.1 255.255.252.0 ip helper-address 10.73.208.10 ip helper-address 10.73.208.14 ! interface Vlan42 description *BSFiPad_214.0/25* ip address 10.73.214.1 255.255.255.128 ip helper-address 10.73.208.10 ip helper-address 10.73.208.14 ! interface Vlan43 description *NTCmac_214.129/26* ip address 10.73.214.129 255.255.255.128 ip helper-address 10.73.208.10 ip helper-address 10.73.208.14 ! interface Vlan99 description *Management_208.64/26* ip address 10.73.208.65 255.255.255.192 ! --More--  interface Vlan100 description *Servers_192.0/26* ip address 10.73.208.1 255.255.255.192 no ip redirects ip pim sparse-mode ! interface Vlan200 description *Printers_213.0/25* ip address 10.73.213.1 255.255.255.128 ! interface Vlan301 description *Cluster_01_216.0/24* ip address 10.73.216.1 255.255.255.0 ip helper-address 10.73.208.10 ip helper-address 10.73.208.14 ip helper-address 10.73.208.44 ip pim sparse-mode ! interface Vlan302 description *Cluster_02_217.0/24* ip address 10.73.217.1 255.255.255.0 ip helper-address 10.73.208.10 ip helper-address 10.73.208.14 --More--   ip helper-address 10.73.208.44 ip pim sparse-mode ! interface Vlan303 description *Cluster_03_218.0/24* ip address 10.73.218.1 255.255.255.0 ip helper-address 10.73.208.10 ip helper-address 10.73.208.14 ip helper-address 10.73.208.44 ip pim sparse-mode ! interface Vlan304 description *Cluster_04_219.0/24* ip address 10.73.219.1 255.255.255.0 ip helper-address 10.73.208.10 ip helper-address 10.73.208.14 ip helper-address 10.73.208.44 ip pim sparse-mode ! interface Vlan309 description *MAC_Provisioning_210.0/26* ip address 10.73.210.1 255.255.255.192 ip helper-address 10.73.208.20 --More--  ! interface Vlan400 description *E_Reg_212.0/25* ip address 10.73.212.1 255.255.255.128 ! interface Vlan500 description *Legacy_PCs_212.128/25* ip address 10.73.212.129 255.255.255.128 ! interface Vlan600 description *Wireless_APs_208.128/25* ip address 10.73.208.129 255.255.255.128 ip helper-address 10.73.208.10 ip helper-address 10.73.208.14 ! interface Vlan800 description *Plasma_Dynamax_213.128/26* ip address 10.73.213.129 255.255.255.192 ip helper-address 10.73.208.10 ip helper-address 10.73.208.14 ip pim sparse-mode ! interface Vlan900 --More--   description *VoIP_Vlan_211.0/24* ip address 10.73.211.1 255.255.255.0 ip helper-address 10.73.208.10 ip helper-address 10.73.208.14 ! interface Vlan998 description *INTERIM LAN* no ip address ! interface Vlan999 description *KCC WAN Transit* ip address 10.73.1.214 255.255.255.252 ip access-group INBOUND-WAN in ip access-group OUTBOUND-WAN out ! router eigrp 10 network 10.73.208.1 0.0.0.0 no auto-summary ! ip classless ip route 0.0.0.0 0.0.0.0 10.73.1.213 ip route 10.73.208.0 255.255.240.0 Null0 no ip http server --More--  ! ip pim rp-address 10.73.208.65 override ip radius source-interface Vlan99 ! ip access-list standard Monitor permit 172.31.1.243 permit 10.5.18.155 permit 10.73.216.47 ! ip access-list extended INBOUND-WAN permit tcp host 10.5.18.225 eq 443 10.73.208.0 0.0.15.255 permit udp 172.31.242.0 0.0.0.3 10.73.208.0 0.0.0.63 eq 1812 permit udp 172.31.242.0 0.0.0.3 10.73.208.0 0.0.0.63 eq 1813 permit udp 172.31.242.0 0.0.0.3 10.73.208.0 0.0.0.63 eq 1645 permit udp 172.31.242.0 0.0.0.3 10.73.208.0 0.0.0.63 eq 1646 deny ip host 172.31.2.3 any deny ip host 172.31.1.133 any permit tcp host 10.5.16.79 10.73.208.0 0.0.0.63 range 8400 8403 permit udp host 10.5.16.79 10.73.208.0 0.0.0.63 range 8400 8403 permit tcp host 10.5.16.79 10.73.208.0 0.0.0.63 range 50000 51000 permit udp host 10.5.16.79 10.73.208.0 0.0.0.63 range 50000 51000 permit tcp host 10.5.16.79 range 8400 8403 10.73.208.0 0.0.0.63 permit udp host 10.5.16.79 range 8400 8403 10.73.208.0 0.0.0.63 --More--   permit tcp host 10.5.16.79 range 50000 51000 10.73.208.0 0.0.0.63 permit udp host 10.5.16.79 range 50000 51000 10.73.208.0 0.0.0.63 permit tcp host 10.5.17.65 10.73.208.0 0.0.0.63 range 8400 8403 log permit udp host 10.5.17.65 10.73.208.0 0.0.0.63 range 8400 8403 permit tcp host 10.5.17.65 10.73.208.0 0.0.0.63 range 50000 51000 permit udp host 10.5.17.65 10.73.208.0 0.0.0.63 range 50000 51000 permit tcp host 10.5.17.65 range 8400 8403 10.73.208.0 0.0.0.63 permit udp host 10.5.17.65 range 8400 8403 10.73.208.0 0.0.0.63 permit tcp host 10.5.17.65 range 50000 51000 10.73.208.0 0.0.0.63 permit udp host 10.5.17.65 range 50000 51000 10.73.208.0 0.0.0.63 permit tcp host 10.73.224.18 host 10.73.208.18 range 8400 8402 permit tcp host 10.73.224.18 host 10.73.208.18 range 50000 51000 permit tcp host 10.73.224.18 range 8400 8402 host 10.73.208.18 permit tcp host 10.73.224.18 range 50000 51000 host 10.73.208.18 permit tcp host 10.74.96.18 host 10.73.208.18 range 8400 8402 permit tcp host 10.74.96.18 host 10.73.208.18 range 50000 51000 permit tcp host 10.74.96.18 range 8400 8402 host 10.73.208.18 permit tcp host 10.74.96.18 range 50000 51000 host 10.73.208.18 permit ip any 10.73.211.0 0.0.0.255 permit ip 10.5.21.0 0.0.0.255 10.73.208.0 0.0.15.255 permit ip 10.5.13.0 0.0.0.255 10.73.208.0 0.0.15.255 permit tcp 10.5.20.0 0.0.0.255 eq 491 10.73.208.0 0.0.15.255 permit tcp 10.5.20.0 0.0.0.255 eq www 10.73.208.0 0.0.15.255 --More--   permit tcp 10.5.20.0 0.0.0.255 eq 443 10.73.208.0 0.0.15.255 permit tcp 10.5.12.0 0.0.0.255 eq www 10.73.208.0 0.0.15.255 permit tcp 10.5.12.0 0.0.0.255 eq 443 10.73.208.0 0.0.15.255 permit tcp 10.5.12.0 0.0.0.255 eq 491 10.73.208.0 0.0.15.255 deny ip 10.5.8.0 0.0.7.255 10.73.208.0 0.0.15.255 deny ip 10.5.16.0 0.0.7.255 10.73.208.0 0.0.15.255 deny ip 10.52.16.0 0.0.15.255 10.73.208.0 0.0.0.63 deny ip 10.41.192.0 0.0.15.255 10.73.208.0 0.0.0.63 deny ip 10.41.176.0 0.0.15.255 10.73.208.0 0.0.0.63 deny ip 10.42.96.0 0.0.15.255 10.73.208.0 0.0.0.63 deny ip 10.73.192.0 0.0.15.255 10.73.208.0 0.0.0.63 deny ip 10.73.208.0 0.0.15.255 10.73.208.0 0.0.0.63 deny ip 10.73.224.0 0.0.15.255 10.73.208.0 0.0.0.63 deny ip 10.51.112.0 0.0.15.255 10.73.208.0 0.0.0.63 deny ip 10.73.176.0 0.0.15.255 10.73.208.0 0.0.0.63 deny ip 10.41.208.0 0.0.15.255 10.73.208.0 0.0.0.63 permit ip 172.31.243.0 0.0.0.255 host 10.73.208.28 permit ip 172.31.244.0 0.0.3.255 host 10.73.208.28 permit udp any eq 1194 host 10.73.208.28 permit udp any host 10.73.208.28 eq 1194 permit ip 172.31.1.0 0.0.0.255 host 10.73.208.28 permit ip 10.81.47.0 0.0.0.255 host 10.73.208.28 permit tcp any eq 443 host 10.73.208.28 --More--   permit tcp any eq www host 10.73.208.28 permit ip 10.5.21.0 0.0.0.255 host 10.73.208.28 permit ip 10.5.13.0 0.0.0.255 host 10.73.208.28 deny ip 10.0.0.0 0.255.255.255 host 10.73.208.28 permit ip host 172.29.81.81 host 10.73.208.28 deny ip 172.16.0.0 0.15.255.255 host 10.73.208.28 deny ip 192.168.0.0 0.0.255.255 host 10.73.208.28 permit ip any any ip access-list extended OUTBOUND-WAN permit tcp 10.73.208.0 0.0.15.255 host 10.5.18.225 eq 443 permit udp 10.73.208.0 0.0.0.63 eq 1812 172.31.242.0 0.0.0.3 permit udp 10.73.208.0 0.0.0.63 eq 1813 172.31.242.0 0.0.0.3 permit udp 10.73.208.0 0.0.0.63 eq 1645 172.31.242.0 0.0.0.3 permit udp 10.73.208.0 0.0.0.63 eq 1646 172.31.242.0 0.0.0.3 deny ip any host 172.31.2.3 deny ip any host 172.31.1.133 permit tcp 10.73.208.0 0.0.0.63 range 8400 8403 host 10.5.16.79 permit udp 10.73.208.0 0.0.0.63 range 8400 8403 host 10.5.16.79 permit tcp 10.73.208.0 0.0.0.63 range 50000 51000 host 10.5.16.79 permit udp 10.73.208.0 0.0.0.63 range 50000 51000 host 10.5.16.79 permit tcp 10.73.208.0 0.0.0.63 host 10.5.16.79 range 8400 8403 permit udp 10.73.208.0 0.0.0.63 host 10.5.16.79 range 8400 8403 permit tcp 10.73.208.0 0.0.0.63 host 10.5.16.79 range 50000 51000 --More--   permit udp 10.73.208.0 0.0.0.63 host 10.5.16.79 range 50000 51000 permit tcp 10.73.208.0 0.0.0.63 range 8400 8403 host 10.5.17.65 log permit udp 10.73.208.0 0.0.0.63 range 8400 8403 host 10.5.17.65 permit tcp 10.73.208.0 0.0.0.63 range 50000 51000 host 10.5.17.65 permit udp 10.73.208.0 0.0.0.63 range 50000 51000 host 10.5.17.65 permit tcp 10.73.208.0 0.0.0.63 host 10.5.17.65 range 8400 8403 permit udp 10.73.208.0 0.0.0.63 host 10.5.17.65 range 8400 8403 permit tcp 10.73.208.0 0.0.0.63 host 10.5.17.65 range 50000 51000 permit udp 10.73.208.0 0.0.0.63 host 10.5.17.65 range 50000 51000 permit tcp host 10.73.208.18 host 10.73.224.18 range 8400 8402 permit tcp host 10.73.208.18 host 10.73.224.18 range 50000 51000 permit tcp host 10.73.208.18 range 8400 8402 host 10.73.224.18 permit tcp host 10.73.208.18 range 50000 51000 host 10.73.224.18 permit tcp host 10.73.208.18 host 10.74.96.18 range 8400 8402 permit tcp host 10.73.208.18 host 10.74.96.18 range 50000 51000 permit tcp host 10.73.208.18 range 8400 8402 host 10.74.96.18 permit tcp host 10.73.208.18 range 50000 51000 host 10.74.96.18 permit ip 10.73.211.0 0.0.0.255 any permit ip 10.73.208.0 0.0.15.255 10.5.21.0 0.0.0.255 permit ip 10.73.208.0 0.0.15.255 10.5.13.0 0.0.0.255 permit tcp 10.73.208.0 0.0.15.255 10.5.20.0 0.0.0.255 eq 491 permit tcp 10.73.208.0 0.0.15.255 10.5.20.0 0.0.0.255 eq www permit tcp 10.73.208.0 0.0.15.255 10.5.20.0 0.0.0.255 eq 443 --More--   permit tcp 10.73.208.0 0.0.15.255 10.5.12.0 0.0.0.255 eq www permit tcp 10.73.208.0 0.0.15.255 10.5.12.0 0.0.0.255 eq 443 permit tcp 10.73.208.0 0.0.15.255 10.5.12.0 0.0.0.255 eq 491 deny ip 10.73.208.0 0.0.15.255 10.5.8.0 0.0.7.255 deny ip 10.73.208.0 0.0.15.255 10.5.16.0 0.0.7.255 deny ip 10.73.208.0 0.0.0.63 10.52.16.0 0.0.15.255 deny ip 10.73.208.0 0.0.0.63 10.41.192.0 0.0.15.255 deny ip 10.73.208.0 0.0.0.63 10.41.176.0 0.0.15.255 deny ip 10.73.208.0 0.0.0.63 10.42.96.0 0.0.15.255 deny ip 10.73.208.0 0.0.0.63 10.73.192.0 0.0.15.255 deny ip 10.73.208.0 0.0.0.63 10.73.208.0 0.0.15.255 deny ip 10.73.208.0 0.0.0.63 10.73.224.0 0.0.15.255 deny ip 10.73.208.0 0.0.0.63 10.51.112.0 0.0.15.255 deny ip 10.73.208.0 0.0.0.63 10.73.176.0 0.0.15.255 deny ip 10.73.208.0 0.0.0.63 10.41.208.0 0.0.15.255 permit ip host 10.73.208.28 172.31.243.0 0.0.0.255 permit ip host 10.73.208.28 172.31.244.0 0.0.3.255 permit udp host 10.73.208.28 any eq 1194 permit udp host 10.73.208.28 eq 1194 any permit ip host 10.73.208.28 172.31.1.0 0.0.0.255 permit ip host 10.73.208.28 10.81.47.0 0.0.0.255 permit ip host 10.73.208.28 10.5.21.0 0.0.0.255 permit ip host 10.73.208.28 10.5.13.0 0.0.0.255 --More--   deny ip host 10.73.208.28 10.0.0.0 0.255.255.255 permit ip host 10.73.208.28 host 172.29.81.81 deny ip host 10.73.208.28 172.16.0.0 0.15.255.255 deny ip host 10.73.208.28 192.168.0.0 0.0.255.255 permit ip any any permit ip 10.74.97.0 0.0.0.255 host 10.5.20.13 ip access-list extended SIMMS_ACL deny ip host 10.73.208.28 host 10.5.17.68 permit ip host 10.73.208.28 10.5.16.0 0.0.7.255 permit ip host 10.73.208.28 host 172.29.81.81 permit tcp host 10.73.208.28 10.73.208.0 0.0.15.255 range 52965 52966 permit tcp 10.73.208.0 0.0.15.255 range 52965 52966 host 10.73.208.28 permit tcp host 10.73.208.28 10.73.208.0 0.0.15.255 eq 8739 permit tcp 10.73.208.0 0.0.15.255 eq 8739 host 10.73.208.28 permit tcp host 10.73.208.28 10.73.208.0 0.0.15.255 eq 139 permit tcp 10.73.208.0 0.0.15.255 host 10.73.208.28 eq 139 permit udp host 10.73.208.28 10.73.208.0 0.0.15.255 range netbios-ns netbios-dgm permit udp 10.73.208.0 0.0.15.255 range netbios-ns netbios-dgm host 10.73.208.28 deny ip host 10.73.208.28 any ip access-list extended WAN-Access permit ip 10.5.16.0 0.0.7.255 host 10.73.208.28 --More--   permit ip 10.5.8.0 0.0.7.255 host 10.73.208.28 permit ip 172.31.1.0 0.0.0.255 host 10.73.208.28 permit ip 172.31.2.0 0.0.0.255 host 10.73.208.28 permit ip 10.81.47.0 0.0.0.255 host 10.73.208.28 permit tcp any eq 443 host 10.73.208.28 permit tcp any eq www host 10.73.208.28 permit udp any eq 1194 host 10.73.208.28 deny ip any host 10.73.208.28 permit ip any any ! access-list 100 permit udp 10.73.52.0 0.0.3.255 host 172.31.81.46 eq domain access-list 100 permit udp 10.73.52.0 0.0.3.255 host 172.31.49.46 eq domain access-list 100 permit udp 10.73.52.0 0.0.3.255 host 10.5.17.21 eq domain access-list 100 permit udp 10.73.52.0 0.0.3.255 host 10.5.9.21 eq domain access-list 100 permit tcp 10.73.52.0 0.0.3.255 10.5.20.0 0.0.3.255 eq www access-list 100 permit tcp 10.73.52.0 0.0.3.255 10.5.12.0 0.0.3.255 eq www access-list 100 permit tcp 10.73.52.0 0.0.3.255 10.5.20.0 0.0.3.255 eq 443 access-list 100 permit tcp 10.73.52.0 0.0.3.255 10.5.12.0 0.0.3.255 eq 443 access-list 100 permit tcp 10.73.52.0 0.0.3.255 10.5.20.0 0.0.3.255 eq 8080 access-list 100 permit tcp 10.73.52.0 0.0.3.255 10.5.12.0 0.0.3.255 eq 8080 access-list 100 permit tcp 10.73.52.0 0.0.3.255 10.73.213.0 0.0.0.127 log access-list 100 permit tcp 10.73.52.0 0.0.3.255 10.73.212.128 0.0.0.7 eq www access-list 100 permit tcp 10.73.52.0 0.0.3.255 10.73.212.128 0.0.0.7 eq 443 --More--  access-list 100 deny ip 10.73.52.0 0.0.3.255 10.0.0.0 0.255.255.255 access-list 100 deny ip 10.73.52.0 0.0.3.255 192.168.0.0 0.0.255.255 access-list 100 deny ip 10.73.52.0 0.0.3.255 172.16.0.0 0.0.15.255 access-list 100 permit udp any any eq bootpc access-list 100 permit udp any any eq bootps route-map SIMS_RM permit 5 match ip address SIMMS_ACL set ip next-hop verify-availability 10.73.208.9 1 track 1 ! snmp-server community ntc-snmp RO Monitor snmp-server location Northfleet Technical College snmp-server enable traps license radius-server dead-criteria time 1 tries 1 radius-server host 10.73.208.10 auth-port 1645 acct-port 1646 radius-server host 10.73.208.14 auth-port 1645 acct-port 1646 radius-server source-ports 1645-1646 radius-server retransmit 2 radius-server timeout 2 radius-server deadtime 1 ! control-plane --More--  ! banner motd ^C *************************************************************************** This is a private system operated by Northgate-IS company business. Authorization from Northgate-IS management is required to use this system. The Northgate-IS Standards of Business Conduct and all Northgate-IS Information Security policies and standards must be strictly followed. Use by unauthorized persons is prohibited and may result in civil and/or criminal liability and prosecution. ***************************************************************************^C ! line con 0 exec-timeout 120 0 logging synchronous line vty 0 4 exec-timeout 120 0 logging synchronous login authentication ACS-AUTH length 0 line vty 5 15 --More--   exec-timeout 120 0 logging synchronous login authentication ACS-AUTH length 0 ! ! monitor session 1 source interface Gi1/0/24 monitor session 1 source interface Gi2/0/1 - 8 monitor session 1 destination interface Gi2/0/9 ntp clock-period 36029435 ntp source Vlan99 ntp server 172.31.49.254 ntp server 172.31.81.254 prefer end NTC_Core_3750# exit