Вы находитесь на странице: 1из 6

GERMANIA_DBI-S355909#sh run

Building configuration...

Current configuration : 7429 bytes


!
! Last configuration change at 20:03:52 UTC Sat Mar 9 2019 by ltenorio.e
!
version 16.6
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
platform qfp utilization monitor load 80
no platform punt-keepalive disable-kernel-core
platform hardware throughput level 75000
!
hostname GERMANIA_DBI-S355909
!
boot-start-marker
boot system flash bootflash:isr4200-universalk9_ias.16.06.04.SPA.bin
boot-end-marker
!
!
logging buffered 100000
logging console critical
enable secret 5 $1$Embg$a.sQ8.OeynSMS17Q7nwo.1
!
aaa new-model
!
!
aaa authentication login default group tacacs+ local
aaa authentication login CLEARPASS group tacacs+ local
aaa authorization console
aaa authorization exec default group tacacs+ local
aaa authorization commands 15 default group tacacs+ local if-authenticated
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 0 default start-stop group tacacs+
aaa accounting commands 1 default start-stop group tacacs+
aaa accounting commands 15 default start-stop group tacacs+
aaa accounting network default start-stop group tacacs+
aaa accounting connection default start-stop group tacacs+
aaa accounting system default start-stop group tacacs+
!
!
!
!
!
!
aaa session-id common
!
no ip bootp server
ip name-server 200.31.108.106 200.31.108.107
ip domain name americatelperu.red
!
!
!
!
!
!
!
!
!
!
subscriber templating
!
!
!
!
!
!
!
multilink bundle-name authenticated
!
!
!
crypto pki trustpoint TP-self-signed-2083340852
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2083340852
revocation-check none
rsakeypair TP-self-signed-2083340852
!
!
crypto pki certificate chain TP-self-signed-2083340852
certificate self-signed 01
30820330 30820218 A0030201 02020101 300D0609 2A864886 F70D0101 05050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 32303833 33343038 3532301E 170D3139 30333039 31373130
32335A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 30383333
34303835 32308201 22300D06 092A8648 86F70D01 01010500 0382010F 00308201
0A028201 0100C29B 9EE06B9F 8E1A470A EDD87FC4 067BE94D E5B0CF06 CB8CD77B
0373D58B 13C92362 6A0835E8 A8D32F12 A5CBD92D F185CCD1 F788D188 CFBCCC4E
75BDF188 C164D8EA 6232DAE9 9CB1F240 950FEECA 2D5FC898 6DE314F2 B858619D
62E44D3D D89BCC9C B8F9FFA6 94D01A3B 8CFDA626 B55F5953 E44FC256 013A3372
548AAE07 C2DF8C64 0DD98A17 0051A893 45DAA994 74A5572F 0B25737C DAC51971
0319AF8A 2461EB8E 77BC3D5D 5DA001D6 36484AB4 E580E092 2224843A 71B73D94
9F41368A B93C7064 AA310966 F804D670 F8BA7320 0B08F0F8 8A5BF097 9848C2D0
F7F47570 0D80497E 7D71D710 E05909F0 E8E4FC88 C3B19058 F1C03E6A BC4C02DF
65E70563 96D90203 010001A3 53305130 0F060355 1D130101 FF040530 030101FF
301F0603 551D2304 18301680 14C0C7C5 414374A4 4AC913AA B892AD2D 1AAA3FF6
74301D06 03551D0E 04160414 C0C7C541 4374A44A C913AAB8 92AD2D1A AA3FF674
300D0609 2A864886 F70D0101 05050003 82010100 6C871651 734ACE30 D9638A5F
F6257B77 986D22CF 87869A8E EADD846D 6A4FC830 3CB6A5FC 403B24FA A49E32B0
B908A471 19630686 B7B40F6B B64F2117 991D7E56 2B5F567C 9C34B640 F90C1764
FA68E7F2 21EA9693 AE460E8C EEFC79FC FF2D5CA1 E77FF75B 763D0027 A00B7B7D
E2F160EB B590F483 C2B2761A DB3F3D2E 3425F91A 0D9B0940 6366FB80 1AC8B72B
CDCE87AB 2FCF5E6E 2A095441 ACC8B2FF 1A88D24D D3000B11 BD7CB549 28C5B178
F7D2E5CA 438C39E8 C923BF02 18A69384 F6026DE7 89F6FD82 40E880D6 D1F6CAFF
4AE807F6 57AB6D28 3EBF0EDB 6D4ADA8D 04ABA0FA A634C2A4 F72A5279 A7CC054E
C43510DC 3B0ADA70 6C364E2C 5C01F7BF 373620FD
quit
!
!
license udi pid ISR4221/K9 sn FGL2233102A
license accept end user agreement
license boot level securityk9
diagnostic bootup level minimal
spanning-tree extend system-id
!
!
!
username americatel privilege 15 password 7 0110520E0F06521D2218
!
redundancy
mode none
!
!
!
!
!
!
!
!
!
!
!
!
!
crypto isakmp policy 10
encr 3des
authentication pre-share
group 2
!
crypto isakmp policy 20
encr 3des
authentication pre-share
group 2
lifetime 28800
crypto isakmp key local1 address 190.8.135.153
crypto isakmp key germania address 190.187.250.48
!
!
crypto ipsec transform-set americatel esp-3des esp-sha-hmac
mode tunnel
!
!
!
crypto map Cliente local-address GigabitEthernet0/0/1
crypto map Cliente 10 ipsec-isakmp
set peer 190.8.135.153
set transform-set americatel
match address 100
crypto map Cliente 20 ipsec-isakmp
set peer 190.187.250.48
set transform-set americatel
set pfs group5
match address 150
!
!
!
!
!
!
!
!
interface GigabitEthernet0/0/0
description WAN-DBI
ip address 10.28.45.226 255.255.255.248
ip nat outside
speed 100
no negotiation auto
crypto map Cliente
ip virtual-reassembly
!
interface GigabitEthernet0/0/1
description LAN-CLIENTE
ip address 192.168.2.2 255.255.255.0 secondary
ip address 190.8.135.209 255.255.255.252 secondary
ip address 200.31.111.182 255.255.255.252
ip nat inside
load-interval 30
negotiation auto
!
router bgp 65000
bgp router-id 10.28.45.226
bgp log-neighbor-changes
neighbor 10.28.45.225 remote-as 19180
neighbor 10.28.45.225 timers 20 60
neighbor 10.28.45.227 remote-as 19180
neighbor 10.28.45.227 timers 20 60
!
address-family ipv4
network 190.8.135.208 mask 255.255.255.252
network 200.31.111.180 mask 255.255.255.252
redistribute connected
neighbor 10.28.45.225 activate
neighbor 10.28.45.225 soft-reconfiguration inbound
neighbor 10.28.45.225 route-map LOCAL-PREF-200 in
neighbor 10.28.45.227 activate
neighbor 10.28.45.227 soft-reconfiguration inbound
exit-address-family
!
ip nat inside source static tcp 192.168.2.11 1432 200.31.111.182 1432 extendable
ip nat inside source static udp 192.168.2.11 1432 200.31.111.182 1432 extendable
ip nat inside source static udp 192.168.2.11 1433 200.31.111.182 1433 extendable
ip nat inside source static tcp 192.168.2.11 1434 200.31.111.182 1434 extendable
ip nat inside source list 199 interface GigabitEthernet0/0/1 overload
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
ip route 0.0.0.0 0.0.0.0 10.28.45.225
ip tacacs source-interface GigabitEthernet0/0/0
!
ip ssh version 2
!
access-list 1 permit 192.168.1.0 0.0.0.255
access-list 100 permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
access-list 100 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 150 permit ip 192.168.2.0 0.0.0.255 10.19.72.0 0.0.0.255
access-list 199 deny ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
access-list 199 deny ip 192.168.2.0 0.0.0.255 10.19.72.0 0.0.0.255
access-list 199 permit ip 192.168.2.0 0.0.0.255 any
!
!
snmp-server community Am3r1c4t3L.1577 RO
snmp-server location JIRON JOSE MANUEL ITURREGUI NRO. 631 (SURQUILLO - LIMA - LIMA)
tacacs-server host 190.187.252.88 key 7 071B754F1A0A0A243A265A55537D
!
!
!
!
control-plane
!
banner login ^CC
********************************************************************************

*********
ACCESO RESTRINGIDO - SOLO PERSONAL AUTORIZADO
********************************************************************************

*********
^C
!
line con 0
session-timeout 5
password 7 104A000F00181E020201
transport input none
-More--
*
*
* Line timeout expired
*
stopbits 1
line vty 0 4
transport input ssh
!
wsma agent exec
!
wsma agent config
!
wsma agent filesys
!
wsma agent notify
!
!
end

GERMANIA_DBI-S355909#
GERMANIA_DBI-S355909 con0 is now available

Press RETURN to get started.

C
********************************************************************************

*********
ACCESO RESTRINGIDO - SOLO PERSONAL AUTORIZADO
********************************************************************************

*********

User Access Verification (Policy Manag