# Huawei Versatile Routing Platform Software # VRP (R) software, Version 8.230 (NetEngine 8000 V800R023C00SPC500) # Copyright (C) 2012-2023 Huawei Technologies Co., Ltd. # Patch Version: V800R023SPH120 # NetEngine 8000 F1A-8H20Q's Device status: # ------------------------------------------------------------------------------- # Slot # Type Online Register Status Role LsId Primary # ------------------------------------------------------------------------------- # 1 IPU Present Registered Normal MMB 0 Master # 2 PWR Present Registered Normal OTHER 0 NA # 3 PWR Present Registered Normal OTHER 0 NA # 4 FAN Present Registered Normal OTHER 0 NA # 5 FAN Present Registered Normal OTHER 0 NA # 6 FAN Present Registered Normal OTHER 0 NA # 7 FAN Present Registered Normal OTHER 0 NA # 9 CLK Present Registered Normal OTHER 0 Master # ------------------------------------------------------------------------------- !Software Version V800R023C00SPC500 !Last configuration was updated at 2024-08-25 20:03:32-03:00 by jeffrey !Last configuration was saved at 2024-08-23 16:40:59-03:00 by jeffrey !kms_feature -- # sysname SE77E-BGP-F1A-CT # undo FTP server-source all-interface undo FTP ipv6 server-source all-interface # service-template template-default0 # service-template template-default1 # service-template template-default2 # service-template template-default3 # service-template template-default4 # ntp-service server source-interface all disable ntp-service ipv6 server source-interface all disable # undo icmp name timestamp-reply send # router id 143.0.252.1 # as-notation plain # ip netstream as-mode 32 ip netstream timeout active 1 ip netstream timeout inactive 15 ip netstream export version 9 origin-as bgp-nexthop ttl ip netstream export template sequence-number fixed ip netstream export index-switch 32 ip netstream export template timeout-rate 1 ip netstream sampler fix-packets 1024 inbound ip netstream sampler fix-packets 1024 outbound ip netstream export source 10.0.0.1 ip netstream export host 143.0.252.52 2065 ip netstream export host 143.0.252.42 3055 ip netstream export template option sampler ip netstream export template option timeout-rate 1 ip netstream export template option application-label # ipv6 netstream as-mode 32 ipv6 netstream timeout active 1 ipv6 netstream timeout inactive 15 ipv6 netstream export version 9 origin-as bgp-nexthop ttl ipv6 netstream export template sequence-number fixed ipv6 netstream export index-switch 32 ipv6 netstream export template timeout-rate 1 ipv6 netstream sampler fix-packets 1024 inbound ipv6 netstream sampler fix-packets 1024 outbound ipv6 netstream export source 10.0.0.1 ipv6 netstream export host 143.0.252.52 2065 ipv6 netstream export host 143.0.252.42 3055 ipv6 netstream export template option sampler ipv6 netstream export template option timeout-rate 1 # undo telnet server-source all-interface undo telnet ipv6 server-source all-interface # mpls lsr-id 10.0.0.1 # mpls mpls te mpls rsvp-te mpls te cspf # mpls l2vpn # mpls ldp # ipv4-family # dhcp server request-packet all-interface disable # acl ip-pool ORIGEM_LIBERADA ip address 143.0.252.0 0.0.3.255 ip address 38.191.124.0 0.0.3.255 ip address 205.164.78.0 0.0.1.255 ip address 177.75.48.147 0.0.0.0 # acl ip-pool PERMITE_SERVICE_PORTS ip address 143.0.255.120 0.0.0.0 ip address 143.0.254.170 0.0.0.0 ip address 143.0.253.13 0.0.0.0 ip address 143.0.254.106 0.0.0.0 ip address 143.0.255.31 0.0.0.0 ip address 143.0.253.52 0.0.0.0 ip address 143.0.253.27 0.0.0.0 ip address 143.0.253.118 0.0.0.0 ip address 205.164.78.3 0.0.0.0 ip address 143.0.255.179 0.0.0.0 ip address 143.0.255.32 0.0.0.0 ip address 143.0.255.34 0.0.0.0 ip address 143.0.253.87 0.0.0.0 ip address 143.0.254.78 0.0.0.0 ip address 143.0.253.69 0.0.0.0 ip address 143.0.255.136 0.0.0.0 ip address 143.0.254.76 0.0.0.0 ip address 143.0.255.145 0.0.0.0 ip address 143.0.255.190 0.0.0.0 ip address 143.0.255.189 0.0.0.0 ip address 143.0.255.135 0.0.0.0 ip address 143.0.254.77 0.0.0.0 ip address 143.0.253.66 0.0.0.0 ip address 143.0.253.76 0.0.0.0 ip address 143.0.255.17 0.0.0.0 ip address 143.0.255.10 0.0.0.0 ip address 143.0.253.47 0.0.0.0 ip address 143.0.254.123 0.0.0.0 ip address 143.0.255.144 0.0.0.0 ip address 143.0.255.140 0.0.0.0 ip address 143.0.253.29 0.0.0.0 ip address 143.0.255.132 0.0.0.0 ip address 143.0.254.92 0.0.0.0 ip address 143.0.254.104 0.0.0.0 ip address 143.0.253.91 0.0.0.0 ip address 143.0.253.89 0.0.0.0 ip address 143.0.254.131 0.0.0.0 ip address 143.0.254.130 0.0.0.0 ip address 143.0.255.173 0.0.0.0 ip address 143.0.255.149 0.0.0.0 ip address 143.0.255.148 0.0.0.0 ip address 143.0.255.134 0.0.0.0 ip address 143.0.255.133 0.0.0.0 ip address 143.0.253.70 0.0.0.0 ip address 143.0.253.107 0.0.0.0 ip address 143.0.255.3 0.0.0.0 ip address 143.0.253.67 0.0.0.0 ip address 143.0.253.126 0.0.0.0 ip address 143.0.254.70 0.0.0.0 ip address 143.0.255.137 0.0.0.0 ip address 143.0.254.119 0.0.0.0 ip address 143.0.254.178 0.0.0.0 ip address 143.0.253.189 0.0.0.0 ip address 143.0.255.37 0.0.0.0 # acl ip-pool PERMITE_SERVICE_PORTS_SRV ip address 143.0.252.13 0.0.0.0 ip address 143.0.252.16 0.0.0.0 ip address 143.0.252.15 0.0.0.0 ip address 143.0.252.25 0.0.0.0 ip address 143.0.252.26 0.0.0.0 ip address 143.0.252.34 0.0.0.0 ip address 143.0.252.54 0.0.0.0 ip address 143.0.252.152 0.0.0.0 ip address 143.0.252.96 0.0.0.15 ip address 143.0.252.22 0.0.0.0 ip address 143.0.255.104 0.0.0.0 ip address 143.0.252.50 0.0.0.0 ip address 143.0.252.21 0.0.0.0 ip address 143.0.252.10 0.0.0.0 ip address 143.0.252.20 0.0.0.0 ip address 143.0.252.30 0.0.0.0 # acl ip-pool PREFIXO_PUBLICO ip address 143.0.252.0 0.0.0.255 ip address 143.0.253.0 0.0.0.255 ip address 143.0.254.0 0.0.0.255 ip address 143.0.255.0 0.0.0.255 ip address 38.191.124.0 0.0.0.255 ip address 38.191.125.0 0.0.0.255 ip address 38.191.126.0 0.0.0.255 ip address 38.191.127.0 0.0.0.255 ip address 205.164.78.0 0.0.0.255 ip address 205.164.79.0 0.0.0.255 # acl ipv6-pool ORIGEM_LIBERADA_V6 ipv6 address 2804:2994:: 32 # acl ipv6-pool PERMITE_SERVICE_PORTS_SRV_V6 ipv6 address 2804:2994:77:77A:: 64 ipv6 address 2804:2994:77::22 128 ipv6 address 2804:2994:77::50 128 ipv6 address 2804:2994:77::21 128 # acl ipv6-pool PERMITE_SERVICE_PORTS_V6 # acl ipv6-pool PREFIXO_PUBLICO_V6 ipv6 address 2804:2994:: 32 # acl port-pool SERVICE_PORTS eq 2277 eq 2377 eq 8077 eq 8291 lt 1024 # acl number 2001 description RESTRICAO_ACESSO_VTY rule 10 permit source 143.0.255.104 0.0.0.3 rule 11 permit source 143.0.253.15 0 rule 12 permit source 143.0.252.1 0 rule 13 permit source 143.0.252.21 0 rule 14 permit source 10.7.7.99 0 # acl number 2061 description RESTRICAO_ACESSO_SNMP rule 10 permit source 10.0.0.0 0.255.255.255 rule 11 permit source 172.0.0.0 0.63.255.255 rule 12 permit source 192.168.0.0 0.0.255.255 rule 13 permit source 143.0.252.0 0.0.3.255 # acl name ACL_SERVICE_PORTS advance rule 18 permit tcp destination-pool PERMITE_SERVICE_PORTS_SRV rule 19 permit udp destination-pool PERMITE_SERVICE_PORTS_SRV rule 20 permit tcp destination-pool PERMITE_SERVICE_PORTS rule 21 permit udp destination-pool PERMITE_SERVICE_PORTS rule 90 permit tcp source-pool ORIGEM_LIBERADA rule 91 permit udp source-pool ORIGEM_LIBERADA rule 200 deny tcp destination-pool PREFIXO_PUBLICO destination-port-pool SERVICE_PORTS rule 201 deny udp destination-pool PREFIXO_PUBLICO destination-port-pool SERVICE_PORTS # acl ipv6 number 2061 description RESTRICAO_ACESSO_SNMP rule 10 permit source 2804:2994::/32 # acl ipv6 name ACL_SERVICE_PORTS_V6 advance rule 18 permit tcp destination-pool PERMITE_SERVICE_PORTS_SRV_V6 rule 19 permit udp destination-pool PERMITE_SERVICE_PORTS_SRV_V6 rule 20 permit tcp destination-pool PERMITE_SERVICE_PORTS_V6 rule 21 permit udp destination-pool PERMITE_SERVICE_PORTS_V6 rule 90 permit tcp source-pool ORIGEM_LIBERADA_V6 rule 91 permit udp source-pool ORIGEM_LIBERADA_V6 rule 200 deny tcp destination-pool PREFIXO_PUBLICO_V6 destination-port lt 1024 rule 201 deny udp destination-pool PREFIXO_PUBLICO_V6 destination-port lt 1024 rule 202 deny tcp destination-pool PREFIXO_PUBLICO_V6 destination-port eq 8291 rule 203 deny udp destination-pool PREFIXO_PUBLICO_V6 destination-port eq 8291 rule 204 deny tcp destination-pool PREFIXO_PUBLICO_V6 destination-port eq 8077 rule 205 deny udp destination-pool PREFIXO_PUBLICO_V6 destination-port eq 8077 rule 206 deny tcp destination-pool PREFIXO_PUBLICO_V6 destination-port eq 2277 rule 207 deny udp destination-pool PREFIXO_PUBLICO_V6 destination-port eq 2277 rule 208 deny tcp destination-pool PREFIXO_PUBLICO_V6 destination-port eq 2377 rule 209 deny udp destination-pool PREFIXO_PUBLICO_V6 destination-port eq 2377 # traffic classifier CLASS-SERVICE_PORTS operator or if-match acl name ACL_SERVICE_PORTS precedence 1 # traffic classifier CLASS-SERVICE_PORTS_V6 operator or if-match ipv6 acl name ACL_SERVICE_PORTS_V6 precedence 1 # traffic behavior BEH-SERVICE_PORTS # traffic behavior BEH-SERVICE_PORTS_V6 # traffic policy POLICY-SERVICE-PORTS undo share-mode statistics enable classifier CLASS-SERVICE_PORTS behavior BEH-SERVICE_PORTS precedence 1 classifier CLASS-SERVICE_PORTS_V6 behavior BEH-SERVICE_PORTS_V6 precedence 2 # aaa local-user jeffrey password irreversible-cipher $1c$zV%t6G5fMD$i]Kc)}M@.-{g@;3d/gg>]TLLA8`Cq=nrZd*Hmgz)$ local-user jeffrey service-type ftp telnet ssh local-user jeffrey level 3 local-user jeffrey state block fail-times 3 interval 5 local-user bruna.noc password irreversible-cipher $1c$=tL%Aie\GQ$Hn}J$`Xb$12\E:Y[F&>G;{7TO6*#;9GB]HO<,:JC$ local-user bruna.noc service-type ftp telnet ssh http local-user bruna.noc level 3 local-user bruna.noc state block fail-times 3 interval 5 local-user lookingglass password irreversible-cipher $1c$Tl"OK=ETgQ$4^y%~9aH":")p#D,5$>y6<%/R6U(^<4^UqNs\HP45tVgi'aO~pu[=-)~d)$ local-user oxidized service-type ssh local-user oxidized level 3 local-user oxidized state active # authentication-scheme default0 # authentication-scheme default1 # authentication-scheme default authentication-mode local # authorization-scheme default # accounting-scheme default0 # accounting-scheme default1 # domain default0 # domain default1 # domain default_admin # ospfv3 1 router-id 10.0.0.1 import-route static default-route-advertise always area 0.0.0.0 # interface GigabitEthernet0/0/0 undo shutdown # interface 100GE0/1/48.10 vlan-type dot1q 10 description VLAN-10-VM's ipv6 enable ip address 143.0.252.1 255.255.255.192 ip address 10.7.7.97 255.255.255.224 sub ip address 10.7.7.129 255.255.255.240 sub ipv6 address 2804:2994:77::1/64 statistic enable ospfv3 1 area 0.0.0.0 # interface 100GE0/1/48.50 vlan-type dot1q 50 description VLAN-50-OCA ipv6 enable ip address 143.0.252.89 255.255.255.252 ipv6 address 2804:2994:77:77::1/64 statistic enable ip netstream inbound ip netstream outbound ipv6 netstream inbound ipv6 netstream outbound # interface 100GE0/1/48.60 vlan-type dot1q 60 description VLAN-60-GGC ipv6 enable ip address 143.0.252.97 255.255.255.240 ipv6 address 2804:2994:77:77A::1/64 statistic enable ip netstream inbound ip netstream outbound ipv6 netstream inbound ipv6 netstream outbound # interface 100GE0/1/48.421 vlan-type dot1q 421 description VLAN-421-SRV-CT-V6 ipv6 enable ipv6 address FC00::99/125 ospfv3 1 area 0.0.0.0 ospfv3 network-type p2p # interface 100GE0/1/48.600 vlan-type dot1q 600 description VLAN-600-G8-IP ipv6 enable ip address 179.96.90.194 255.255.255.252 ipv6 address 2804:39C:F002::29E/126 statistic enable traffic-policy POLICY-SERVICE-PORTS inbound ip netstream inbound ip netstream outbound ipv6 netstream inbound ipv6 netstream outbound binding tunnel gre # interface 100GE0/1/48.700 vlan-type dot1q 700 description VLAN-700-SW-HW-GR-L3 ip address 10.0.77.13 255.255.255.252 statistic enable ospf network-type p2p # interface 100GE0/1/48.1200 vlan-type dot1q 1200 description VLAN-1200-GCA-DF ipv6 enable ip address 143.0.252.78 255.255.255.252 ipv6 address 2804:2994:77:77C::2/126 statistic enable arp expire-time 14400 ip netstream inbound ip netstream outbound ipv6 netstream inbound ipv6 netstream outbound arp rate-limit 0 # interface 100GE0/1/48.1601 vlan-type dot1q 1601 description VLAN-1601-UPX-IX ipv6 enable ip address 10.177.129.129 255.255.255.254 ipv6 address 2804:2870:1:C11E::129:129/127 statistic enable traffic-policy POLICY-SERVICE-PORTS inbound # interface 100GE0/1/48.1700 vlan-type dot1q 1700 description VLAN-1700-PTT-IX-DF-V4 ip address 200.192.110.148 255.255.255.0 statistic enable traffic-policy POLICY-SERVICE-PORTS inbound arp expire-time 14400 ip netstream inbound ip netstream outbound arp rate-limit 0 # interface 100GE0/1/48.1701 vlan-type dot1q 1701 description VLAN-1701-PTT-IX-DF-V6 ipv6 enable ipv6 address 2001:12F8:0:13::148/64 statistic enable traffic-policy POLICY-SERVICE-PORTS inbound arp expire-time 14400 ipv6 netstream inbound ipv6 netstream outbound arp rate-limit 0 # interface 100GE0/1/48.2004 vlan-type dot1q 2004 description VLAN-2004-iBGP-V4 ip address 10.7.7.5 255.255.255.252 statistic enable ospf network-type p2p ip netstream inbound ip netstream outbound # interface 100GE0/1/48.2006 vlan-type dot1q 2006 description VLAN-2006-iBGP-V6 ipv6 enable ipv6 address FC00::9/125 statistic enable ospfv3 1 area 0.0.0.0 ospfv3 network-type p2p ipv6 netstream inbound ipv6 netstream outbound # interface 100GE0/1/48.2400 vlan-type dot1q 2400 description VLAN-2400-CGNAT-V4 ip address 10.7.7.21 255.255.255.252 statistic enable ospf network-type p2p # interface 100GE0/1/48.2406 vlan-type dot1q 2406 description VLAN-2406-CHINA-TELECOM ipv6 enable ip address 218.30.37.210 255.255.255.252 ipv6 address 2804:1E48::1122/126 statistic enable traffic-policy POLICY-SERVICE-PORTS inbound ip netstream inbound ip netstream outbound ipv6 netstream inbound ipv6 netstream outbound # interface 100GE0/1/48.2502 vlan-type dot1q 2502 description VLAN-2502-IX-SP-V4 ip address 187.16.215.245 255.255.240.0 statistic enable traffic-policy POLICY-SERVICE-PORTS inbound arp expire-time 14400 ip netstream inbound ip netstream outbound arp rate-limit 0 # interface 100GE0/1/48.2503 vlan-type dot1q 2503 description VLAN-2503-IX-SP-V6 ipv6 enable ipv6 address 2001:12F8::215:245/64 statistic enable traffic-policy POLICY-SERVICE-PORTS inbound arp expire-time 14400 ipv6 netstream inbound ipv6 netstream outbound arp rate-limit 0 # interface 100GE0/1/48.2600 vlan-type dot1q 2600 description VLAN-2600-CGNAT-V6 ipv6 enable ipv6 address FC00::1/125 ospfv3 1 area 0.0.0.0 ospfv3 network-type p2p # interface 100GE0/1/48.3025 vlan-type dot1q 3025 description VLAN-3025-OPENCDN-DF ipv6 enable ip address 168.181.23.51 255.255.255.254 ipv6 address 2801:80:17B1::23:51/127 statistic enable ip netstream inbound ip netstream outbound ipv6 netstream inbound ipv6 netstream outbound # interface 100GE0/1/48.3783 vlan-type dot1q 3783 mtu 1500 description VLAN-3783-IX-HUGE ipv6 enable ip address 10.188.56.2 255.255.255.252 ipv6 address 2804:1E20:AAA1:409::B/80 statistic enable # interface LoopBack0 description loopback-privada ip address 10.0.0.1 255.255.255.255 # interface LoopBack1 description loopback-publica ipv6 enable ip address 143.0.252.152 255.255.255.255 ipv6 address 2804:2994:400::1/128 ospfv3 1 area 0.0.0.0 # interface LoopBack2 ipv6 enable ip address 10.0.0.250 255.255.255.255 ipv6 address FC00::19/125 ospfv3 1 area 0.0.0.0 # interface Virtual-Ethernet0/1/21.400 vlan-type dot1q 400 description VLAN-400-BGN-CT-V4 ip address 10.7.7.13 255.255.255.252 statistic enable ospf network-type p2p # interface Virtual-Ethernet0/1/21.401 vlan-type dot1q 401 description VLAN-401-BGN-CT-V6 ipv6 enable ipv6 address auto link-local ipv6 mtu 1480 statistic enable ospfv3 1 area 0.0.0.0 ospfv3 network-type p2p ipv6 netstream inbound ipv6 netstream outbound # interface Tunnel10 description Tunnel-HUGE-G8-V6 ipv6 enable ip address 10.195.38.2 255.255.255.252 ipv6 address 2804:1E20:AAA1:B0::B/80 ipv6 address 2804:1E20:AAA1:1FF::B/80 tunnel-protocol gre ipv6 source 2804:39C:F002::29E destination 2804:1E20:11:A::1FF # interface Tunnel11 description Tunnel-UPX-G8-V6 ipv6 enable ip address 10.177.129.245 255.255.255.254 tunnel-protocol gre ipv6 source 2804:39C:F002::29E destination 2804:2870:1:100::11 # interface NULL0 # bgp 264023 undo check-first-as private-4-byte-as enable peer 10.0.0.2 as-number 264023 peer 10.0.0.2 description VLAN-2004-iBGP-V4 peer 10.0.0.10 as-number 264023 peer 10.0.0.10 description WANGUARD-MITIGAR peer 10.0.0.10 connect-interface LoopBack2 10.0.0.250 peer 10.188.56.1 as-number 264409 peer 10.188.56.1 description VLAN-3783-IX-HUGE peer 143.0.252.52 as-number 264023 peer 143.0.252.52 description EXBGP-FLOW peer 143.0.252.52 connect-interface LoopBack0 10.0.0.1 peer 179.96.90.193 as-number 28329 peer 179.96.90.193 description VLAN-600-G8-IP peer 187.16.216.252 as-number 20121 peer 187.16.216.252 description lgc.saopaulo.sp.ix.br peer 187.16.216.252 ebgp-max-hop 255 peer 187.16.216.252 check-first-as disable peer 187.16.216.253 as-number 26162 peer 187.16.216.253 description rs1.saopaulo.sp.ix.br peer 187.16.216.253 ebgp-max-hop 255 peer 187.16.216.253 check-first-as disable peer 187.16.216.254 as-number 26162 peer 187.16.216.254 description rs2.saopaulo.sp.ix.br peer 187.16.216.254 ebgp-max-hop 255 peer 187.16.216.254 check-first-as disable peer 218.30.37.209 as-number 23764 peer 218.30.37.209 description VLAN-2406-CHINA-TELECOM peer 218.30.37.209 connect-interface 100GE0/1/48.2406 peer 2001:12F8::252 as-number 20121 peer 2001:12F8::252 description lgc.saopaulo.sp.ix.br peer 2001:12F8::252 ebgp-max-hop 255 peer 2001:12F8::252 check-first-as disable peer 2001:12F8::253 as-number 26162 peer 2001:12F8::253 description rs1.saopaulo.sp.ix.br peer 2001:12F8::253 ebgp-max-hop 255 peer 2001:12F8::253 check-first-as disable peer 2001:12F8::254 as-number 26162 peer 2001:12F8::254 description rs2.saopaulo.sp.ix.br peer 2001:12F8::254 ebgp-max-hop 255 peer 2001:12F8::254 check-first-as disable peer 2804:39C:F002::29D as-number 28329 peer 2804:39C:F002::29D description VLAN-600-G8-IP peer 2804:1E20:AAA1:409::A as-number 264409 peer 2804:1E20:AAA1:409::A description VLAN-3783-IX-HUGE peer 2804:1E48::1121 as-number 23764 peer 2804:1E48::1121 description VLAN-2406-CHINA-TELECOM peer 2804:1E48::1121 connect-interface 100GE0/1/48.2406 peer 2804:2870:1:C11E::129:128 as-number 52863 peer 2804:2994:77::52 as-number 264023 peer 2804:2994:77::52 description EXBGP-FLOW peer 2804:2994:77::52 connect-interface LoopBack1 2804:2994:400::1 peer 2804:2994:77:77C::1 as-number 28604 peer 2804:2994:77:77C::1 description VLAN-1200-GLOBO-DF peer FC00::A as-number 264023 peer FC00::A description VLAN-2006-iBGP-V6 peer FC00::29 as-number 264023 peer FC00::29 description WANGUARD-MITIGAR peer FC00::29 connect-interface LoopBack2 FC00::19 group CDN-V4 external peer 143.0.252.77 as-number 28604 peer 143.0.252.77 group CDN-V4 peer 143.0.252.77 description VLAN-1200-GLOBO-DF peer 143.0.252.90 as-number 40027 peer 143.0.252.90 group CDN-V4 peer 143.0.252.90 description NETFLIX-OCA-V4 peer 143.0.252.90 connect-interface 143.0.252.89 peer 143.0.252.110 as-number 11344 peer 143.0.252.110 group CDN-V4 peer 143.0.252.110 description GOOGLE-GGC-V4 peer 143.0.252.110 password cipher %^%#>[3d4'p_~5Su"5;]3_1(XfqBQbw:sEE^YLC.#{HH%^%# peer 168.181.23.50 as-number 61580 peer 168.181.23.50 group CDN-V4 peer 168.181.23.50 description VLAN-3025-OPENCDN-DF group CDN-V6 external peer 2801:80:17B1::23:50 as-number 61580 peer 2801:80:17B1::23:50 group CDN-V6 peer 2801:80:17B1::23:50 description VLAN-3025-OPENCDN peer 2804:2994:77:77::2 as-number 40027 peer 2804:2994:77:77::2 group CDN-V6 peer 2804:2994:77:77::2 description NETFLIX-OCA-V6 peer 2804:2994:77:77A::FFFE as-number 11344 peer 2804:2994:77:77A::FFFE group CDN-V6 peer 2804:2994:77:77A::FFFE description GOOGLE-GGC-V6 peer 2804:2994:77:77A::FFFE password cipher %^%#Du~^PQeF-FyL[z'LHYv5`!:C&(3j}$0wZ10a(P[,%^%# group HUGE-V4 external peer HUGE-V4 as-number 264409 peer 10.195.38.1 as-number 264409 peer 10.195.38.1 group HUGE-V4 peer 10.195.38.1 description Tunnel-HUGE-G8-V6 group HUGE-V6 external peer 2804:1E20:AAA1:1FF::A as-number 264409 peer 2804:1E20:AAA1:1FF::A group HUGE-V6 peer 2804:1E20:AAA1:1FF::A description Tunnel-HUGE-G8-V6 group PEERING-V4 external peer PEERING-V4 ebgp-max-hop 255 peer PEERING-V4 connect-interface 100GE0/1/48.2502 peer 187.16.213.181 as-number 714 peer 187.16.213.181 group PEERING-V4 peer 187.16.213.181 description PEERING-AS714-APPLE peer 187.16.213.182 as-number 714 peer 187.16.213.182 group PEERING-V4 peer 187.16.213.182 description PEERING-AS714-APPLE peer 200.192.110.10 as-number 20940 peer 200.192.110.10 group PEERING-V4 peer 200.192.110.10 description PEERING-IX-DF-AKAMAI-V4 peer 200.192.110.10 connect-interface 100GE0/1/48.1700 group PEERING-V6 external peer PEERING-V6 ebgp-max-hop 255 peer PEERING-V6 connect-interface 100GE0/1/48.2503 peer 2001:12F8::213:181 as-number 714 peer 2001:12F8::213:181 group PEERING-V6 peer 2001:12F8::213:181 description PEERING-AS714-APPLE peer 2001:12F8::213:182 as-number 714 peer 2001:12F8::213:182 group PEERING-V6 peer 2001:12F8::213:182 description PEERING-AS714-APPLE group PTT-IX-DF-V4 external peer PTT-IX-DF-V4 as-number 26162 peer 200.192.110.252 as-number 20121 peer 200.192.110.252 group PTT-IX-DF-V4 peer 200.192.110.252 description LG.DF.IX.BR peer 200.192.110.253 as-number 26162 peer 200.192.110.253 group PTT-IX-DF-V4 peer 200.192.110.254 as-number 26162 peer 200.192.110.254 group PTT-IX-DF-V4 group PTT-IX-DF-V6 external peer PTT-IX-DF-V6 as-number 26162 peer 2001:12F8:0:13::252 as-number 20121 peer 2001:12F8:0:13::252 group PTT-IX-DF-V6 peer 2001:12F8:0:13::252 description LG.DF.IX.BR peer 2001:12F8:0:13::253 as-number 26162 peer 2001:12F8:0:13::253 group PTT-IX-DF-V6 peer 2001:12F8:0:13::254 as-number 26162 peer 2001:12F8:0:13::254 group PTT-IX-DF-V6 group PTT-IX-SP-V4 external group PTT-IX-SP-V6 external group UPX-V4 external peer 10.177.129.128 as-number 52863 peer 10.177.129.128 group UPX-V4 peer 10.177.129.128 description VLAN-1601-UPX-IX peer 10.177.129.244 as-number 52863 peer 10.177.129.244 group UPX-V4 peer 10.177.129.244 description Tunnel-UPX-via-G8 group UPX-V6 external # ipv4-family unicast undo synchronization preference 20 200 255 network 38.191.124.0 255.255.252.0 network 38.191.124.0 255.255.254.0 network 38.191.124.0 255.255.255.0 network 38.191.124.0 255.255.255.128 network 38.191.124.128 255.255.255.128 network 38.191.125.0 255.255.255.0 network 38.191.125.0 255.255.255.128 network 38.191.125.128 255.255.255.128 network 38.191.126.0 255.255.254.0 network 38.191.126.0 255.255.255.0 network 38.191.126.0 255.255.255.128 network 38.191.126.128 255.255.255.128 network 38.191.127.0 255.255.255.0 network 38.191.127.0 255.255.255.128 network 38.191.127.128 255.255.255.128 network 143.0.252.0 255.255.252.0 network 143.0.252.0 255.255.254.0 network 143.0.252.0 255.255.255.0 network 143.0.252.0 255.255.255.128 network 143.0.252.128 255.255.255.128 network 143.0.253.0 255.255.255.0 network 143.0.253.0 255.255.255.128 network 143.0.253.128 255.255.255.128 network 143.0.254.0 255.255.254.0 network 143.0.254.0 255.255.255.0 network 143.0.254.0 255.255.255.128 network 143.0.254.128 255.255.255.128 network 143.0.255.0 255.255.255.0 network 143.0.255.0 255.255.255.128 network 143.0.255.128 255.255.255.128 network 205.164.78.0 255.255.254.0 network 205.164.78.0 255.255.255.0 network 205.164.78.0 255.255.255.128 network 205.164.78.128 255.255.255.128 network 205.164.79.0 255.255.255.0 network 205.164.79.0 255.255.255.128 network 205.164.79.128 255.255.255.128 ext-community-change enable prefix origin-validation enable bestroute origin-as-validation allow-invalid undo peer CDN-V6 enable undo peer PTT-IX-DF-V6 enable undo peer PEERING-V6 enable peer 10.0.0.2 enable peer 10.0.0.2 next-hop-local peer 10.0.0.2 advertise-community peer 10.0.0.2 advertise-large-community peer 10.0.0.2 advertise-ext-community peer 10.0.0.10 enable peer 10.0.0.10 route-policy WANGUARD-IN import peer 10.0.0.10 route-policy DROP-ALL export peer 10.0.0.10 reflect-client peer 10.0.0.10 next-hop-local peer 10.0.0.10 advertise-community peer 10.0.0.10 advertise-large-community peer 10.0.0.10 advertise-ext-community peer 143.0.252.52 enable peer 143.0.252.52 route-policy ACCEPT-ALL import peer 143.0.252.52 route-policy DROP-ALL export peer 143.0.252.52 reflect-client peer 143.0.252.52 advertise-community peer 143.0.252.52 advertise-large-community peer 143.0.252.52 advertise-ext-community peer 179.96.90.193 enable peer 179.96.90.193 route-policy G8-V4-IN import peer 179.96.90.193 route-policy G8-V4-OUT export peer 179.96.90.193 advertise-community peer 179.96.90.193 advertise-large-community peer 179.96.90.193 advertise-ext-community peer 218.30.37.209 enable peer 218.30.37.209 route-policy CHINA-TELECOM-V4-IN import peer 218.30.37.209 route-policy CHINA-TELECOM-V4-OUT export peer 218.30.37.209 advertise-community peer 218.30.37.209 advertise-large-community peer 218.30.37.209 advertise-ext-community peer CDN-V4 enable peer CDN-V4 route-policy DROP-ALL import peer CDN-V4 route-policy CDN-V4-OUT export peer CDN-V4 advertise-community peer CDN-V4 advertise-ext-community peer CDN-V4 advertise-large-community peer 143.0.252.77 enable peer 143.0.252.77 group CDN-V4 peer 143.0.252.90 enable peer 143.0.252.90 group CDN-V4 peer 143.0.252.110 enable peer 143.0.252.110 group CDN-V4 peer 168.181.23.50 enable peer 168.181.23.50 group CDN-V4 peer 168.181.23.50 route-policy OPENCDN-V4-IN import peer 168.181.23.50 route-policy OPENCDN-V4-OUT export peer HUGE-V4 enable peer HUGE-V4 route-policy DROP-ALL import peer HUGE-V4 route-policy HUGE-OUT export peer HUGE-V4 advertise-community peer HUGE-V4 advertise-ext-community peer HUGE-V4 keep-all-routes peer 10.188.56.1 enable peer 10.188.56.1 group HUGE-V4 peer 10.195.38.1 enable peer 10.195.38.1 group HUGE-V4 peer HUGE-V6 enable peer PEERING-V4 enable peer PEERING-V4 route-policy PEERING-V4-IN import peer PEERING-V4 route-policy PEERING-V4-OUT export peer PEERING-V4 advertise-community peer PEERING-V4 advertise-ext-community peer 187.16.213.181 enable peer 187.16.213.181 group PEERING-V4 peer 187.16.213.182 enable peer 187.16.213.182 group PEERING-V4 peer 200.192.110.10 enable peer 200.192.110.10 group PEERING-V4 peer PTT-IX-DF-V4 enable peer PTT-IX-DF-V4 route-policy PTT-IX-DF-V4-IN import peer PTT-IX-DF-V4 route-policy PTT-IX-DF-V4-OUT export peer PTT-IX-DF-V4 advertise-community peer PTT-IX-DF-V4 advertise-ext-community peer PTT-IX-DF-V4 advertise-large-community peer 200.192.110.252 enable peer 200.192.110.252 group PTT-IX-DF-V4 peer 200.192.110.253 enable peer 200.192.110.253 group PTT-IX-DF-V4 peer 200.192.110.254 enable peer 200.192.110.254 group PTT-IX-DF-V4 peer PTT-IX-SP-V4 enable peer PTT-IX-SP-V4 route-policy PTT-SP-V4-IN import peer PTT-IX-SP-V4 route-policy PTT-SP-V4-OUT export peer PTT-IX-SP-V4 advertise-community peer PTT-IX-SP-V4 advertise-ext-community peer PTT-IX-SP-V4 advertise-large-community peer 187.16.216.252 enable peer 187.16.216.252 group PTT-IX-SP-V4 peer 187.16.216.253 enable peer 187.16.216.253 group PTT-IX-SP-V4 peer 187.16.216.254 enable peer 187.16.216.254 group PTT-IX-SP-V4 peer PTT-IX-SP-V6 enable peer UPX-V4 enable peer UPX-V4 route-policy DROP-ALL import peer UPX-V4 route-policy UPX-V4-OUT export peer UPX-V4 advertise-community peer UPX-V4 advertise-ext-community peer UPX-V4 advertise-large-community peer 10.177.129.128 enable peer 10.177.129.128 group UPX-V4 peer 10.177.129.128 route-policy UPX-PTT-V4-OUT export peer 10.177.129.244 enable peer 10.177.129.244 group UPX-V4 peer UPX-V6 enable # ipv4-family flow route match-destination peer 143.0.252.52 enable peer 143.0.252.52 redirect ip rfc-compatible peer 143.0.252.52 route-policy ACCEPT-ALL import peer 143.0.252.52 route-policy DROP-ALL export peer 143.0.252.52 reflect-client peer 143.0.252.52 advertise-community peer 143.0.252.52 advertise-large-community peer 143.0.252.52 validation-disable route validation-mode include-as # ipv6-family unicast undo synchronization preference 20 200 255 network 2804:2994:: 32 network 2804:2994:: 33 network 2804:2994:: 34 network 2804:2994:: 35 network 2804:2994:: 36 network 2804:2994:1000:: 36 network 2804:2994:2000:: 35 network 2804:2994:2000:: 36 network 2804:2994:3000:: 36 network 2804:2994:4000:: 34 network 2804:2994:4000:: 35 network 2804:2994:4000:: 36 network 2804:2994:5000:: 36 network 2804:2994:6000:: 35 network 2804:2994:6000:: 36 network 2804:2994:7000:: 36 network 2804:2994:8000:: 33 network 2804:2994:8000:: 34 network 2804:2994:8000:: 35 network 2804:2994:8000:: 36 network 2804:2994:9000:: 36 network 2804:2994:A000:: 35 network 2804:2994:A000:: 36 network 2804:2994:B000:: 36 network 2804:2994:C000:: 34 network 2804:2994:C000:: 35 network 2804:2994:C000:: 36 network 2804:2994:D000:: 36 network 2804:2994:E000:: 35 network 2804:2994:E000:: 36 prefix origin-validation enable bestroute origin-as-validation allow-invalid peer 2804:39C:F002::29D enable peer 2804:39C:F002::29D route-policy G8-V6-IN import peer 2804:39C:F002::29D route-policy G8-V6-OUT export peer 2804:39C:F002::29D advertise-community peer 2804:39C:F002::29D advertise-large-community peer 2804:39C:F002::29D advertise-ext-community peer 2804:1E48::1121 enable peer 2804:1E48::1121 route-policy CHINA-TELECOM-V6-IN import peer 2804:1E48::1121 route-policy CHINA-TELECOM-V6-OUT export peer 2804:1E48::1121 advertise-community peer 2804:1E48::1121 advertise-large-community peer 2804:1E48::1121 advertise-ext-community peer 2804:2994:77::52 enable peer 2804:2994:77::52 route-policy ACCEPT-ALL import peer 2804:2994:77::52 route-policy DROP-ALL export peer 2804:2994:77::52 reflect-client peer 2804:2994:77::52 advertise-community peer 2804:2994:77::52 advertise-large-community peer 2804:2994:77::52 advertise-ext-community peer FC00::A enable peer FC00::A next-hop-local peer FC00::A advertise-community peer FC00::A advertise-large-community peer FC00::A advertise-ext-community peer FC00::29 enable peer FC00::29 route-policy WANGUARD-IN import peer FC00::29 route-policy DROP-ALL export peer FC00::29 reflect-client peer FC00::29 advertise-community peer FC00::29 advertise-large-community peer FC00::29 advertise-ext-community peer CDN-V6 enable peer CDN-V6 route-policy DROP-ALL import peer CDN-V6 route-policy CDN-V6-OUT export peer CDN-V6 advertise-community peer CDN-V6 advertise-ext-community peer CDN-V6 advertise-large-community peer 2801:80:17B1::23:50 enable peer 2801:80:17B1::23:50 group CDN-V6 peer 2801:80:17B1::23:50 route-policy OPENCDN-V6-IN import peer 2801:80:17B1::23:50 route-policy OPENCDN-V6-OUT export peer 2804:2994:77:77::2 enable peer 2804:2994:77:77::2 group CDN-V6 peer 2804:2994:77:77::2 keep-all-routes peer 2804:2994:77:77A::FFFE enable peer 2804:2994:77:77A::FFFE group CDN-V6 peer 2804:2994:77:77A::FFFE keep-all-routes peer 2804:2994:77:77C::1 enable peer 2804:2994:77:77C::1 group CDN-V6 peer HUGE-V6 enable peer HUGE-V6 route-policy DROP-ALL import peer HUGE-V6 route-policy DROP-ALL export peer HUGE-V6 advertise-community peer HUGE-V6 advertise-ext-community peer 2804:1E20:AAA1:1FF::A enable peer 2804:1E20:AAA1:1FF::A group HUGE-V6 peer 2804:1E20:AAA1:1FF::A route-policy HUGE-G8-V6-OUT export peer 2804:1E20:AAA1:409::A enable peer 2804:1E20:AAA1:409::A group HUGE-V6 peer 2804:1E20:AAA1:409::A route-policy HUGE-PTT-V6-OUT export peer PEERING-V6 enable peer PEERING-V6 route-policy PEERING-V6-IN import peer PEERING-V6 route-policy PEERING-V6-OUT export peer PEERING-V6 advertise-community peer PEERING-V6 advertise-ext-community peer 2001:12F8::213:181 enable peer 2001:12F8::213:181 group PEERING-V6 peer 2001:12F8::213:182 enable peer 2001:12F8::213:182 group PEERING-V6 peer PTT-IX-DF-V6 enable peer PTT-IX-DF-V6 route-policy PTT-IX-DF-V6-IN import peer PTT-IX-DF-V6 route-policy PTT-IX-DF-V6-OUT export peer PTT-IX-DF-V6 advertise-community peer PTT-IX-DF-V6 advertise-ext-community peer 2001:12F8:0:13::252 enable peer 2001:12F8:0:13::252 group PTT-IX-DF-V6 peer 2001:12F8:0:13::253 enable peer 2001:12F8:0:13::253 group PTT-IX-DF-V6 peer 2001:12F8:0:13::254 enable peer 2001:12F8:0:13::254 group PTT-IX-DF-V6 peer PTT-IX-SP-V6 enable peer PTT-IX-SP-V6 route-policy PTT-SP-V6-IN import peer PTT-IX-SP-V6 route-policy PTT-SP-V6-OUT export peer PTT-IX-SP-V6 advertise-community peer PTT-IX-SP-V6 advertise-ext-community peer PTT-IX-SP-V6 advertise-large-community peer 2001:12F8::252 enable peer 2001:12F8::252 group PTT-IX-SP-V6 peer 2001:12F8::253 enable peer 2001:12F8::253 group PTT-IX-SP-V6 peer 2001:12F8::254 enable peer 2001:12F8::254 group PTT-IX-SP-V6 peer UPX-V6 enable peer UPX-V6 route-policy DROP-ALL import peer UPX-V6 route-policy UPX-V6-OUT export peer UPX-V6 advertise-community peer UPX-V6 advertise-ext-community peer UPX-V6 advertise-large-community peer 2804:2870:1:C11E::129:128 enable peer 2804:2870:1:C11E::129:128 group UPX-V6 # ipv6-family flow route match-destination peer 2804:2994:77::52 enable peer 2804:2994:77::52 route-policy ACCEPT-ALL import peer 2804:2994:77::52 route-policy DROP-ALL export peer 2804:2994:77::52 reflect-client peer 2804:2994:77::52 advertise-community peer 2804:2994:77::52 advertise-large-community peer 2804:2994:77::52 validation-disable route validation-mode include-as # rpki # session 143.0.252.38 tcp port 3323 timer refresh 1200 rpki-limit 512000 alert-only # session 2804:2994:77::38 tcp port 3323 # ospf 1 router-id 10.0.0.1 default-route-advertise always import-route static opaque-capability enable area 0.0.0.0 network 10.0.0.1 0.0.0.0 description loopback-privada network 10.0.0.250 0.0.0.1 description loopback-privada network 10.0.77.12 0.0.0.3 description VLAN-700-SW-HW-GR-L3 network 10.7.7.4 0.0.0.3 description VLAN-2004-iBGP-V4 network 10.7.7.12 0.0.0.3 description VLAN-400-BGN-CT-V4 network 10.7.7.20 0.0.0.3 description VLAN-2400-CGNAT-V4 network 10.7.7.96 0.0.0.31 description Servidores-Privados network 10.7.7.128 0.0.0.15 description VLAN-10-VM's network 143.0.252.0 0.0.0.63 description VLAN-10-VM's network 143.0.252.88 0.0.0.3 description VLAN-50-OCA network 143.0.252.96 0.0.0.15 description VLAN-60-GGC network 143.0.252.152 0.0.0.1 description loopback-publica # ip community-list PTT-SP community 65000:19551 description nega-incapsula community 64603:28604 description prepend-globo # ip ip-prefix CDN-V4 index 10 permit 143.0.252.0 22 greater-equal 22 less-equal 25 ip ip-prefix CDN-V4 index 20 permit 205.164.78.0 23 greater-equal 23 less-equal 25 ip ip-prefix CDN-V4 index 30 permit 38.191.124.0 22 greater-equal 22 less-equal 25 ip ip-prefix CHINA-TELECOM index 10 permit 143.0.252.0 22 greater-equal 22 less-equal 22 ip ip-prefix CHINA-TELECOM index 30 permit 205.164.78.0 23 greater-equal 23 less-equal 23 ip ip-prefix CHINA-TELECOM index 40 permit 38.191.124.0 22 greater-equal 22 less-equal 22 ip ip-prefix G8-V4-OUT index 10 permit 143.0.252.0 22 greater-equal 22 less-equal 22 ip ip-prefix G8-V4-OUT index 20 permit 38.191.124.0 22 greater-equal 22 less-equal 22 ip ip-prefix G8-V4-OUT index 30 permit 205.164.78.0 23 greater-equal 23 less-equal 23 ip ip-prefix HUGE-V4 index 20 permit 38.191.124.0 22 greater-equal 22 less-equal 24 ip ip-prefix OPENCDN-V4 index 10 permit 143.0.252.0 22 greater-equal 22 less-equal 23 ip ip-prefix OPENCDN-V4 index 20 permit 205.164.78.0 23 greater-equal 23 less-equal 23 ip ip-prefix OPENCDN-V4 index 30 permit 38.191.124.0 22 greater-equal 22 less-equal 23 ip ip-prefix PEERING-V4 index 10 permit 143.0.252.0 22 greater-equal 22 less-equal 24 ip ip-prefix PEERING-V4 index 20 permit 38.191.124.0 22 greater-equal 22 less-equal 24 ip ip-prefix PEERING-V4 index 30 permit 205.164.78.0 23 greater-equal 23 less-equal 24 ip ip-prefix PTT-IX-DF-V4 index 10 permit 143.0.252.0 22 greater-equal 22 less-equal 22 ip ip-prefix PTT-IX-DF-V4 index 20 permit 38.191.124.0 22 greater-equal 22 less-equal 22 ip ip-prefix PTT-IX-DF-V4 index 30 permit 38.191.124.0 22 greater-equal 22 less-equal 23 ip ip-prefix PTT-IX-DF-V4 index 40 permit 143.0.252.0 22 greater-equal 22 less-equal 23 ip ip-prefix PTT-IX-DF-V4 index 50 permit 205.164.78.0 23 greater-equal 23 less-equal 23 ip ip-prefix PTT-SP-V4 index 10 permit 143.0.252.0 22 greater-equal 22 less-equal 22 ip ip-prefix PTT-SP-V4 index 20 permit 38.191.124.0 22 greater-equal 22 less-equal 22 ip ip-prefix ROUTE-DEFAULT index 10 permit 0.0.0.0 0 ip ip-prefix UPX-G8 index 10 permit 143.0.252.0 22 greater-equal 22 less-equal 24 ip ip-prefix UPX-PTT index 10 permit 143.0.252.0 22 greater-equal 22 less-equal 24 ip ip-prefix UPX-V4 index 10 permit 143.0.252.0 22 greater-equal 22 less-equal 24 ip ip-prefix UPX-V4 index 30 permit 205.164.78.0 23 greater-equal 23 less-equal 24 ip ip-prefix UPX-V4 index 40 permit 38.191.124.0 22 greater-equal 22 less-equal 24 ip as-path-filter CLIENTES-ASPATH-IX index 10 permit _262880$ ip as-path-filter FILTER-ASN index 10 permit _267626$ ip as-path-filter FILTER-ASN index 11 permit _16509$ ip as-path-filter FILTER-ASN index 21 permit _16735$ ip as-path-filter NEGANDO_LOCAWEB index 20 permit _27715$ ip as-path-filter NEGANDO_LOCAWEB index 30 permit _32787$ ip community-filter basic BOGONS index 10 permit 65332:888 ip community-filter basic EXP->HUGE index 10 permit 23456:777 ip community-filter basic UTRS-AS64496 index 10 permit 64496:0 ip extcommunity-filter basic BLACKHOLE index 10 permit rt 264023:666 ip extcommunity-filter basic CDN-FNA index 10 permit rt 264023:702 ip extcommunity-filter basic CDN-GGC index 10 permit rt 264023:700 ip extcommunity-filter basic CDN-OCA index 10 permit rt 264023:701 ip extcommunity-filter basic CLIENTES-BGP index 10 permit rt 264023:500 ip extcommunity-filter basic EXP->HUGE index 10 permit rt 264023:777 ip extcommunity-filter basic IP-TRANSITO index 10 permit rt 264023:100 ip extcommunity-filter basic PTT-IX-SP index 10 permit rt 264023:200 ip extcommunity-filter basic RADAR-AS2628 index 10 permit rt 264023:900 # ip ipv6-prefix CDN-V6 index 10 permit 2804:2994:: 32 greater-equal 32 less-equal 36 ip ipv6-prefix CHINA-TELECOM-V6 index 10 permit 2804:2994:: 32 greater-equal 32 less-equal 32 ip ipv6-prefix G8-V6-OUT index 10 permit 2804:2994:: 32 greater-equal 32 less-equal 32 ip ipv6-prefix HUGE-G8-V6 index 10 permit 2804:2994:: 32 greater-equal 32 less-equal 48 ip ipv6-prefix HUGE-PTT-V6 index 10 permit 2804:2994:: 32 greater-equal 32 less-equal 48 ip ipv6-prefix OPENCDN-V6 index 10 permit 2804:2994:: 32 greater-equal 32 less-equal 34 ip ipv6-prefix PEERING-V6 index 10 permit 2804:2994:: 32 greater-equal 32 less-equal 35 ip ipv6-prefix PTT-IX-DF-V6 index 10 permit 2804:2994:: 32 greater-equal 32 less-equal 35 ip ipv6-prefix PTT-SP-V6 index 10 permit 2804:2994:: 32 greater-equal 32 less-equal 32 ip ipv6-prefix PTT-SP-V6 index 20 permit 2804:2994:: 32 greater-equal 32 less-equal 33 ip ipv6-prefix ROUTE-DEFAULT-V6 index 10 permit :: 0 ip ipv6-prefix UPX-V6 index 10 permit 2804:2994:: 32 greater-equal 32 less-equal 48 # route-policy ACCEPT-ALL permit node 10 # route-policy CDN-V4-OUT permit node 10 if-match ip-prefix CDN-V4 # route-policy CDN-V6-OUT permit node 10 if-match ipv6 address prefix-list CDN-V6 # route-policy CHINA-TELECOM-V4-IN permit node 3 if-match ip-prefix ROUTE-DEFAULT # route-policy CHINA-TELECOM-V4-IN deny node 4 # route-policy CHINA-TELECOM-V4-IN deny node 5 if-match rpki origin-as-validation invalid # route-policy CHINA-TELECOM-V4-IN permit node 6 if-match rpki origin-as-validation valid # route-policy CHINA-TELECOM-V4-IN permit node 7 if-match rpki origin-as-validation not-found apply extcommunity rt 264023:6666 # route-policy CHINA-TELECOM-V4-OUT deny node 5 if-match extcommunity-filter EXP->HUGE # route-policy CHINA-TELECOM-V4-OUT permit node 10 if-match ip-prefix CHINA-TELECOM apply community 20940:51000 26162:51000 32934:51000 26615:51000 65525:21500 65525:21511 65525:21512 additive # route-policy CHINA-TELECOM-V6-IN permit node 3 if-match ipv6 address prefix-list ROUTE-DEFAULT-V6 # route-policy CHINA-TELECOM-V6-IN deny node 4 # route-policy CHINA-TELECOM-V6-IN deny node 5 if-match rpki origin-as-validation invalid # route-policy CHINA-TELECOM-V6-IN permit node 6 if-match rpki origin-as-validation valid # route-policy CHINA-TELECOM-V6-IN permit node 7 if-match rpki origin-as-validation not-found apply extcommunity rt 264023:6666 # route-policy CHINA-TELECOM-V6-OUT deny node 5 # route-policy CHINA-TELECOM-V6-OUT permit node 10 if-match ipv6 address prefix-list CHINA-TELECOM-V6 apply community 20940:51000 26162:51000 32934:51000 26615:51000 65525:21500 65525:21511 65525:21512 additive # route-policy DROP-ALL deny node 10 # route-policy G8-V4-IN permit node 3 if-match ip-prefix ROUTE-DEFAULT # route-policy G8-V4-IN deny node 4 # route-policy G8-V4-IN deny node 5 if-match rpki origin-as-validation invalid # route-policy G8-V4-IN permit node 6 if-match rpki origin-as-validation valid # route-policy G8-V4-IN permit node 7 if-match rpki origin-as-validation not-found apply extcommunity rt 264023:6666 # route-policy G8-V4-IN permit node 10 # route-policy G8-V4-OUT deny node 5 if-match extcommunity-filter EXP->HUGE # route-policy G8-V4-OUT permit node 10 if-match ip-prefix G8-V4-OUT apply as-path 264023 264023 264023 264023 264023 additive apply community 28329:9902 28329:9903 additive apply extcommunity rt 264023:30 additive # route-policy G8-V6-IN permit node 3 if-match ipv6 address prefix-list ROUTE-DEFAULT-V6 # route-policy G8-V6-IN deny node 4 # route-policy G8-V6-IN deny node 5 if-match rpki origin-as-validation invalid # route-policy G8-V6-IN permit node 6 if-match rpki origin-as-validation valid # route-policy G8-V6-IN permit node 7 if-match rpki origin-as-validation not-found apply extcommunity rt 264023:6666 # route-policy G8-V6-OUT deny node 5 if-match extcommunity-filter EXP->HUGE # route-policy G8-V6-OUT permit node 10 if-match ipv6 address prefix-list G8-V6-OUT apply as-path 264023 264023 264023 264023 264023 additive apply extcommunity rt 264023:30 additive # route-policy HUGE-G8-V6-OUT deny node 2 # route-policy HUGE-G8-V6-OUT permit node 10 if-match ipv6 address prefix-list HUGE-G8-V6 if-match extcommunity-filter EXP->HUGE # route-policy HUGE-OUT deny node 2 # route-policy HUGE-OUT permit node 10 if-match ip-prefix HUGE-V4 # route-policy HUGE-PTT-V6-OUT deny node 2 # route-policy HUGE-PTT-V6-OUT permit node 10 if-match ipv6 address prefix-list HUGE-PTT-V6 if-match extcommunity-filter EXP->HUGE # route-policy OPENCDN-V4-IN deny node 5 if-match rpki origin-as-validation invalid # route-policy OPENCDN-V4-IN permit node 6 if-match rpki origin-as-validation valid apply local-preference 1000 # route-policy OPENCDN-V4-IN permit node 7 if-match rpki origin-as-validation not-found apply local-preference 1000 apply extcommunity rt 264023:6666 # route-policy OPENCDN-V4-IN permit node 10 apply local-preference 1000 # route-policy OPENCDN-V4-OUT permit node 10 if-match ip-prefix OPENCDN-V4 apply community 40027:40000 # route-policy OPENCDN-V6-IN deny node 5 if-match rpki origin-as-validation invalid # route-policy OPENCDN-V6-IN permit node 6 if-match rpki origin-as-validation valid apply local-preference 1000 # route-policy OPENCDN-V6-IN permit node 7 if-match rpki origin-as-validation not-found apply local-preference 1000 # route-policy OPENCDN-V6-IN permit node 10 apply local-preference 1000 # route-policy OPENCDN-V6-OUT permit node 10 if-match ipv6 address prefix-list OPENCDN-V6 apply community 40027:40000 # route-policy PEERING-V4-IN deny node 5 if-match rpki origin-as-validation invalid # route-policy PEERING-V4-IN permit node 6 if-match rpki origin-as-validation valid apply local-preference 1000 # route-policy PEERING-V4-IN permit node 7 if-match rpki origin-as-validation not-found apply local-preference 1000 apply extcommunity rt 264023:6666 # route-policy PEERING-V4-OUT permit node 10 if-match ip-prefix PEERING-V4 # route-policy PEERING-V6-IN deny node 5 if-match rpki origin-as-validation invalid # route-policy PEERING-V6-IN permit node 6 if-match rpki origin-as-validation valid apply local-preference 1000 # route-policy PEERING-V6-IN permit node 7 if-match rpki origin-as-validation not-found apply local-preference 1000 apply extcommunity rt 264023:6666 # route-policy PEERING-V6-OUT permit node 10 if-match ipv6 address prefix-list PEERING-V6 # route-policy PTT-IX-DF-V4-IN deny node 4 if-match as-path-filter FILTER-ASN # route-policy PTT-IX-DF-V4-IN deny node 5 if-match as-path-filter CLIENTES-ASPATH-IX # route-policy PTT-IX-DF-V4-IN deny node 6 if-match rpki origin-as-validation invalid # route-policy PTT-IX-DF-V4-IN permit node 7 if-match rpki origin-as-validation valid apply local-preference 800 # route-policy PTT-IX-DF-V4-IN permit node 8 if-match rpki origin-as-validation not-found apply local-preference 800 apply extcommunity rt 264023:6666 # route-policy PTT-IX-DF-V4-OUT deny node 5 if-match extcommunity-filter EXP->HUGE # route-policy PTT-IX-DF-V4-OUT permit node 10 if-match ip-prefix PTT-IX-DF-V4 apply community 65000:28604 65000:16735 additive # route-policy PTT-IX-DF-V6-IN deny node 4 if-match as-path-filter FILTER-ASN # route-policy PTT-IX-DF-V6-IN deny node 5 if-match as-path-filter CLIENTES-ASPATH-IX # route-policy PTT-IX-DF-V6-IN deny node 6 if-match rpki origin-as-validation invalid # route-policy PTT-IX-DF-V6-IN permit node 7 if-match rpki origin-as-validation valid apply local-preference 800 # route-policy PTT-IX-DF-V6-IN permit node 8 if-match rpki origin-as-validation not-found apply local-preference 800 apply extcommunity rt 264023:6666 # route-policy PTT-IX-DF-V6-OUT deny node 5 if-match extcommunity-filter EXP->HUGE # route-policy PTT-IX-DF-V6-OUT permit node 10 if-match ipv6 address prefix-list PTT-IX-DF-V6 apply community 65000:28604 65000:16735 additive # route-policy PTT-SP-V4-IN deny node 3 if-match as-path-filter FILTER-ASN # route-policy PTT-SP-V4-IN deny node 4 if-match as-path-filter CLIENTES-ASPATH-IX # route-policy PTT-SP-V4-IN deny node 6 if-match rpki origin-as-validation invalid # route-policy PTT-SP-V4-IN permit node 7 if-match rpki origin-as-validation valid apply local-preference 400 # route-policy PTT-SP-V4-IN permit node 8 if-match rpki origin-as-validation not-found apply local-preference 400 apply extcommunity rt 264023:6666 # route-policy PTT-SP-V4-OUT deny node 5 if-match extcommunity-filter EXP->HUGE # route-policy PTT-SP-V4-OUT permit node 10 if-match ip-prefix PTT-SP-V4 apply community 65000:16735 additive # route-policy PTT-SP-V6-IN deny node 3 if-match as-path-filter FILTER-ASN # route-policy PTT-SP-V6-IN deny node 4 if-match as-path-filter CLIENTES-ASPATH-IX # route-policy PTT-SP-V6-IN deny node 6 if-match rpki origin-as-validation invalid # route-policy PTT-SP-V6-IN permit node 7 if-match rpki origin-as-validation valid apply local-preference 600 # route-policy PTT-SP-V6-IN permit node 8 if-match rpki origin-as-validation not-found apply local-preference 600 apply extcommunity rt 264023:6666 # route-policy PTT-SP-V6-OUT permit node 10 if-match ipv6 address prefix-list PTT-SP-V6 apply community 65000:16735 additive # route-policy UPX-PTT-V4-OUT permit node 10 if-match ip-prefix UPX-V4 if-match extcommunity-filter EXP->HUGE # route-policy UPX-V4-OUT permit node 10 if-match ip-prefix UPX-V4 if-match extcommunity-filter EXP->HUGE apply cost 100 # route-policy UPX-V6-OUT permit node 10 if-match ipv6 address prefix-list UPX-V6 if-match extcommunity-filter EXP->HUGE # route-policy WANGUARD-IN permit node 10 apply preferred-value 33000 # ip route-static 0.0.0.0 0.0.0.0 NULL0 no-install ip route-static 0.0.0.0 0.0.0.0 10.0.0.2 preference 255 description ROUTE-IGRE-iBGP-BKP ip route-static 10.0.0.10 255.255.255.255 143.0.252.52 description loopback-wanguard ip route-static 38.191.124.0 255.255.252.0 NULL0 no-install ip route-static 38.191.124.0 255.255.254.0 NULL0 no-install ip route-static 38.191.124.0 255.255.255.0 NULL0 no-install ip route-static 38.191.124.0 255.255.255.128 NULL0 no-install ip route-static 38.191.124.128 255.255.255.128 NULL0 no-install ip route-static 38.191.125.0 255.255.255.0 NULL0 no-install ip route-static 38.191.125.0 255.255.255.128 NULL0 no-install ip route-static 38.191.125.128 255.255.255.128 NULL0 no-install ip route-static 38.191.126.0 255.255.254.0 NULL0 no-install ip route-static 38.191.126.0 255.255.255.0 NULL0 no-install ip route-static 38.191.126.0 255.255.255.128 NULL0 no-install ip route-static 38.191.126.128 255.255.255.128 NULL0 no-install ip route-static 38.191.127.0 255.255.255.0 NULL0 no-install ip route-static 38.191.127.0 255.255.255.128 NULL0 no-install ip route-static 38.191.127.128 255.255.255.128 NULL0 no-install ip route-static 143.0.252.0 255.255.252.0 NULL0 no-install ip route-static 143.0.252.0 255.255.254.0 NULL0 no-install ip route-static 143.0.252.0 255.255.255.0 NULL0 no-install ip route-static 143.0.252.0 255.255.255.128 NULL0 no-install ip route-static 143.0.252.128 255.255.255.128 NULL0 no-install ip route-static 143.0.253.0 255.255.255.0 NULL0 no-install ip route-static 143.0.253.0 255.255.255.128 NULL0 no-install ip route-static 143.0.253.128 255.255.255.128 NULL0 no-install ip route-static 143.0.254.0 255.255.254.0 NULL0 no-install ip route-static 143.0.254.0 255.255.255.0 NULL0 no-install ip route-static 143.0.254.0 255.255.255.128 NULL0 no-install ip route-static 143.0.254.128 255.255.255.128 NULL0 no-install ip route-static 143.0.255.0 255.255.255.0 NULL0 no-install ip route-static 143.0.255.0 255.255.255.128 NULL0 no-install ip route-static 143.0.255.128 255.255.255.128 NULL0 no-install ip route-static 192.0.2.1 255.255.255.255 NULL0 no-install description BLACKHOLE ip route-static 205.164.78.0 255.255.254.0 NULL0 no-install ip route-static 205.164.78.0 255.255.255.0 NULL0 no-install ip route-static 205.164.78.0 255.255.255.128 NULL0 no-install ip route-static 205.164.78.128 255.255.255.128 NULL0 no-install ip route-static 205.164.79.0 255.255.255.0 NULL0 no-install ip route-static 205.164.79.0 255.255.255.128 NULL0 no-install ip route-static 205.164.79.128 255.255.255.128 NULL0 no-install # ipv6 route-static :: 0 NULL0 no-install ipv6 route-static :: 0 FC00::A preference 255 description ROUTE-IGRE-iBGP-BKP-V6 ipv6 route-static 100:: 64 NULL0 description BLACKHOLE ipv6 route-static 2804:2994:: 32 NULL0 no-install ipv6 route-static 2804:2994:: 33 NULL0 no-install ipv6 route-static 2804:2994:: 34 NULL0 no-install ipv6 route-static 2804:2994:: 35 NULL0 no-install ipv6 route-static 2804:2994:: 36 NULL0 no-install ipv6 route-static 2804:2994:1000:: 36 NULL0 no-install ipv6 route-static 2804:2994:2000:: 35 NULL0 no-install ipv6 route-static 2804:2994:2000:: 36 NULL0 no-install ipv6 route-static 2804:2994:3000:: 36 NULL0 no-install ipv6 route-static 2804:2994:4000:: 34 NULL0 no-install ipv6 route-static 2804:2994:4000:: 35 NULL0 no-install ipv6 route-static 2804:2994:4000:: 36 NULL0 no-install ipv6 route-static 2804:2994:5000:: 36 NULL0 no-install ipv6 route-static 2804:2994:6000:: 35 NULL0 no-install ipv6 route-static 2804:2994:6000:: 36 NULL0 no-install ipv6 route-static 2804:2994:7000:: 36 NULL0 no-install ipv6 route-static 2804:2994:8000:: 33 NULL0 no-install ipv6 route-static 2804:2994:8000:: 34 NULL0 no-install ipv6 route-static 2804:2994:8000:: 35 NULL0 no-install ipv6 route-static 2804:2994:8000:: 36 NULL0 no-install ipv6 route-static 2804:2994:9000:: 36 NULL0 no-install ipv6 route-static 2804:2994:A000:: 35 NULL0 no-install ipv6 route-static 2804:2994:A000:: 36 NULL0 no-install ipv6 route-static 2804:2994:B000:: 36 NULL0 no-install ipv6 route-static 2804:2994:C000:: 34 NULL0 no-install ipv6 route-static 2804:2994:C000:: 35 NULL0 no-install ipv6 route-static 2804:2994:C000:: 36 NULL0 no-install ipv6 route-static 2804:2994:D000:: 36 NULL0 no-install ipv6 route-static 2804:2994:E000:: 35 NULL0 no-install ipv6 route-static 2804:2994:E000:: 36 NULL0 no-install ipv6 route-static 2804:2994:F000:: 36 NULL0 no-install ipv6 route-static FC00::28 125 2804:2994:77::52 description loopback-wanguard # snmp-agent snmp-agent acl 2061 snmp-agent local-engineid 800007DB03B8D6F62EF6A102 snmp-agent community read cipher %^%#u}fU6[fm&2*Wl[Y],`c=,8O+,h+O2_5COM~hXbqhmH'wXyJ9v{~*aCKvV%^%# alias SE77E # snmp-agent sys-info contact NOC snmp-agent sys-info version v2c v3 snmp-agent community complexity-check disable # snmp-agent mib-view included mibvew mib-2 snmp-agent mib-view included mib2view mib-2 # snmp-agent protocol source-status all-interface snmp-agent protocol source-status ipv6 all-interface # undo snmp-agent proxy protocol source-status all-interface undo snmp-agent proxy protocol source-status ipv6 all-interface # stelnet server enable ssh server authentication-retries 5 ssh server rsa-key min-length 3072 ssh ipv4 server port 2277 ssh ipv6 server port 2277 ssh user bruna.noc ssh user bruna.noc authentication-type all ssh user bruna.noc service-type all ssh user jeffrey ssh user jeffrey authentication-type all ssh user jeffrey service-type all ssh server-source all-interface undo ssh ipv6 server-source all-interface ssh server acl 2001 ssh server ip-block disable ssh authorization-type default aaa # ssh server cipher aes128_gcm aes128_ctr aes192_cbc aes128_cbc 3des_cbc ssh server hmac sha2_512 sha2_256_96 sha2_256 sha1 sha1_96 md5 md5_96 ssh server key-exchange dh_group_exchange_sha256 dh_group_exchange_sha1 dh_group14_sha1 dh_group1_sha1 ecdh_sha2_nistp256 ecdh_sha2_nistp384 ecdh_sha2_nistp521 # ssh server publickey dsa ecc rsa sm2 # ssh server dh-exchange min-len 2048 # ssh client publickey rsa_sha2_256 rsa_sha2_512 # ssh client cipher aes256_gcm aes128_gcm aes256_ctr aes192_ctr aes128_ctr ssh client hmac sha2_512 sha2_256 ssh client key-exchange dh_group_exchange_sha256 # user-interface maximum-vty 21 # user-interface vty 0 4 acl 2001 inbound authentication-mode aaa user privilege level 3 idle-timeout 35791 0 # local-aaa-server # return