grant/grant-mdf-4507.cfg Wed Apr 1 08:32:41 PM EDT 2026

This commit is contained in:
John Poland 2026-04-01 20:32:43 -04:00
parent 611b97d7a5
commit 63310f18b7

View File

@ -1,9 +1,9 @@
Building configuration... Building configuration...
Current configuration : 34293 bytes Current configuration : 34109 bytes
! !
! Last configuration change at 07:41:06 EDT Tue Mar 31 2026 by jpoland.oa ! Last configuration change at 12:02:42 EDT Wed Apr 1 2026 by swalts49.admin
! NVRAM config last updated at 07:41:06 EDT Tue Mar 31 2026 by jpoland.oa ! NVRAM config last updated at 12:02:43 EDT Wed Apr 1 2026 by swalts49.admin
! !
version 15.2 version 15.2
no service pad no service pad
@ -420,7 +420,7 @@ interface Loopback0
interface Port-channel5 interface Port-channel5
description To MDF .5 Stack ** description To MDF .5 Stack **
switchport switchport
switchport trunk allowed vlan 10,20,30,35,40,50,59,60,70 switchport trunk allowed vlan 10,20,30,35,40,50,59,60,70,230
switchport trunk native vlan 10 switchport trunk native vlan 10
switchport mode trunk switchport mode trunk
! !
@ -462,7 +462,7 @@ interface Port-channel51
interface Port-channel61 interface Port-channel61
description ** To IDF6 ** description ** To IDF6 **
switchport switchport
switchport trunk allowed vlan 10,20,30,35,40,56,70 switchport trunk allowed vlan 10,20,30,35,40,56,70,230
switchport trunk native vlan 10 switchport trunk native vlan 10
switchport mode trunk switchport mode trunk
! !
@ -475,7 +475,7 @@ interface FastEthernet1
! !
interface TenGigabitEthernet1/1 interface TenGigabitEthernet1/1
description *** To grant-mdf153-sw1 *** description *** To grant-mdf153-sw1 ***
switchport trunk allowed vlan 10,20,30,35,40,50,59,60,70 switchport trunk allowed vlan 10,20,30,35,40,50,59,60,70,230
switchport trunk native vlan 10 switchport trunk native vlan 10
switchport mode trunk switchport mode trunk
channel-group 5 mode active channel-group 5 mode active
@ -517,7 +517,7 @@ interface TenGigabitEthernet1/6
! !
interface TenGigabitEthernet1/7 interface TenGigabitEthernet1/7
description *** To grant-idf360-sw1 *** description *** To grant-idf360-sw1 ***
switchport trunk allowed vlan 10,20,30,35,40,56,70 switchport trunk allowed vlan 10,20,30,35,40,56,70,230
switchport trunk native vlan 10 switchport trunk native vlan 10
switchport mode trunk switchport mode trunk
channel-group 61 mode active channel-group 61 mode active
@ -543,7 +543,7 @@ interface TenGigabitEthernet1/12
! !
interface TenGigabitEthernet2/1 interface TenGigabitEthernet2/1
description *** To grant-mdf153-sw1 *** description *** To grant-mdf153-sw1 ***
switchport trunk allowed vlan 10,20,30,35,40,50,59,60,70 switchport trunk allowed vlan 10,20,30,35,40,50,59,60,70,230
switchport trunk native vlan 10 switchport trunk native vlan 10
switchport mode trunk switchport mode trunk
channel-group 5 mode active channel-group 5 mode active
@ -585,7 +585,7 @@ interface TenGigabitEthernet2/6
! !
interface TenGigabitEthernet2/7 interface TenGigabitEthernet2/7
description *** To grant-idf360-sw1 *** description *** To grant-idf360-sw1 ***
switchport trunk allowed vlan 10,20,30,35,40,56,70 switchport trunk allowed vlan 10,20,30,35,40,56,70,230
switchport trunk native vlan 10 switchport trunk native vlan 10
switchport mode trunk switchport mode trunk
channel-group 61 mode active channel-group 61 mode active
@ -910,6 +910,7 @@ interface Vlan35
! !
interface Vlan40 interface Vlan40
ip address 10.9.40.1 255.255.255.0 ip address 10.9.40.1 255.255.255.0
ip access-group hvac-acl in
no ip redirects no ip redirects
ip pim sparse-mode ip pim sparse-mode
! !
@ -1009,7 +1010,6 @@ interface Vlan107
! !
interface Vlan230 interface Vlan230
ip address 10.9.230.1 255.255.255.224 ip address 10.9.230.1 255.255.255.224
ip access-group hvac in
! !
interface Vlan233 interface Vlan233
ip address 10.9.233.1 255.255.255.0 ip address 10.9.233.1 255.255.255.0
@ -1117,16 +1117,14 @@ ip access-list extended AutoQos-4.0-ACL-Transactional-Data
ip access-list extended CAP1-FILTER-LIST ip access-list extended CAP1-FILTER-LIST
permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255 permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
ip access-list extended hvac ip access-list extended hvac-acl
permit ip 10.9.230.0 0.0.0.31 object-group day-enterprise-servers permit ip any host 10.1.230.11
permit udp 10.9.230.0 0.0.0.31 object-group dns-servers eq domain permit ip any host 10.1.40.108
permit udp 10.9.230.0 0.0.0.31 object-group ntp-servers eq ntp permit udp any any eq domain
permit icmp 10.9.230.0 0.0.0.31 host 10.9.230.1 deny ip any 10.0.0.0 0.0.0.255
permit icmp host 10.9.230.1 10.9.230.0 0.0.0.31
deny ip any 10.0.0.0 0.255.255.255
deny ip any 192.168.0.0 0.0.255.255 deny ip any 192.168.0.0 0.0.255.255
deny ip any 172.16.0.0 0.15.255.255 deny ip any 172.16.0.0 0.15.255.255
permit tcp 10.9.230.0 0.0.0.31 any eq 587 log-input permit tcp any any eq 587 log count
ip access-list extended sbhc-acl ip access-list extended sbhc-acl
permit ip 10.9.107.0 0.0.0.255 10.107.50.0 0.0.0.255 permit ip 10.9.107.0 0.0.0.255 10.107.50.0 0.0.0.255
permit tcp 10.9.107.0 0.0.0.255 any eq 443 permit tcp 10.9.107.0 0.0.0.255 any eq 443