Compare commits

...

10 Commits

10 changed files with 479 additions and 483 deletions

View File

@ -775,7 +775,7 @@ interface lag 28 multi-chassis
no shutdown
no routing
vlan trunk native 699
vlan trunk allowed 10,30,35,100,160,164,302-310,313-316,320-325,327-330,333-334,336-337,340-342,344-349,351,353-357,360,366,386,402-410,413-416,420-425,427-430,433-434,436-437,440-442,444-449,451,453-457,460,466,486
vlan trunk allowed 10,30,35,100,160,164,302-310,313-316,320-325,327-330,333-334,336-337,340-342,344-349,351,353-357,360,366-367,386,402-410,413-416,420-425,427-430,433-434,436-437,440-442,444-449,451,453-457,460,466-467,486
lacp mode active
interface lag 181 multi-chassis
description FG-A inside
@ -922,6 +922,7 @@ ip route 10.0.0.0/8 nullroute vrf outside
ip route 10.11.0.0/20 10.251.1.5 vrf outside
ip route 10.46.0.0/16 10.251.1.5 vrf outside
ip route 10.51.62.32/28 10.251.1.5 vrf outside
ip route 10.67.0.0/16 10.251.1.5 vrf outside
ip route 10.79.0.0/16 10.251.1.5 vrf outside
ip route 10.107.49.0/24 10.251.1.5 vrf outside
ip route 10.107.50.0/24 10.251.1.5 vrf outside

File diff suppressed because it is too large Load Diff

View File

@ -2852,7 +2852,7 @@ config firewall address
set associated-interface "inside"
set subnet 10.1.40.241 255.255.255.255
next
edit "RAP-Users"
edit "RAP_10.67.0.0/16"
set associated-interface "RAP"
set allow-routing enable
set subnet 10.67.0.0 255.255.0.0
@ -2872,7 +2872,7 @@ config firewall address
set allow-routing enable
set subnet 10.46.0.0 255.255.0.0
next
edit "DPS_Internal"
edit "DPS_Mgmt"
set subnet 192.168.46.0 255.255.255.0
next
edit "DPS_192.168.146.0/24"
@ -6149,8 +6149,8 @@ config firewall policy
set srcintf "RAP"
set dstintf "inside"
set action accept
set srcaddr "RAP-Users" "RAP-MGMT"
set dstaddr "Server_40" "Server_48"
set srcaddr "RAP_10.67.0.0/16" "RAP-MGMT"
set dstaddr "all"
set schedule "always"
set service "ALL"
set utm-status enable
@ -6255,8 +6255,8 @@ config firewall policy
set srcintf "inside"
set dstintf "RAP"
set action accept
set srcaddr "Server_40" "Server_48" "21JumpSt" "Sys-Net-Admins"
set dstaddr "RAP-Users" "RAP-MGMT" "RAP-FW-Inside"
set srcaddr "all"
set dstaddr "RAP_10.67.0.0/16" "RAP-MGMT" "RAP-FW-Inside"
set schedule "always"
set service "ALL"
set utm-status enable
@ -6273,7 +6273,7 @@ config firewall policy
set dstintf "DPS"
set action accept
set srcaddr "all"
set dstaddr "DPS_10.46.0.0/16" "DPS_Internal" "DPS_192.168.146.0/24"
set dstaddr "DPS_10.46.0.0/16" "DPS_Mgmt" "DPS_192.168.146.0/24"
set schedule "always"
set service "ALL"
next
@ -6282,7 +6282,7 @@ config firewall policy
set srcintf "DPS"
set dstintf "inside"
set action accept
set srcaddr "DPS_10.46.0.0/16" "DPS_192.168.146.0/24" "DPS_Internal"
set srcaddr "DPS_10.46.0.0/16" "DPS_192.168.146.0/24" "DPS_Mgmt"
set dstaddr "all"
set schedule "always"
set service "ALL"

View File

@ -802,14 +802,14 @@ interface lag 20 multi-chassis
no shutdown
no routing
vlan trunk native 699
vlan trunk allowed 10,30,35,100,160,164,302-310,313-316,320-325,327-330,333-334,336-337,340-342,344-349,351,353-357,360,366,386,402-410,413-416,420-425,427-430,433-434,436-437,440-442,444-449,451,453-457,460,466,486
vlan trunk allowed 10,30,35,100,160,164,302-310,313-316,320-325,327-330,333-334,336-337,340-342,344-349,351,353-357,360,366-367,386,402-410,413-416,420-425,427-430,433-434,436-437,440-442,444-449,451,453-457,460,466-467,486
lacp mode active
interface lag 21 multi-chassis
description aruba-wlc-b pc-0
no shutdown
no routing
vlan trunk native 699
vlan trunk allowed 10,30,35,100,160,164,302-310,313-316,320-325,327-330,333-334,336-337,340-342,344-349,351,353-357,360,366,386,402-410,413-416,420-425,427-430,433-434,436-437,440-442,444-449,451,453-457,460,466,486
vlan trunk allowed 10,30,35,100,160,164,302-310,313-316,320-325,327-330,333-334,336-337,340-342,344-349,351,353-357,360,366-367,386,402-410,413-416,420-425,427-430,433-434,436-437,440-442,444-449,451,453-457,460,466-467,486
lacp mode active
interface lag 106 multi-chassis
description to to FG-A Inside

View File

@ -802,14 +802,14 @@ interface lag 20 multi-chassis
no shutdown
no routing
vlan trunk native 699
vlan trunk allowed 10,30,35,100,160,164,302-310,313-316,320-325,327-330,333-334,336-337,340-342,344-349,351,353-357,360,366,386,402-410,413-416,420-425,427-430,433-434,436-437,440-442,444-449,451,453-457,460,466,486
vlan trunk allowed 10,30,35,100,160,164,302-310,313-316,320-325,327-330,333-334,336-337,340-342,344-349,351,353-357,360,366-367,386,402-410,413-416,420-425,427-430,433-434,436-437,440-442,444-449,451,453-457,460,466-467,486
lacp mode active
interface lag 21 multi-chassis
description aruba-wlc-b pc-0
no shutdown
no routing
vlan trunk native 699
vlan trunk allowed 10,30,35,100,160,164,302-310,313-316,320-325,327-330,333-334,336-337,340-342,344-349,351,353-357,360,366,386,402-410,413-416,420-425,427-430,433-434,436-437,440-442,444-449,451,453-457,460,466,486
vlan trunk allowed 10,30,35,100,160,164,302-310,313-316,320-325,327-330,333-334,336-337,340-342,344-349,351,353-357,360,366-367,386,402-410,413-416,420-425,427-430,433-434,436-437,440-442,444-449,451,453-457,460,466-467,486
lacp mode active
interface lag 106 multi-chassis
description to to FG-A Inside
@ -997,6 +997,7 @@ ip route 10.0.0.0/8 nullroute vrf outside
ip route 10.11.0.0/20 10.251.1.5 vrf outside
ip route 10.46.0.0/16 10.251.1.5 vrf outside
ip route 10.51.62.32/28 10.251.1.5 vrf outside
ip route 10.67.0.0/16 10.251.1.5 vrf outside
ip route 10.79.0.0/16 10.251.1.5 vrf outside
ip route 10.107.49.0/24 10.251.1.5 vrf outside
ip route 10.107.50.0/24 10.251.1.5 vrf outside

View File

@ -7,7 +7,7 @@ clock timezone America/New_York -05 0
!
conductorip 10.1.35.33 ipsec ****** interface vlan 35
location "Building1.floor1"
controller config 707
controller config 708
crypto-local pki ServerCert scsd_full_wc3 StarCert-Ex03_26_fullchain.pfx
crypto-local pki ServerCert scsd_full_wc_2026 StarCert-Ex03_26_fullchain.pfx
crypto-local pki ServerCert scsd_wc3_2026 StarCert-Expire03202026.pfx
@ -2629,12 +2629,10 @@ wlan ssid-profile "default"
wlan ssid-profile "Intune_ssid_prof"
essid "Intune"
wpa-passphrase *redacted*
opmode wpa2-psk-aes
a-basic-rates 24
a-tx-rates 36 48 54
g-basic-rates 12
g-tx-rates 12 18 24 36 48 54
hide-ssid
!
wlan ssid-profile "IoT_ssid_prof"
essid "IoT"

View File

@ -7,7 +7,7 @@ clock timezone America/New_York -05 0
!
conductorip 10.1.35.33 ipsec ****** interface vlan 35
location "Building1.floor1"
controller config 707
controller config 708
crypto-local pki ServerCert scsd_full_wc3 StarCert-Ex03_26_fullchain.pfx
crypto-local pki ServerCert scsd_full_wc_2026 StarCert-Ex03_26_fullchain.pfx
crypto-local pki ServerCert scsd_wc3_2026 StarCert-Expire03202026.pfx
@ -2591,12 +2591,10 @@ wlan ssid-profile "default"
wlan ssid-profile "Intune_ssid_prof"
essid "Intune"
wpa-passphrase *redacted*
opmode wpa2-psk-aes
a-basic-rates 24
a-tx-rates 36 48 54
g-basic-rates 12
g-tx-rates 12 18 24 36 48 54
hide-ssid
!
wlan ssid-profile "IoT_ssid_prof"
essid "IoT"

View File

@ -7,7 +7,7 @@ clock timezone America/New_York -05 0
!
conductorip 10.1.35.33 ipsec ****** interface vlan 35
location "Building1.floor1"
controller config 707
controller config 708
crypto-local pki ServerCert scsd_full_wc3 StarCert-Ex03_26_fullchain.pfx
crypto-local pki ServerCert scsd_full_wc_2026 StarCert-Ex03_26_fullchain.pfx
crypto-local pki ServerCert scsd_wc3_2026 StarCert-Expire03202026.pfx
@ -2583,12 +2583,10 @@ wlan ssid-profile "default"
wlan ssid-profile "Intune_ssid_prof"
essid "Intune"
wpa-passphrase *redacted*
opmode wpa2-psk-aes
a-basic-rates 24
a-tx-rates 36 48 54
g-basic-rates 12
g-tx-rates 12 18 24 36 48 54
hide-ssid
!
wlan ssid-profile "IoT_ssid_prof"
essid "IoT"

View File

@ -6,7 +6,7 @@ hostname "NOC-ARUBA-MM-2"
clock timezone America/New_York -05 0
!
location "Building1.floor1"
controller config 707
controller config 708
crypto-local pki ServerCert scsd_wc2_full_2025 Star-Exp042025-fullchain.pfx
crypto-local pki ServerCert scsd_wc2_full_2026 StarCert-Ex03_26_fullchain.pfx
crypto-local pki ServerCert scsd_wildcard_2025 StartCert-Expire042025.pfx

View File

@ -6,7 +6,7 @@ hostname "noc-aruba-mm"
clock timezone America/New_York -05 0
!
location "Building1.floor1"
controller config 707
controller config 708
crypto-local pki ServerCert scsd_wc2_full_2026 StarCert-Ex03_26_fullchain.pfx
crypto-local pki ServerCert scsd_wildcard_2026 StarCert-Ex03_26_fullchain.pfx
crypto-local pki PublicCert master-ssh-pub-cert master-ssh-pub-cert