set security ike proposal MNO_IKE_PROP authentication-method pre-shared-keys set security ike proposal MNO_IKE_PROP dh-group group2 set security ike proposal MNO_IKE_PROP authentication-algorithm sha1 set security ike proposal MNO_IKE_PROP encryption-algorithm aes-256-cbc set security ike proposal MNO_IKE_PROP lifetime-seconds 36000 set security ike policy MNO_IKE_POL mode main set security ike policy MNO_IKE_POL proposals MNO_IKE_PROP set security ike policy MNO_IKE_POL pre-shared-key ascii-text "somekey" set security ike gateway MNO_GW ike-policy MNO_IKE_POL set security ike gateway MNO_GW address someip set security ike gateway MNO_GW dead-peer-detection always-send set security ike gateway MNO_GW dead-peer-detection interval 60 set security ike gateway MNO_GW dead-peer-detection threshold 5 set security ike gateway MNO_GW no-nat-traversal set security ike gateway MNO_GW local-identity inet x.x.49.240 set security ike gateway MNO_GW external-interface lo0.0 set security ike gateway MNO_GW local-address x.x.49.240 set security ike gateway MNO_GW general-ikeid set security ike gateway MNO_GW version v2-only set security ipsec proposal MNO_IPSEC_PROP protocol esp set security ipsec proposal MNO_IPSEC_PROP authentication-algorithm hmac-sha1-96 set security ipsec proposal MNO_IPSEC_PROP encryption-algorithm aes-256-cbc set security ipsec proposal MNO_IPSEC_PROP lifetime-seconds 3600 set security ipsec policy MNO_IPSEC_POL perfect-forward-secrecy keys group14 set security ipsec policy MNO_IPSEC_POL proposals MNO_IPSEC_PROP set security ipsec vpn MNO_VPN bind-interface st0.0 set security ipsec vpn MNO_VPN ike gateway MNO_GW set security ipsec vpn MNO_VPN ike proxy-identity local 0.0.0.0/0 set security ipsec vpn MNO_VPN ike proxy-identity remote 0.0.0.0/0 set security ipsec vpn MNO_VPN ike ipsec-policy MNO_IPSEC_POL set security ipsec vpn MNO_VPN establish-tunnels immediately set security nat source pool 3_TEST2_IN address z.z.79.249/32 set security nat source rule-set MNO_NAT_IN from routing-instance MNO set security nat source rule-set MNO_NAT_IN to routing-instance default set security nat source rule-set MNO_NAT_IN rule 3_TEST2_IN match source-address 10.59.15.254/32 set security nat source rule-set MNO_NAT_IN rule 3_TEST2_IN then source-nat pool 3_TEST2_IN set security nat static rule-set MNO_NAT from zone INSIDE set security nat static rule-set MNO_NAT rule VF match destination-address y.y.85.128/25 set security nat static rule-set MNO_NAT rule VF then static-nat prefix 10.52.16.0/25 set security nat static rule-set MNO_NAT rule VF then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule VF-B match destination-address a.a.162.0/25 set security nat static rule-set MNO_NAT rule VF-B then static-nat prefix 10.52.16.128/25 set security nat static rule-set MNO_NAT rule VF-B then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule VF-C match destination-address a.a.162.128/25 set security nat static rule-set MNO_NAT rule VF-C then static-nat prefix 10.52.17.0/25 set security nat static rule-set MNO_NAT rule VF-C then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule O2 match destination-address y.y.86.0/25 set security nat static rule-set MNO_NAT rule O2 then static-nat prefix 10.50.40.0/25 set security nat static rule-set MNO_NAT rule O2 then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule 3 match destination-address y.y.86.128/26 set security nat static rule-set MNO_NAT rule 3 then static-nat prefix 10.59.8.0/26 set security nat static rule-set MNO_NAT rule 3 then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule EEnonaggregated match destination-address y.y.85.80/28 set security nat static rule-set MNO_NAT rule EEnonaggregated then static-nat prefix 10.55.24.0/28 set security nat static rule-set MNO_NAT rule EEnonaggregated then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule EE match destination-address y.y.86.192/26 set security nat static rule-set MNO_NAT rule EE then static-nat prefix 10.255.48.0/26 set security nat static rule-set MNO_NAT rule EE then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule EE2 match destination-address a.a.160.0/26 set security nat static rule-set MNO_NAT rule EE2 then static-nat prefix 10.255.48.64/26 set security nat static rule-set MNO_NAT rule EE2 then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule EE_WH-B match destination-address a.a.160.128/26 set security nat static rule-set MNO_NAT rule EE_WH-B then static-nat prefix 10.255.48.128/26 set security nat static rule-set MNO_NAT rule EE_WH-B then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule EE_WH-C match destination-address a.a.160.192/26 set security nat static rule-set MNO_NAT rule EE_WH-C then static-nat prefix 10.255.48.192/26 set security nat static rule-set MNO_NAT rule EE_WH-C then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule EE_WH-D match destination-address a.a.161.0/24 set security nat static rule-set MNO_NAT rule EE_WH-D then static-nat prefix 10.255.49.0/24 set security nat static rule-set MNO_NAT rule EE_WH-D then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule TELE2 match destination-address a.a.163.128/27 set security nat static rule-set MNO_NAT rule TELE2 then static-nat prefix 10.54.6.0/27 set security nat static rule-set MNO_NAT rule TELE2 then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule O2-TEST match destination-address a.a.163.254/32 set security nat static rule-set MNO_NAT rule O2-TEST then static-nat prefix 10.50.40.128/32 set security nat static rule-set MNO_NAT rule O2-TEST then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule O2_TEST1 match destination-address z.z.79.250/32 set security nat static rule-set MNO_NAT rule O2_TEST1 then static-nat prefix 10.50.47.255/32 set security nat static rule-set MNO_NAT rule O2_TEST1 then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule VF_TEST1 match destination-address z.z.79.251/32 set security nat static rule-set MNO_NAT rule VF_TEST1 then static-nat prefix 10.52.23.255/32 set security nat static rule-set MNO_NAT rule VF_TEST1 then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule TELE2_TEST1 match destination-address z.z.79.252/32 set security nat static rule-set MNO_NAT rule TELE2_TEST1 then static-nat prefix 10.54.7.255/32 set security nat static rule-set MNO_NAT rule TELE2_TEST1 then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule EE_TEST1 match destination-address z.z.79.253/32 set security nat static rule-set MNO_NAT rule EE_TEST1 then static-nat prefix 10.55.24.127/32 set security nat static rule-set MNO_NAT rule EE_TEST1 then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule 3_TEST1 match destination-address z.z.79.254/32 set security nat static rule-set MNO_NAT rule 3_TEST1 then static-nat prefix 10.59.15.255/32 set security nat static rule-set MNO_NAT rule 3_TEST1 then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule EE_TEST2 match destination-address z.z.79.255/32 set security nat static rule-set MNO_NAT rule EE_TEST2 then static-nat prefix 10.255.63.255/32 set security nat static rule-set MNO_NAT rule EE_TEST2 then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule EE_TEST3 match destination-address z.z.79.248/32 set security nat static rule-set MNO_NAT rule EE_TEST3 then static-nat prefix 10.255.63.254/32 set security nat static rule-set MNO_NAT rule EE_TEST3 then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT rule 3_TEST2 match destination-address z.z.79.249/32 set security nat static rule-set MNO_NAT rule 3_TEST2 then static-nat prefix 10.59.15.254/32 set security nat static rule-set MNO_NAT rule 3_TEST2 then static-nat prefix routing-instance MNO set security nat static rule-set MNO_NAT_IN from zone MNO set security policies from-zone INSIDE to-zone INSIDE policy ALLOW_ALL_INSIDE match source-address any set security policies from-zone INSIDE to-zone INSIDE policy ALLOW_ALL_INSIDE match destination-address any set security policies from-zone INSIDE to-zone INSIDE policy ALLOW_ALL_INSIDE match application any set security policies from-zone INSIDE to-zone INSIDE policy ALLOW_ALL_INSIDE then permit set security policies from-zone MNO to-zone INSIDE policy MNO_OUT_IN match source-address any set security policies from-zone MNO to-zone INSIDE policy MNO_OUT_IN match destination-address any set security policies from-zone MNO to-zone INSIDE policy MNO_OUT_IN match application any set security policies from-zone MNO to-zone INSIDE policy MNO_OUT_IN then permit set security policies from-zone INSIDE to-zone MNO policy MNO_IN_OUT match source-address any set security policies from-zone INSIDE to-zone MNO policy MNO_IN_OUT match destination-address any set security policies from-zone INSIDE to-zone MNO policy MNO_IN_OUT match application any set security policies from-zone INSIDE to-zone MNO policy MNO_IN_OUT then permit set security policies from-zone MNO to-zone MNO policy ALLOW_ALL_MNO match source-address any set security policies from-zone MNO to-zone MNO policy ALLOW_ALL_MNO match destination-address any set security policies from-zone MNO to-zone MNO policy ALLOW_ALL_MNO match application any set security policies from-zone MNO to-zone MNO policy ALLOW_ALL_MNO then permit set security zones security-zone OUTSIDE address-book address MNO_VF_AGG 10.52.16.0/24 set security zones security-zone OUTSIDE address-book address MNO_VF 10.52.17.0/25 set security zones security-zone OUTSIDE address-book address MNO_EE_AGG 10.255.48.0/23 set security zones security-zone OUTSIDE address-book address MNO_O2 10.50.40.0/25 set security zones security-zone OUTSIDE address-book address MNO_3 10.59.8.0/26 set security zones security-zone OUTSIDE address-book address MNO_EE 10.55.24.0/28 set security zones security-zone OUTSIDE address-book address MNO_TELE 10.54.6.0/27 set security zones security-zone OUTSIDE address-book address-set MNO_ADDRESSES address MNO_3 set security zones security-zone OUTSIDE address-book address-set MNO_ADDRESSES address MNO_EE set security zones security-zone OUTSIDE address-book address-set MNO_ADDRESSES address MNO_EE_AGG set security zones security-zone OUTSIDE address-book address-set MNO_ADDRESSES address MNO_O2 set security zones security-zone OUTSIDE address-book address-set MNO_ADDRESSES address MNO_TELE set security zones security-zone OUTSIDE address-book address-set MNO_ADDRESSES address MNO_VF set security zones security-zone OUTSIDE address-book address-set MNO_ADDRESSES address MNO_VF_AGG set security zones security-zone OUTSIDE host-inbound-traffic system-services all set security zones security-zone OUTSIDE host-inbound-traffic protocols all set security zones security-zone INSIDE host-inbound-traffic system-services all set security zones security-zone INSIDE host-inbound-traffic protocols all set security zones security-zone INSIDE interfaces ge-0/0/14.0 set security zones security-zone INSIDE interfaces ge-0/0/15.0 set security zones security-zone INSIDE interfaces lo0.0 set security zones security-zone INSIDE interfaces lt-0/0/0.0 set security zones security-zone MNO host-inbound-traffic system-services all set security zones security-zone MNO host-inbound-traffic protocols all set security zones security-zone MNO interfaces st0.0 set security zones security-zone MNO interfaces lt-0/0/0.345 set interfaces lt-0/0/0 unit 0 encapsulation ethernet set interfaces lt-0/0/0 unit 0 peer-unit 345 set interfaces lt-0/0/0 unit 0 family inet address x.x.50.52/31 set interfaces lt-0/0/0 unit 345 encapsulation ethernet set interfaces lt-0/0/0 unit 345 peer-unit 0 set interfaces lt-0/0/0 unit 345 family inet address x.x.50.53/31 set interfaces ge-0/0/14 description UPL-LON01LER01-ge0_0_9 set interfaces ge-0/0/14 flexible-vlan-tagging set interfaces ge-0/0/14 native-vlan-id 0 set interfaces ge-0/0/14 unit 0 vlan-id 0 set interfaces ge-0/0/14 unit 0 family inet address x.x.50.49/31 set interfaces ge-0/0/15 description UPL-LON01LER02-ge0_0_9 set interfaces ge-0/0/15 flexible-vlan-tagging set interfaces ge-0/0/15 native-vlan-id 0 set interfaces ge-0/0/15 unit 0 vlan-id 0 set interfaces ge-0/0/15 unit 0 family inet address x.x.50.51/31 set interfaces lo0 unit 0 family inet address x.x.50.6/32 set interfaces lo0 unit 0 family inet address x.x.49.240/32 set interfaces st0 enable set interfaces st0 unit 0 enable set interfaces st0 unit 0 description MNO_IPSEC set interfaces st0 unit 0 family inet address 172.17.1.190/32 set routing-options router-id x.x.50.6 set routing-options autonomous-system someas set protocols bgp group IBGP type internal set protocols bgp group IBGP description IPV4_PEERS set protocols bgp group IBGP local-address x.x.50.6 set protocols bgp group IBGP log-updown set protocols bgp group IBGP family inet unicast set protocols bgp group IBGP export MNO_SECONDARY set protocols bgp group IBGP export STATIC_TO_BGP set protocols bgp group IBGP neighbor y.y.80.11 description LON01LSR01 set protocols bgp group IBGP neighbor y.y.80.13 description LON01LSR02 set protocols bgp group IBGP neighbor x.x.51.1 description LON02LSR01 set protocols bgp group IBGP neighbor x.x.51.2 description LON02LSR02 set protocols bgp group IBGP neighbor x.x.51.129 description LON02AGG01 set protocols bgp group IBGP neighbor x.x.50.126 description LON01AGG01 set protocols bgp group IBGP neighbor x.x.51.21 description LON02TSR01 set protocols bgp group IBGP neighbor y.y.80.10 description LON01TSR01 set protocols bgp group IBGP neighbor x.x.50.7 description LON01LER01 set protocols bgp group IBGP neighbor x.x.50.8 description LON01LER02 set protocols bgp group IBGP neighbor x.x.51.11 description LON02LER01 set protocols bgp group IBGP neighbor x.x.51.12 description LON02LER02 set protocols bgp group IBGP neighbor x.x.51.25 description LON02LNS01 set protocols bgp group IBGP neighbor y.y.80.1 description LON01LNS01 set protocols bgp group IBGP neighbor x.x.50.125 description LON02FWL02 set protocols bgp group IBGP neighbor x.x.51.22 description LON02TSR02 set protocols bgp group IBGP neighbor x.x.50.9 description LON01FWL01 set protocols bgp group IBGP neighbor x.x.51.6 description LON02FWL03 set protocols bgp group IBGP neighbor x.x.51.13 description LON02LER03 set protocols bgp group IBGP neighbor x.x.51.14 description LON02LER04 set protocols bgp group IBGP-RR type internal set protocols bgp group IBGP-RR description MNO_ROUTE_REFLECTOR set protocols bgp group IBGP-RR local-address x.x.50.52 set protocols bgp group IBGP-RR log-updown set protocols bgp group IBGP-RR export DEFAULT_ROUTE_SELF set protocols bgp group IBGP-RR cluster x.x.50.6 set protocols bgp group IBGP-RR neighbor x.x.50.53 description LON01FWL03-MNO set protocols ospf export STATIC_TO_OSPF set protocols ospf area 0.0.0.0 interface ge-0/0/14.0 set protocols ospf area 0.0.0.0 interface ge-0/0/15.0 set protocols ospf area 0.0.0.0 interface lo0.0 passive set protocols ospf area 0.0.0.0 interface ge-0/0/0.0 interface-type p2p set protocols ospf area 0.0.0.0 interface ge-0/0/1.0 interface-type p2p set protocols ospf area 0.0.0.0 interface lt-0/0/0.0 set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter y.y.85.128/25 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter y.y.86.0/24 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter a.a.160.0/26 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter a.a.160.128/25 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter a.a.163.128/28 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter a.a.161.0/24 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter a.a.162.0/23 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter y.y.85.80/28 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter a.a.163.255/32 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter a.a.163.254/32 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter z.z.79.250/32 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter z.z.79.251/32 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter z.z.79.252/32 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter z.z.79.253/32 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter z.z.79.254/32 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter z.z.79.255/32 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter z.z.79.248/32 exact set policy-options policy-statement MNO_SECONDARY term ALLOW from route-filter z.z.79.249/32 exact set policy-options policy-statement MNO_SECONDARY term ALLOW then local-preference 50 set policy-options policy-statement MNO_SECONDARY term ALLOW then accept set policy-options policy-statement MNO_SECONDARY term DENY then reject set policy-options policy-statement DEFAULT_ROUTE term ALLOW from route-filter 0.0.0.0/0 exact set policy-options policy-statement DEFAULT_ROUTE term ALLOW then accept set policy-options policy-statement DEFAULT_ROUTE term DENY then reject set policy-options policy-statement DEFAULT_ROUTE_SELF term ALLOW from route-filter 0.0.0.0/0 exact set policy-options policy-statement DEFAULT_ROUTE_SELF term ALLOW from route-filter x.x.50.173/32 exact set policy-options policy-statement DEFAULT_ROUTE_SELF term ALLOW then next-hop self set policy-options policy-statement DEFAULT_ROUTE_SELF term ALLOW then accept set policy-options policy-statement DEFAULT_ROUTE_SELF term DENY then reject set policy-options policy-statement PREPEND_MNO_DEFAULT term ALLOW from route-filter 0.0.0.0/0 exact set policy-options policy-statement PREPEND_MNO_DEFAULT term ALLOW from route-filter x.x.50.173/32 exact set policy-options policy-statement PREPEND_MNO_DEFAULT term ALLOW then as-path-prepend "someas someas someas" set policy-options policy-statement PREPEND_MNO_DEFAULT term ALLOW then accept set policy-options policy-statement PREPEND_MNO_DEFAULT term DENY then reject set policy-options policy-statement STATIC_TO_BGP from route-filter 0.0.0.0/0 orlonger set policy-options policy-statement STATIC_TO_BGP then reject set policy-options policy-statement STATIC_TO_OSPF from route-filter 0.0.0.0/0 orlonger set policy-options policy-statement STATIC_TO_OSPF then reject set policy-options condition CHECK_MNO_PRIVATE if-route-exists 10.52.16.0/25 set policy-options condition CHECK_MNO_PRIVATE if-route-exists table MNO.inet.0 set routing-instances MNO instance-type virtual-router set routing-instances MNO interface lt-0/0/0.345 set routing-instances MNO interface ge-0/0/12.0 set routing-instances MNO interface st0.0 set routing-instances MNO routing-options static route 172.17.1.189/32 next-hop st0.0 set routing-instances MNO routing-options static route y.y.85.80/28 discard set routing-instances MNO routing-options static route y.y.85.80/28 no-install set routing-instances MNO routing-options static route y.y.85.128/25 discard set routing-instances MNO routing-options static route y.y.85.128/25 no-install set routing-instances MNO routing-options static route y.y.86.0/24 discard set routing-instances MNO routing-options static route y.y.86.0/24 no-install set routing-instances MNO routing-options static route a.a.160.0/26 discard set routing-instances MNO routing-options static route a.a.160.0/26 no-install set routing-instances MNO routing-options static route a.a.160.128/25 discard set routing-instances MNO routing-options static route a.a.160.128/25 no-install set routing-instances MNO routing-options static route a.a.163.128/27 discard set routing-instances MNO routing-options static route a.a.163.128/27 no-install set routing-instances MNO routing-options static route a.a.161.0/24 discard set routing-instances MNO routing-options static route a.a.161.0/24 no-install set routing-instances MNO routing-options static route a.a.162.0/23 discard set routing-instances MNO routing-options static route a.a.162.0/23 no-install set routing-instances MNO routing-options static route a.a.163.255/32 discard set routing-instances MNO routing-options static route a.a.163.255/32 no-install set routing-instances MNO routing-options static route a.a.163.254/32 discard set routing-instances MNO routing-options static route a.a.163.254/32 no-install set routing-instances MNO routing-options static route z.z.79.250/32 discard set routing-instances MNO routing-options static route z.z.79.250/32 no-install set routing-instances MNO routing-options static route z.z.79.251/32 discard set routing-instances MNO routing-options static route z.z.79.251/32 no-install set routing-instances MNO routing-options static route z.z.79.252/32 discard set routing-instances MNO routing-options static route z.z.79.252/32 no-install set routing-instances MNO routing-options static route z.z.79.253/32 discard set routing-instances MNO routing-options static route z.z.79.253/32 no-install set routing-instances MNO routing-options static route z.z.79.254/32 discard set routing-instances MNO routing-options static route z.z.79.254/32 no-install set routing-instances MNO routing-options static route z.z.79.255/32 discard set routing-instances MNO routing-options static route z.z.79.255/32 no-install set routing-instances MNO routing-options static route z.z.79.248/32 discard set routing-instances MNO routing-options static route z.z.79.248/32 no-install set routing-instances MNO routing-options static route z.z.79.249/32 discard set routing-instances MNO routing-options static route z.z.79.249/32 no-install set routing-instances MNO protocols bgp family inet unicast set routing-instances MNO protocols bgp group MNO_BGP type external set routing-instances MNO protocols bgp group MNO_BGP multihop ttl 3 set routing-instances MNO protocols bgp group MNO_BGP authentication-key "somekey" set routing-instances MNO protocols bgp group MNO_BGP peer-as someas set routing-instances MNO protocols bgp group MNO_BGP local-as someas set routing-instances MNO protocols bgp group MNO_BGP neighbor 172.17.1.189 export PREPEND_MNO_DEFAULT set routing-instances MNO protocols bgp group MNO-IBGP type internal set routing-instances MNO protocols bgp group MNO-IBGP local-address x.x.50.53 set routing-instances MNO protocols bgp group MNO-IBGP log-updown set routing-instances MNO protocols bgp group MNO-IBGP family inet unicast set routing-instances MNO protocols bgp group MNO-IBGP export MNO_SECONDARY set routing-instances MNO protocols bgp group MNO-IBGP neighbor x.x.50.52 description LON01FWL03