telmexuser@CAUTP9999_10-3# show | display set set version 12.1X44-D35.5 set system host-name CAUTP9999_10-3 set system time-zone America/Bogota set system root-authentication encrypted-password "$1$gVjEWJEo$reUsrWrSUuGNbdZYHMlrb1" set system login message "\n\n\n\t*************************************************************\n\t* ATENCION: Este equipo es propiedad de TELMEX Colombia. *\n\t* El uso no autorizado esta estrictamente prohibido. *\n\t* Todos los usuarios son legalmente responsables de sus *\n\t* acciones sobre el sistema y toda actividad sera registrada*\n\t*************************************************************\n\n\n" set system login user telmexuser uid 2000 set system login user telmexuser class super-user set system login user telmexuser authentication encrypted-password "$1$8kgQk20d$RtyCKBCfKRMneOI4PdOSm0" set system services ssh set system services telnet set interfaces fe-0/0/0 unit 0 family ethernet-switching vlan members INTRANET set interfaces fe-0/0/1 unit 0 family ethernet-switching vlan members INTERNET set interfaces fe-0/0/2 unit 0 family ethernet-switching vlan members INTRANET set interfaces fe-0/0/3 unit 0 family ethernet-switching vlan members INTRANET set interfaces fe-0/0/4 unit 0 family ethernet-switching vlan members INTRANET set interfaces fe-0/0/6 vlan-tagging set interfaces fe-0/0/6 unit 2074 description "--- WAN INTERNET BKUP - CAUTP13 ---" set interfaces fe-0/0/6 unit 2074 vlan-id 2074 set interfaces fe-0/0/6 unit 2074 family inet address 10.161.183.2/30 set interfaces fe-0/0/7 vlan-tagging set interfaces fe-0/0/7 unit 253 description " --- WAN INTRANET - CAUTP05 ---" set interfaces fe-0/0/7 unit 253 vlan-id 253 set interfaces fe-0/0/7 unit 253 family inet address 10.161.201.2/30 set interfaces fe-0/0/7 unit 254 description "--- WAN INTERNET PPAL - CAUTP10 ---" set interfaces fe-0/0/7 unit 254 vlan-id 254 set interfaces fe-0/0/7 unit 254 family inet address 10.161.244.98/30 set interfaces vlan unit 2 family inet address 192.168.193.2/24 set interfaces vlan unit 3 description "--- INTERNET PPAL - CAUTP10,13 ---" set interfaces vlan unit 3 family inet address 181.49.220.1/28 set snmp community CRpWE3677TeLmEx authorization read-write set snmp community CpE3677TeLmEx authorization read-only set routing-options static route 192.168.194.0/24 next-hop 192.168.193.3 set routing-options static route 192.168.195.0/24 next-hop 192.168.193.3 set routing-options autonomous-system 65495 set protocols bgp group CONTINENTAL type external set protocols bgp group CONTINENTAL export Rutas-Export set protocols bgp group CONTINENTAL neighbor 10.161.244.97 description "--- PPAL - CAUTP10 ---" set protocols bgp group CONTINENTAL neighbor 10.161.244.97 hold-time 30 set protocols bgp group CONTINENTAL neighbor 10.161.244.97 peer-as 14080 set protocols bgp group CONTINENTAL neighbor 10.161.183.1 description " --- BCK - CAUTP13 ---" set protocols bgp group CONTINENTAL neighbor 10.161.183.1 preference 200 set protocols bgp group CONTINENTAL neighbor 10.161.183.1 hold-time 30 set protocols bgp group CONTINENTAL neighbor 10.161.183.1 peer-as 14080 set protocols bgp group CONTINENTAL-INTRA type external set protocols bgp group CONTINENTAL-INTRA export Intra-Export set protocols bgp group CONTINENTAL-INTRA neighbor 10.161.201.1 description "--- INTRANET - CAUTP05 ---" set protocols bgp group CONTINENTAL-INTRA neighbor 10.161.201.1 peer-as 14080 set protocols stp set policy-options prefix-list INTERNET 181.49.220.0/28 set policy-options prefix-list DATOS 0.0.0.0/0 set policy-options prefix-list DATOS 192.168.193.0/24 set policy-options prefix-list DATOS 192.168.194.0/24 set policy-options prefix-list DATOS 192.168.195.0/24 set policy-options policy-statement Intra-Export term 1 from protocol direct set policy-options policy-statement Intra-Export term 1 from protocol static set policy-options policy-statement Intra-Export term 1 from prefix-list DATOS set policy-options policy-statement Intra-Export term 1 then accept set policy-options policy-statement Rutas-Export term 1 from protocol direct set policy-options policy-statement Rutas-Export term 1 from prefix-list INTERNET set policy-options policy-statement Rutas-Export term 1 then accept set security alg dns disable set security alg ftp disable set security alg h323 disable set security alg mgcp disable set security alg msrpc disable set security alg sunrpc disable set security alg rsh disable set security alg rtsp disable set security alg sccp disable set security alg sip disable set security alg sql disable set security alg talk disable set security alg tftp disable set security alg pptp disable set security nat source pool NAT address 181.49.220.1/32 set security nat source rule-set ONETOONE from zone LAN set security nat source rule-set ONETOONE to zone WAN set security nat source rule-set ONETOONE rule RULENAT match source-address 192.168.193.0/24 set security nat source rule-set ONETOONE rule RULENAT then source-nat pool NAT set security policies from-zone LAN to-zone WAN policy SALIDA match source-address any set security policies from-zone LAN to-zone WAN policy SALIDA match destination-address any set security policies from-zone LAN to-zone WAN policy SALIDA match application any set security policies from-zone LAN to-zone WAN policy SALIDA then permit set security policies from-zone WAN to-zone LAN policy ENTRADA match source-address any set security policies from-zone WAN to-zone LAN policy ENTRADA match destination-address any set security policies from-zone WAN to-zone LAN policy ENTRADA match application any set security policies from-zone WAN to-zone LAN policy ENTRADA then permit set security policies from-zone LAN to-zone LAN policy TROUGHPUT match source-address any set security policies from-zone LAN to-zone LAN policy TROUGHPUT match destination-address any set security policies from-zone LAN to-zone LAN policy TROUGHPUT match application any set security policies from-zone LAN to-zone LAN policy TROUGHPUT then permit set security zones security-zone WAN host-inbound-traffic system-services all set security zones security-zone WAN host-inbound-traffic protocols all set security zones security-zone WAN interfaces fe-0/0/6.2074 set security zones security-zone WAN interfaces fe-0/0/7.253 set security zones security-zone WAN interfaces fe-0/0/7.254 set security zones security-zone LAN host-inbound-traffic system-services all set security zones security-zone LAN host-inbound-traffic protocols all set security zones security-zone LAN interfaces vlan.2 set security zones security-zone LAN interfaces vlan.3 set vlans INTERNET vlan-id 3 set vlans INTERNET l3-interface vlan.3 set vlans INTRANET vlan-id 2 set vlans INTRANET l3-interface vlan.2 [edit] telmexuser@CAUTP9999_10-3#