<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://mars.merhot.dk/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Sahan109</id>
		<title>Teknologisk videncenter - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="http://mars.merhot.dk/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Sahan109"/>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php/Special:Contributions/Sahan109"/>
		<updated>2026-04-09T10:05:13Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.29.0</generator>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:DT4-ValgfagI.jpg&amp;diff=10933</id>
		<title>File:DT4-ValgfagI.jpg</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:DT4-ValgfagI.jpg&amp;diff=10933"/>
				<updated>2010-02-02T11:32:16Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10741</id>
		<title>Netværk II IT2 KT2 januar 2010</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10741"/>
				<updated>2010-01-20T10:41:20Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*[[CCNA]]&lt;br /&gt;
- Materialer&lt;br /&gt;
* Kapitel 3: [[media:Introducing VLANs.pdf|Introducing VLAN]]&lt;br /&gt;
* Kapitel 4: [[media:VTP.pdf|VTP]]&lt;br /&gt;
* Kapitel 5: [[media:STP.pdf|STP]]&lt;br /&gt;
* Kapitel 6: [[media:Inter-VLAN_routing.pdf|Inter-VLAN routing]]&lt;br /&gt;
* Kapitel 7: [[media:Basic_wireless_Concepts_and_Configuration.pdf|Basic Wireless Concepts]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Øvelse&lt;br /&gt;
[[image:VlanØvelse.jpg|thumb|none|650px|Network diagram]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:Basic_wireless_Concepts_and_Configuration.pdf&amp;diff=10740</id>
		<title>File:Basic wireless Concepts and Configuration.pdf</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:Basic_wireless_Concepts_and_Configuration.pdf&amp;diff=10740"/>
				<updated>2010-01-20T10:40:16Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10738</id>
		<title>Netværk II IT2 KT2 januar 2010</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10738"/>
				<updated>2010-01-19T08:32:39Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*[[CCNA]]&lt;br /&gt;
- Materialer&lt;br /&gt;
* Kapitel 3: [[media:Introducing VLANs.pdf|Introducing VLAN]]&lt;br /&gt;
* Kapitel 4: [[media:VTP.pdf|VTP]]&lt;br /&gt;
* Kapitel 5: [[media:STP.pdf|STP]]&lt;br /&gt;
* Kapitel 6: [[media:Inter-VLAN_routing.pdf|Inter-VLAN routing]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Øvelse&lt;br /&gt;
[[image:VlanØvelse.jpg|thumb|none|650px|Network diagram]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10737</id>
		<title>Netværk II IT2 KT2 januar 2010</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10737"/>
				<updated>2010-01-19T08:32:23Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*[[CCNA]]&lt;br /&gt;
- Materialer&lt;br /&gt;
* Kapitel 3: [[media:Introducing VLANs.pdf|Introducing VLAN]]&lt;br /&gt;
* Kapitel 4: [[media:VTP.pdf|VTP]]&lt;br /&gt;
* Kapitel 5: [[media:STP.pdf|STP]]&lt;br /&gt;
* Kapitel 6: [[media:Inter-VLAN_routing.pdf|Inter-VLAN routing]]&lt;br /&gt;
&lt;br /&gt;
Stuen: Christian, Lasse, Paw&lt;br /&gt;
&lt;br /&gt;
Etage 1:&lt;br /&gt;
&lt;br /&gt;
Etage 2: Helen, Jann, Jan&lt;br /&gt;
&lt;br /&gt;
Etage 3:&lt;br /&gt;
&lt;br /&gt;
Etage 4: Danni, Kristoffer, Kim J.&lt;br /&gt;
&lt;br /&gt;
Etage 5:&lt;br /&gt;
&lt;br /&gt;
Etage 6:&lt;br /&gt;
&lt;br /&gt;
Øvelse&lt;br /&gt;
[[image:VlanØvelse.jpg|thumb|none|650px|Network diagram]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10736</id>
		<title>Netværk II IT2 KT2 januar 2010</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10736"/>
				<updated>2010-01-19T08:32:09Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*[[CCNA]]&lt;br /&gt;
- Materialer&lt;br /&gt;
* Kapitel 3: [[media:Introducing VLANs.pdf|Introducing VLAN]]&lt;br /&gt;
* Kapitel 4: [[media:VTP.pdf|VTP]]&lt;br /&gt;
* Kapitel 5: [[media:STP.pdf|STP]]&lt;br /&gt;
* Kapitel 6: [[media:Inter-VLAN_routing.pdf|Inter-VLAN_routing]]&lt;br /&gt;
&lt;br /&gt;
Stuen: Christian, Lasse, Paw&lt;br /&gt;
&lt;br /&gt;
Etage 1:&lt;br /&gt;
&lt;br /&gt;
Etage 2: Helen, Jann, Jan&lt;br /&gt;
&lt;br /&gt;
Etage 3:&lt;br /&gt;
&lt;br /&gt;
Etage 4: Danni, Kristoffer, Kim J.&lt;br /&gt;
&lt;br /&gt;
Etage 5:&lt;br /&gt;
&lt;br /&gt;
Etage 6:&lt;br /&gt;
&lt;br /&gt;
Øvelse&lt;br /&gt;
[[image:VlanØvelse.jpg|thumb|none|650px|Network diagram]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:Inter-VLAN_routing.pdf&amp;diff=10735</id>
		<title>File:Inter-VLAN routing.pdf</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:Inter-VLAN_routing.pdf&amp;diff=10735"/>
				<updated>2010-01-19T08:31:11Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=IT2-KT2/skema_uge_3_-_2010&amp;diff=10725</id>
		<title>IT2-KT2/skema uge 3 - 2010</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=IT2-KT2/skema_uge_3_-_2010&amp;diff=10725"/>
				<updated>2010-01-18T13:33:28Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Infobox ugeskema2&lt;br /&gt;
 |uge     = 3 | ugedage =&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Mandag&lt;br /&gt;
  |dato    = 18. Jan&lt;br /&gt;
  |antalfag= 8&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = VTP øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Vtp øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Kapitel 4 test gennemgang&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Kapitel 5 teori (STP)&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Kapitel 5 teori (STP)&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:00 - 12:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = STP øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:45 - 13:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = STP øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 13:45 - 14:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 14:30 - 15:15&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Tirsdag&lt;br /&gt;
  |dato    = 19. Jan&lt;br /&gt;
  |antalfag= 8&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Morgenmøde / Teori Inter Vlan routing&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Gennemgang Kapitel test 5&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:00 - 12:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:45 - 13:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 13:45 - 14:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 14:30 - 15:15&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Onsdag&lt;br /&gt;
  |dato    = 20. Jan&lt;br /&gt;
  |antalfag= 8&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[IT IT2  KT2 januar 2010|IT]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:00 - 12:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = kbiv&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[IT IT2  KT2 januar 2010|IT]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:45 - 13:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = kbiv&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[IT IT2  KT2 januar 2010|IT]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 13:45 - 14:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = kbiv&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[IT IT2  KT2 januar 2010|IT]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 14:30 - 15:15&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = kbiv&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Torsdag&lt;br /&gt;
  |dato    = 21. Jan&lt;br /&gt;
  |antalfag= 8&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Engelsk IT2  KT2 januar 2010|Engelsk]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:00 - 12:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = soch&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Engelsk IT2  KT2 januar 2010|Engelsk]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:45 - 13:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = soch&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Engelsk IT2  KT2 januar 2010|Engelsk]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 13:45 - 14:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = soch&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Engelsk IT2  KT2 januar 2010|Engelsk]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 14:30 - 15:15&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = soch&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Fredag&lt;br /&gt;
  |dato    = 22. Jan&lt;br /&gt;
  |antalfag= 4&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Fredag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Fredag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Fredag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Fredag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10724</id>
		<title>Netværk II IT2 KT2 januar 2010</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10724"/>
				<updated>2010-01-18T12:12:20Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*[[CCNA]]&lt;br /&gt;
- Materialer&lt;br /&gt;
* Kapitel 3: [[media:Introducing VLANs.pdf|Introducing VLAN]]&lt;br /&gt;
* Kapitel 4: [[media:VTP.pdf|VTP]]&lt;br /&gt;
* Kapitel 5: [[media:STP.pdf|STP]]&lt;br /&gt;
&lt;br /&gt;
Stuen: Christian, Lasse, Paw&lt;br /&gt;
&lt;br /&gt;
Etage 1:&lt;br /&gt;
&lt;br /&gt;
Etage 2: Helen, Jann, Jan&lt;br /&gt;
&lt;br /&gt;
Etage 3:&lt;br /&gt;
&lt;br /&gt;
Etage 4: Danni, Kristoffer, Kim J.&lt;br /&gt;
&lt;br /&gt;
Etage 5:&lt;br /&gt;
&lt;br /&gt;
Etage 6:&lt;br /&gt;
&lt;br /&gt;
Øvelse&lt;br /&gt;
[[image:VlanØvelse.jpg|thumb|none|650px|Network diagram]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=IT2-KT2/skema_uge_3_-_2010&amp;diff=10723</id>
		<title>IT2-KT2/skema uge 3 - 2010</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=IT2-KT2/skema_uge_3_-_2010&amp;diff=10723"/>
				<updated>2010-01-18T12:11:49Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Infobox ugeskema2&lt;br /&gt;
 |uge     = 3 | ugedage =&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Mandag&lt;br /&gt;
  |dato    = 18. Jan&lt;br /&gt;
  |antalfag= 8&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = VTP øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Vtp øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Kapitel 4 test gennemgang&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Kapitel 5 teori (STP)&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Kapitel 5 teori (STP)&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:00 - 12:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = STP øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:45 - 13:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = STP øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 13:45 - 14:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 14:30 - 15:15&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Tirsdag&lt;br /&gt;
  |dato    = 19. Jan&lt;br /&gt;
  |antalfag= 8&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:00 - 12:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:45 - 13:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 13:45 - 14:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 14:30 - 15:15&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Onsdag&lt;br /&gt;
  |dato    = 20. Jan&lt;br /&gt;
  |antalfag= 8&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[IT IT2  KT2 januar 2010|IT]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:00 - 12:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = kbiv&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[IT IT2  KT2 januar 2010|IT]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:45 - 13:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = kbiv&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[IT IT2  KT2 januar 2010|IT]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 13:45 - 14:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = kbiv&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[IT IT2  KT2 januar 2010|IT]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 14:30 - 15:15&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = kbiv&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Torsdag&lt;br /&gt;
  |dato    = 21. Jan&lt;br /&gt;
  |antalfag= 8&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Engelsk IT2  KT2 januar 2010|Engelsk]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:00 - 12:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = soch&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Engelsk IT2  KT2 januar 2010|Engelsk]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:45 - 13:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = soch&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Engelsk IT2  KT2 januar 2010|Engelsk]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 13:45 - 14:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = soch&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Engelsk IT2  KT2 januar 2010|Engelsk]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 14:30 - 15:15&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = soch&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Fredag&lt;br /&gt;
  |dato    = 22. Jan&lt;br /&gt;
  |antalfag= 4&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Fredag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Fredag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Fredag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Fredag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:STP.pdf&amp;diff=10722</id>
		<title>File:STP.pdf</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:STP.pdf&amp;diff=10722"/>
				<updated>2010-01-18T12:09:23Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=DT2_jan_2010/skema_uge_2_-_2010&amp;diff=10580</id>
		<title>DT2 jan 2010/skema uge 2 - 2010</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=DT2_jan_2010/skema_uge_2_-_2010&amp;diff=10580"/>
				<updated>2010-01-15T08:49:41Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Infobox ugeskema2&lt;br /&gt;
 |uge     = 2 | ugedage =&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Mandag&lt;br /&gt;
  |dato    = 11. Jan&lt;br /&gt;
  |antalfag= 8&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[LKS IT2  KT2 januar 2010|LKS]]&lt;br /&gt;
   |emne      = Velkomst og introduktion&lt;br /&gt;
   |aktivitet = Plenum&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[A19]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Net Design - Exploration semester 3 - kapitel 1&lt;br /&gt;
   |aktivitet = teori&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II IT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:00 - 12:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:45 - 13:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 13:45 - 14:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Mandag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 14:30 - 15:15&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Tirsdag&lt;br /&gt;
  |dato    = 12. Jan&lt;br /&gt;
  |antalfag= 8&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Morgenmøde&lt;br /&gt;
   |aktivitet = Plenum&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = heth&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Kapitel 1 test&lt;br /&gt;
   |aktivitet = Test&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = heth&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Gennemgang af kapitel 1 test&lt;br /&gt;
   |aktivitet = Teori&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = heth&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Gennemgang af Exploration 3 kapitel 2 (Del 1)&lt;br /&gt;
   |aktivitet = teori&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = heth&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:00 - 12:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = heth&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:45 - 13:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = heth&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Gennemgang af Exploration 3 kapitel 2 (Del 2)&lt;br /&gt;
   |aktivitet = teori&lt;br /&gt;
   |tid       = 13:45 - 14:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = heth&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Tirsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 14:30 - 15:15&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = heth&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Onsdag&lt;br /&gt;
  |dato    = 13. Jan&lt;br /&gt;
  |antalfag= 8&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Mogenmøde&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Gennemgang af kapitel 2 test&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Vlan øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:00 - 12:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Vlan øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:45 - 13:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Vlan øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 13:45 - 14:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Onsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Vlan øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 14:30 - 15:15&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Torsdag&lt;br /&gt;
  |dato    = 14. Jan&lt;br /&gt;
  |antalfag= 8&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Mogenmøde&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Vlan øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Gennemgang Kapitel 3 test&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Vlan øvelse&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Engelsk DT2  KT2 januar 2010|Engelsk]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:00 - 12:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Engelsk DT2  KT2 januar 2010|Engelsk]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 12:45 - 13:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Engelsk DT2  KT2 januar 2010|Engelsk]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 13:45 - 14:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Torsdag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Engelsk DT2  KT2 januar 2010|Engelsk]]&lt;br /&gt;
   |emne      = -&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 14:30 - 15:15&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
 {{Infobox ugeskema/dag&lt;br /&gt;
  |ugedag  = Fredag&lt;br /&gt;
  |dato    = 15. Jan&lt;br /&gt;
  |antalfag= 4&lt;br /&gt;
  |dagfag=&lt;br /&gt;
&amp;lt;!-------------------------- Fredag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Morgenmøde / Uge evaluering&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:00 - 08:45&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Fredag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Kapitel 4 (vtp) gennemgang&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 08:45 - 09:30&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Fredag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Foredrag i kantinen&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 09:55 - 10:40&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
&amp;lt;!-------------------------- Fredag  ------------------------&amp;gt;&lt;br /&gt;
  {{Infobox ugeskema/dagfag2&lt;br /&gt;
   |fag       = [[Netværk II DT2  KT2 januar 2010|Netværk II]]&lt;br /&gt;
   |emne      = Foredrag i kantinen&lt;br /&gt;
   |aktivitet = Praktik&lt;br /&gt;
   |tid       = 10:40 - 11:25&lt;br /&gt;
   |lokale    = [[olc]]&lt;br /&gt;
   |lærer     = shan&lt;br /&gt;
  }}&lt;br /&gt;
 }}&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10579</id>
		<title>Netværk II IT2 KT2 januar 2010</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10579"/>
				<updated>2010-01-15T08:28:55Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*[[CCNA]]&lt;br /&gt;
- Materialer&lt;br /&gt;
* Kapitel 3: [[media:Introducing VLANs.pdf|Introducing VLAN]]&lt;br /&gt;
* Kapitel 4: [[media:VTP.pdf|VTP]]&lt;br /&gt;
&lt;br /&gt;
Stuen: Christian, Lasse, Paw&lt;br /&gt;
&lt;br /&gt;
Etage 1:&lt;br /&gt;
&lt;br /&gt;
Etage 2: Helen, Jann, Jan&lt;br /&gt;
&lt;br /&gt;
Etage 3:&lt;br /&gt;
&lt;br /&gt;
Etage 4: Danni, Kristoffer, Kim J.&lt;br /&gt;
&lt;br /&gt;
Etage 5:&lt;br /&gt;
&lt;br /&gt;
Etage 6:&lt;br /&gt;
&lt;br /&gt;
Øvelse&lt;br /&gt;
[[image:VlanØvelse.jpg|thumb|none|650px|Network diagram]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:VTP.pdf&amp;diff=10578</id>
		<title>File:VTP.pdf</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:VTP.pdf&amp;diff=10578"/>
				<updated>2010-01-15T08:27:17Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10577</id>
		<title>Netværk II IT2 KT2 januar 2010</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10577"/>
				<updated>2010-01-13T14:10:50Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*[[CCNA]]&lt;br /&gt;
- Materialer&lt;br /&gt;
[[media:Introducing VLANs.pdf|Introducing VLAN]]&lt;br /&gt;
&lt;br /&gt;
Stuen: Christian, Lasse, Paw&lt;br /&gt;
&lt;br /&gt;
Etage 1:&lt;br /&gt;
&lt;br /&gt;
Etage 2: Helen, Jann, Jan&lt;br /&gt;
&lt;br /&gt;
Etage 3:&lt;br /&gt;
&lt;br /&gt;
Etage 4: Danni, Kristoffer, Kim J.&lt;br /&gt;
&lt;br /&gt;
Etage 5:&lt;br /&gt;
&lt;br /&gt;
Etage 6:&lt;br /&gt;
&lt;br /&gt;
Øvelse&lt;br /&gt;
[[image:VlanØvelse.jpg|thumb|none|650px|Network diagram]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10576</id>
		<title>Netværk II IT2 KT2 januar 2010</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10576"/>
				<updated>2010-01-13T14:09:48Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*[[CCNA]]&lt;br /&gt;
- Materialer&lt;br /&gt;
[[media:Introducing VLANs.pdf|Introducing VLAN]]&lt;br /&gt;
&lt;br /&gt;
Stuen&lt;br /&gt;
Christian&lt;br /&gt;
Lasse&lt;br /&gt;
Paw&lt;br /&gt;
&lt;br /&gt;
Etage 1&lt;br /&gt;
&lt;br /&gt;
Etage 2&lt;br /&gt;
Helen&lt;br /&gt;
Jann&lt;br /&gt;
Jan&lt;br /&gt;
&lt;br /&gt;
Etage 3&lt;br /&gt;
&lt;br /&gt;
Etage 4&lt;br /&gt;
Danni&lt;br /&gt;
Kristoffer&lt;br /&gt;
Kim J.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Øvelse&lt;br /&gt;
[[image:VlanØvelse.jpg|thumb|none|650px|Network diagram]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10575</id>
		<title>Netværk II IT2 KT2 januar 2010</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10575"/>
				<updated>2010-01-13T14:06:54Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*[[CCNA]]&lt;br /&gt;
[[media:Introducing VLANs.pdf|Introducing VLAN]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Øvelse&lt;br /&gt;
[[image:VlanØvelse.jpg|thumb|none|650px|Network diagram]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:Vlan%C3%98velse.jpg&amp;diff=10572</id>
		<title>File:VlanØvelse.jpg</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:Vlan%C3%98velse.jpg&amp;diff=10572"/>
				<updated>2010-01-13T13:59:56Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:Introducing_VLANs.pdf&amp;diff=10563</id>
		<title>File:Introducing VLANs.pdf</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:Introducing_VLANs.pdf&amp;diff=10563"/>
				<updated>2010-01-13T12:33:37Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: uploaded a new version of &amp;quot;Image:Introducing VLANs.pdf&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10562</id>
		<title>Netværk II IT2 KT2 januar 2010</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Netv%C3%A6rk_II_IT2_KT2_januar_2010&amp;diff=10562"/>
				<updated>2010-01-13T12:16:41Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*[[CCNA]]&lt;br /&gt;
[[media:Introducing VLANs.pdf|Introducing VLAN]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:Introducing_VLANs.pdf&amp;diff=10561</id>
		<title>File:Introducing VLANs.pdf</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:Introducing_VLANs.pdf&amp;diff=10561"/>
				<updated>2010-01-13T12:06:37Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9012</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9012"/>
				<updated>2009-09-14T08:59:37Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* AHA01FW */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
=Filial Ålborg=&lt;br /&gt;
==AAA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AAA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AAA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.2.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.2.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180064&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Århus=&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01RTVG==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179984&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179832&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179994&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.6 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180096&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Filial Viborg=&lt;br /&gt;
==VIA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA02SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$e4ZP$h.AoOqEe1T8g2tm1rGjtj/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zzrV$FHjI7ZjZ6S9ZWJ8IFxfPQ1&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description VIFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA01SWCO1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_VIA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.3 255.255.255.0&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.3 255.255.255.0&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.3 255.255.255.0&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.3 255.255.255.0&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==VIA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWCO&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$CjQy$2ViWy5DbihxoJ1X.HcDyh1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$U0Sf$m2vxqz9Xpz/ZIGE21E7HY.&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2 priority 24576&lt;br /&gt;
spanning-tree vlan 8 priority 24576&lt;br /&gt;
spanning-tree vlan 9 priority 24576&lt;br /&gt;
spanning-tree vlan 10 priority 24576&lt;br /&gt;
spanning-tree vlan 11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.2 255.255.255.0&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 subnets&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.17.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.17.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.17.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-OUT out&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 10 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
access-list 101 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
access-list 101 permit ip any any&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jcK0$h6.iMf2Chj5ZSmadD8YJb1&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zK2S$Cg6yVpoyI0jjfuRuy6XBb1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 ip address 172.16.254.2 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.2 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 ip address 172.17.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 metric 255 subnets&lt;br /&gt;
 network 172.17.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.1 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.1 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.2 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65002 65002 65002 65002 65002 65002 65002&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vtp domain BEO-LY&lt;br /&gt;
vtp mode transparent&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
vlan 2,8-9 &lt;br /&gt;
!&lt;br /&gt;
vlan 10&lt;br /&gt;
 name LYOLAN&lt;br /&gt;
!&lt;br /&gt;
vlan 11 &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to VIA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to VI02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.1.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.1.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179912&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9011</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9011"/>
				<updated>2009-09-14T08:59:05Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* AAA01SWOP */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
=Filial Ålborg=&lt;br /&gt;
==AAA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AAA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AAA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.2.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.2.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180064&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01RTVG==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179984&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179832&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179994&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.6 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180096&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Filial Viborg=&lt;br /&gt;
==VIA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA02SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$e4ZP$h.AoOqEe1T8g2tm1rGjtj/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zzrV$FHjI7ZjZ6S9ZWJ8IFxfPQ1&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description VIFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA01SWCO1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_VIA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.3 255.255.255.0&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.3 255.255.255.0&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.3 255.255.255.0&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.3 255.255.255.0&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==VIA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWCO&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$CjQy$2ViWy5DbihxoJ1X.HcDyh1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$U0Sf$m2vxqz9Xpz/ZIGE21E7HY.&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2 priority 24576&lt;br /&gt;
spanning-tree vlan 8 priority 24576&lt;br /&gt;
spanning-tree vlan 9 priority 24576&lt;br /&gt;
spanning-tree vlan 10 priority 24576&lt;br /&gt;
spanning-tree vlan 11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.2 255.255.255.0&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 subnets&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.17.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.17.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.17.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-OUT out&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 10 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
access-list 101 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
access-list 101 permit ip any any&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jcK0$h6.iMf2Chj5ZSmadD8YJb1&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zK2S$Cg6yVpoyI0jjfuRuy6XBb1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 ip address 172.16.254.2 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.2 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 ip address 172.17.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 metric 255 subnets&lt;br /&gt;
 network 172.17.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.1 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.1 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.2 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65002 65002 65002 65002 65002 65002 65002&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vtp domain BEO-LY&lt;br /&gt;
vtp mode transparent&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
vlan 2,8-9 &lt;br /&gt;
!&lt;br /&gt;
vlan 10&lt;br /&gt;
 name LYOLAN&lt;br /&gt;
!&lt;br /&gt;
vlan 11 &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to VIA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to VI02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.1.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.1.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179912&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9010</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9010"/>
				<updated>2009-09-14T08:58:40Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
=Filial Ålborg=&lt;br /&gt;
==AAA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AAA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AAA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.2.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.2.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180064&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01RTVG==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179984&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179832&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179994&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.6 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180096&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==AAA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AAA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AAA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.2.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.2.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180064&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=Filial Viborg=&lt;br /&gt;
==VIA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA02SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$e4ZP$h.AoOqEe1T8g2tm1rGjtj/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zzrV$FHjI7ZjZ6S9ZWJ8IFxfPQ1&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description VIFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA01SWCO1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_VIA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.3 255.255.255.0&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.3 255.255.255.0&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.3 255.255.255.0&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.3 255.255.255.0&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==VIA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWCO&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$CjQy$2ViWy5DbihxoJ1X.HcDyh1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$U0Sf$m2vxqz9Xpz/ZIGE21E7HY.&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2 priority 24576&lt;br /&gt;
spanning-tree vlan 8 priority 24576&lt;br /&gt;
spanning-tree vlan 9 priority 24576&lt;br /&gt;
spanning-tree vlan 10 priority 24576&lt;br /&gt;
spanning-tree vlan 11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.2 255.255.255.0&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 subnets&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.17.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.17.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.17.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-OUT out&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 10 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
access-list 101 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
access-list 101 permit ip any any&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jcK0$h6.iMf2Chj5ZSmadD8YJb1&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zK2S$Cg6yVpoyI0jjfuRuy6XBb1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 ip address 172.16.254.2 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.2 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 ip address 172.17.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 metric 255 subnets&lt;br /&gt;
 network 172.17.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.1 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.1 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.2 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65002 65002 65002 65002 65002 65002 65002&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vtp domain BEO-LY&lt;br /&gt;
vtp mode transparent&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
vlan 2,8-9 &lt;br /&gt;
!&lt;br /&gt;
vlan 10&lt;br /&gt;
 name LYOLAN&lt;br /&gt;
!&lt;br /&gt;
vlan 11 &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to VIA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to VI02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.1.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.1.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179912&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9009</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9009"/>
				<updated>2009-09-14T08:57:54Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* Viborg */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
=Filial Ålborg=&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01RTVG==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179984&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179832&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179994&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.6 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180096&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==AAA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AAA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AAA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.2.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.2.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180064&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=Filial Viborg=&lt;br /&gt;
==VIA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA02SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$e4ZP$h.AoOqEe1T8g2tm1rGjtj/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zzrV$FHjI7ZjZ6S9ZWJ8IFxfPQ1&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description VIFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA01SWCO1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_VIA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.3 255.255.255.0&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.3 255.255.255.0&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.3 255.255.255.0&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.3 255.255.255.0&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==VIA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWCO&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$CjQy$2ViWy5DbihxoJ1X.HcDyh1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$U0Sf$m2vxqz9Xpz/ZIGE21E7HY.&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2 priority 24576&lt;br /&gt;
spanning-tree vlan 8 priority 24576&lt;br /&gt;
spanning-tree vlan 9 priority 24576&lt;br /&gt;
spanning-tree vlan 10 priority 24576&lt;br /&gt;
spanning-tree vlan 11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.2 255.255.255.0&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 subnets&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.17.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.17.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.17.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-OUT out&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 10 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
access-list 101 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
access-list 101 permit ip any any&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jcK0$h6.iMf2Chj5ZSmadD8YJb1&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zK2S$Cg6yVpoyI0jjfuRuy6XBb1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 ip address 172.16.254.2 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.2 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 ip address 172.17.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 metric 255 subnets&lt;br /&gt;
 network 172.17.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.1 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.1 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.2 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65002 65002 65002 65002 65002 65002 65002&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vtp domain BEO-LY&lt;br /&gt;
vtp mode transparent&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
vlan 2,8-9 &lt;br /&gt;
!&lt;br /&gt;
vlan 10&lt;br /&gt;
 name LYOLAN&lt;br /&gt;
!&lt;br /&gt;
vlan 11 &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to VIA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to VI02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.1.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.1.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179912&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9008</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9008"/>
				<updated>2009-09-14T08:57:31Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* VIA02SWCO */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
=Filial Ålborg=&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01RTVG==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179984&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179832&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179994&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.6 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180096&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==AAA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AAA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AAA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.2.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.2.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180064&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=Viborg=&lt;br /&gt;
==VIA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA02SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$e4ZP$h.AoOqEe1T8g2tm1rGjtj/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zzrV$FHjI7ZjZ6S9ZWJ8IFxfPQ1&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description VIFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA01SWCO1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_VIA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.3 255.255.255.0&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.3 255.255.255.0&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.3 255.255.255.0&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.3 255.255.255.0&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==VIA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWCO&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$CjQy$2ViWy5DbihxoJ1X.HcDyh1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$U0Sf$m2vxqz9Xpz/ZIGE21E7HY.&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2 priority 24576&lt;br /&gt;
spanning-tree vlan 8 priority 24576&lt;br /&gt;
spanning-tree vlan 9 priority 24576&lt;br /&gt;
spanning-tree vlan 10 priority 24576&lt;br /&gt;
spanning-tree vlan 11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.2 255.255.255.0&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 subnets&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.17.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.17.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.17.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-OUT out&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 10 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
access-list 101 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
access-list 101 permit ip any any&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jcK0$h6.iMf2Chj5ZSmadD8YJb1&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zK2S$Cg6yVpoyI0jjfuRuy6XBb1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 ip address 172.16.254.2 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.2 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 ip address 172.17.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 metric 255 subnets&lt;br /&gt;
 network 172.17.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.1 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.1 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.2 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65002 65002 65002 65002 65002 65002 65002&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vtp domain BEO-LY&lt;br /&gt;
vtp mode transparent&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
vlan 2,8-9 &lt;br /&gt;
!&lt;br /&gt;
vlan 10&lt;br /&gt;
 name LYOLAN&lt;br /&gt;
!&lt;br /&gt;
vlan 11 &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to VIA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to VI02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.1.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.1.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179912&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9007</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9007"/>
				<updated>2009-09-14T08:57:07Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
=Filial Ålborg=&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01RTVG==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179984&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179832&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179994&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.6 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180096&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==AAA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AAA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AAA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.2.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.2.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180064&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA02SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$e4ZP$h.AoOqEe1T8g2tm1rGjtj/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zzrV$FHjI7ZjZ6S9ZWJ8IFxfPQ1&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description VIFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA01SWCO1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_VIA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.3 255.255.255.0&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.3 255.255.255.0&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.3 255.255.255.0&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.3 255.255.255.0&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWCO&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$CjQy$2ViWy5DbihxoJ1X.HcDyh1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$U0Sf$m2vxqz9Xpz/ZIGE21E7HY.&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2 priority 24576&lt;br /&gt;
spanning-tree vlan 8 priority 24576&lt;br /&gt;
spanning-tree vlan 9 priority 24576&lt;br /&gt;
spanning-tree vlan 10 priority 24576&lt;br /&gt;
spanning-tree vlan 11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.2 255.255.255.0&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 subnets&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.17.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.17.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.17.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-OUT out&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 10 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
access-list 101 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
access-list 101 permit ip any any&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jcK0$h6.iMf2Chj5ZSmadD8YJb1&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zK2S$Cg6yVpoyI0jjfuRuy6XBb1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 ip address 172.16.254.2 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.2 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 ip address 172.17.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 metric 255 subnets&lt;br /&gt;
 network 172.17.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.1 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.1 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.2 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65002 65002 65002 65002 65002 65002 65002&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vtp domain BEO-LY&lt;br /&gt;
vtp mode transparent&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
vlan 2,8-9 &lt;br /&gt;
!&lt;br /&gt;
vlan 10&lt;br /&gt;
 name LYOLAN&lt;br /&gt;
!&lt;br /&gt;
vlan 11 &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to VIA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to VI02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.1.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.1.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179912&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9006</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9006"/>
				<updated>2009-09-14T08:55:10Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
=Filial Ålborg=&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01RTVG==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179984&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jcK0$h6.iMf2Chj5ZSmadD8YJb1&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zK2S$Cg6yVpoyI0jjfuRuy6XBb1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 ip address 172.16.254.2 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.2 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 ip address 172.17.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 metric 255 subnets&lt;br /&gt;
 network 172.17.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.1 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.1 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.2 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65002 65002 65002 65002 65002 65002 65002&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179832&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179994&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.6 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180096&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==VIA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vtp domain BEO-LY&lt;br /&gt;
vtp mode transparent&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
vlan 2,8-9 &lt;br /&gt;
!&lt;br /&gt;
vlan 10&lt;br /&gt;
 name LYOLAN&lt;br /&gt;
!&lt;br /&gt;
vlan 11 &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to VIA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to VI02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.1.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.1.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179912&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AAA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AAA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.2.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.2.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180064&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA02SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$e4ZP$h.AoOqEe1T8g2tm1rGjtj/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zzrV$FHjI7ZjZ6S9ZWJ8IFxfPQ1&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description VIFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA01SWCO1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_VIA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.3 255.255.255.0&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.3 255.255.255.0&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.3 255.255.255.0&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.3 255.255.255.0&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWCO&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$CjQy$2ViWy5DbihxoJ1X.HcDyh1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$U0Sf$m2vxqz9Xpz/ZIGE21E7HY.&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2 priority 24576&lt;br /&gt;
spanning-tree vlan 8 priority 24576&lt;br /&gt;
spanning-tree vlan 9 priority 24576&lt;br /&gt;
spanning-tree vlan 10 priority 24576&lt;br /&gt;
spanning-tree vlan 11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.2 255.255.255.0&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 subnets&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.17.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.17.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.17.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-OUT out&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 10 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
access-list 101 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
access-list 101 permit ip any any&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9004</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9004"/>
				<updated>2009-09-14T08:39:16Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* VIA01SWCO */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jcK0$h6.iMf2Chj5ZSmadD8YJb1&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zK2S$Cg6yVpoyI0jjfuRuy6XBb1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 ip address 172.16.254.2 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.2 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 ip address 172.17.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 metric 255 subnets&lt;br /&gt;
 network 172.17.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.1 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.1 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.2 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65002 65002 65002 65002 65002 65002 65002&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179832&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179994&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.6 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180096&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==VIA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vtp domain BEO-LY&lt;br /&gt;
vtp mode transparent&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
vlan 2,8-9 &lt;br /&gt;
!&lt;br /&gt;
vlan 10&lt;br /&gt;
 name LYOLAN&lt;br /&gt;
!&lt;br /&gt;
vlan 11 &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to VIA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to VI02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.1.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.1.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179912&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AAA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AAA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.2.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.2.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180064&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA02SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$e4ZP$h.AoOqEe1T8g2tm1rGjtj/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zzrV$FHjI7ZjZ6S9ZWJ8IFxfPQ1&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description VIFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA01SWCO1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_VIA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.3 255.255.255.0&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.3 255.255.255.0&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.3 255.255.255.0&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.3 255.255.255.0&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWCO&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$CjQy$2ViWy5DbihxoJ1X.HcDyh1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$U0Sf$m2vxqz9Xpz/ZIGE21E7HY.&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2 priority 24576&lt;br /&gt;
spanning-tree vlan 8 priority 24576&lt;br /&gt;
spanning-tree vlan 9 priority 24576&lt;br /&gt;
spanning-tree vlan 10 priority 24576&lt;br /&gt;
spanning-tree vlan 11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.2 255.255.255.0&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 subnets&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.17.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.17.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.17.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-OUT out&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 10 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
access-list 101 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
access-list 101 permit ip any any&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9003</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9003"/>
				<updated>2009-09-14T08:38:34Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* VIA02SWCO */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jcK0$h6.iMf2Chj5ZSmadD8YJb1&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zK2S$Cg6yVpoyI0jjfuRuy6XBb1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 ip address 172.16.254.2 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.2 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 ip address 172.17.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 metric 255 subnets&lt;br /&gt;
 network 172.17.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.1 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.1 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.2 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65002 65002 65002 65002 65002 65002 65002&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179832&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179994&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.6 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180096&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==VIA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vtp domain BEO-LY&lt;br /&gt;
vtp mode transparent&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
vlan 2,8-9 &lt;br /&gt;
!&lt;br /&gt;
vlan 10&lt;br /&gt;
 name LYOLAN&lt;br /&gt;
!&lt;br /&gt;
vlan 11 &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to VIA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to VI02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.1.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.1.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179912&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AAA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AAA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.2.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.2.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180064&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA02SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$e4ZP$h.AoOqEe1T8g2tm1rGjtj/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zzrV$FHjI7ZjZ6S9ZWJ8IFxfPQ1&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description VIFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA01SWCO1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_VIA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.3 255.255.255.0&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.3 255.255.255.0&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.3 255.255.255.0&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.3 255.255.255.0&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWCO&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$CjQy$2ViWy5DbihxoJ1X.HcDyh1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$U0Sf$m2vxqz9Xpz/ZIGE21E7HY.&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2 priority 24576&lt;br /&gt;
spanning-tree vlan 8 priority 24576&lt;br /&gt;
spanning-tree vlan 9 priority 24576&lt;br /&gt;
spanning-tree vlan 10 priority 24576&lt;br /&gt;
spanning-tree vlan 11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.2 255.255.255.0&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 subnets&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.17.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.17.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.17.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-OUT out&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 10 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
access-list 101 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
access-list 101 permit ip any any&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9002</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9002"/>
				<updated>2009-09-14T08:30:09Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* AAA01SWOP */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jcK0$h6.iMf2Chj5ZSmadD8YJb1&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zK2S$Cg6yVpoyI0jjfuRuy6XBb1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 ip address 172.16.254.2 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.2 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 ip address 172.17.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 metric 255 subnets&lt;br /&gt;
 network 172.17.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.1 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.1 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.2 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65002 65002 65002 65002 65002 65002 65002&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179832&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179994&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.6 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180096&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==VIA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vtp domain BEO-LY&lt;br /&gt;
vtp mode transparent&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
vlan 2,8-9 &lt;br /&gt;
!&lt;br /&gt;
vlan 10&lt;br /&gt;
 name LYOLAN&lt;br /&gt;
!&lt;br /&gt;
vlan 11 &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to VIA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to VI02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.1.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.1.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179912&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AAA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AAA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.2.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.2.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180064&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA02SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$e4ZP$h.AoOqEe1T8g2tm1rGjtj/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zzrV$FHjI7ZjZ6S9ZWJ8IFxfPQ1&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description VIFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA01SWCO1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_VIA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.3 255.255.255.0&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.3 255.255.255.0&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.3 255.255.255.0&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.3 255.255.255.0&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9000</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9000"/>
				<updated>2009-09-14T08:15:09Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* AHA02SWCO */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jcK0$h6.iMf2Chj5ZSmadD8YJb1&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zK2S$Cg6yVpoyI0jjfuRuy6XBb1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 ip address 172.16.254.2 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.2 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 ip address 172.17.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 metric 255 subnets&lt;br /&gt;
 network 172.17.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.1 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.1 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.2 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65002 65002 65002 65002 65002 65002 65002&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8999</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8999"/>
				<updated>2009-09-14T08:07:27Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* AHA01SWCO */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8998</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8998"/>
				<updated>2009-09-14T08:01:13Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* AHA01SWCO */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.7.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.7.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8997</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8997"/>
				<updated>2009-09-14T07:50:03Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* AHA01RT */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8996</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8996"/>
				<updated>2009-09-14T07:42:35Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* AHA01RT */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8995</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8995"/>
				<updated>2009-09-14T07:41:38Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* AAA01RT */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8994</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8994"/>
				<updated>2009-09-14T07:41:10Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* AHA01FW */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8993</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8993"/>
				<updated>2009-09-14T07:36:30Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* AHA01RT */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map match-any AutoQoS-VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
class-map match-any AutoQoS-VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map AutoQoS-Policy-Trust&lt;br /&gt;
 class AutoQoS-VoIP-RTP-Trust&lt;br /&gt;
  priority percent 70&lt;br /&gt;
 class AutoQoS-VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output AutoQoS-Policy-Trust&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8992</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8992"/>
				<updated>2009-09-14T07:33:52Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map match-any AutoQoS-VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
class-map match-any AutoQoS-VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map AutoQoS-Policy-Trust&lt;br /&gt;
 class AutoQoS-VoIP-RTP-Trust&lt;br /&gt;
  priority percent 70&lt;br /&gt;
 class AutoQoS-VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output AutoQoS-Policy-Trust&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8989</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8989"/>
				<updated>2009-09-14T07:17:26Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map match-any AutoQoS-VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
class-map match-any AutoQoS-VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map AutoQoS-Policy-Trust&lt;br /&gt;
 class AutoQoS-VoIP-RTP-Trust&lt;br /&gt;
  priority percent 70&lt;br /&gt;
 class AutoQoS-VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output AutoQoS-Policy-Trust&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8988</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8988"/>
				<updated>2009-09-14T07:16:32Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
AHA01FW&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map match-any AutoQoS-VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
class-map match-any AutoQoS-VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map AutoQoS-Policy-Trust&lt;br /&gt;
 class AutoQoS-VoIP-RTP-Trust&lt;br /&gt;
  priority percent 70&lt;br /&gt;
 class AutoQoS-VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output AutoQoS-Policy-Trust&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8987</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8987"/>
				<updated>2009-09-14T07:05:29Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* AAA01SWCO */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8983</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=8983"/>
				<updated>2009-09-14T06:58:45Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_Firewall&amp;diff=8080</id>
		<title>Opgave CCDP - Firewall</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_Firewall&amp;diff=8080"/>
				<updated>2009-08-13T11:46:13Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{In progress}}&lt;br /&gt;
[[Opgave CCDP]]&lt;br /&gt;
[[Image:CCDP-Edge.png|800px|center|thumb|Enterprise Edge Design]]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
=Internet=&lt;br /&gt;
[[Image:CCDP-WAN.png|500px|right|thumb|Multihomed Single Boarder Router Architecture]]&lt;br /&gt;
Internet bliver leveret af 2 forskellige ISP'er med alternativt fremførte linier, for at sikre sig mod kabelbrud, eller interne routnings problemer. Vi kører Routning med de 2 ISP'er og importerer alle internet routes til vores internet switch.&amp;lt;br/&amp;gt;&lt;br /&gt;
Dette gør vi for at kunne vores sekundære ISP hvis den primære har routnings problemer, men kun for de routes det er nødvendige.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vores primære internet forbindelse bliver en 100Mbit, der bliver brugt til alt, dog med regler for at StudNet og PaNet maks kan bruge 50% så der altid er plads til dem der arbejder. Den sekundære ISP linie bliver en 50Mbit, som folk fint kan leve med, indtil den primære bliver fikset igen.&lt;br /&gt;
Skulle det vise sig at hastigheden bliver uacceptable kan linierne opgraderes.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For at sikre os at alt trafik løber den rigtige vej ud af vores netværk skal BGP localpreference værdien på den primære linie sættes op, så det altid er den der bliver valgt til udgående trafik. Ved BGP er der utrolig mange parametre man kan bruge for at styre trafikken ud af sit netværk, men knap så mange man kan bruge til indgående.&amp;lt;br/&amp;gt;&lt;br /&gt;
Nogle af dem man kan bruge er AS_PATH prepending. Det vil sige man tilføjer nogle dummy AS numre. Da BGP måler afstand i AS hops, vil den tage den korteste vej fra kilde til destination. Ved at lave AS_PATH prepending på det ene link, vil AS Hop længere ud i netværket bliver større og routen vil være knap så atraktiv.&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
For at sikre sig at alt trafik i en optimal situation kommer den rigtige vej ind i ens netværk, laver man AS_PATH prepending på det link der ikke skal bruges, linket vil så se ud som om det hat en længere AS_PATH til dit netværk og derfor mindre attrativ. Dette kan gøres sådan:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
router bgp 300&lt;br /&gt;
 network 10.0.0.0&lt;br /&gt;
&lt;br /&gt;
 neighbor 10.10.10.10 remote-as 100&lt;br /&gt;
&lt;br /&gt;
 neighbor 20.20.20.20 remote-as 200&lt;br /&gt;
 neighbor 20.20.20.20 route-map as_path_prepending out&lt;br /&gt;
&lt;br /&gt;
!Tilføjer 2 ekstra hops til dit netværk&lt;br /&gt;
route-map as_path_prepending permit 10&lt;br /&gt;
 set as-path prepend 300 300&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Filtrering af trafik===&lt;br /&gt;
Når man laver en multihomed løsning er der nogle faldgrupper man skal passe på. Hvis man ikke filtrerer på de AS numrer man importerer kan man importere sin egen routing tabel, gennem sin ISP og lave et loop. Eller hvis man ikke filtrere på de paths man sender vidre, kan man være transit AS for trafik der skal et andet sted hen. Lad mig komme med nogle eksepler.&lt;br /&gt;
&lt;br /&gt;
===Transit trafik filtrering===&lt;br /&gt;
Hvis man har flere ISP'er og kører fuld routning med dem via eBGP får man alle deres routes, for at forhindre trafik mellem AS 100 og AS 200 vil løbe igennem ens netværk kan man filtrere alle eksterne AS'er fra i de udgående AS_PATH's. Det vil sige at AS 100 kun kender til AS 300 gennem linket og AS 200 også kun kender til AS 300 gennem linket til vores enterprise netværk. Dette vil forhindre at de 2 ISP'er kender nogle andre veje igennem os end til AS 300.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
Et eksempel på configuration med transit trafik filtrering hvor man ikke sender nogle andre AS numre med i sine udgående routes.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
router bgp 300&lt;br /&gt;
 network 10.0.0.0&lt;br /&gt;
&lt;br /&gt;
 neighbor 10.10.10.10 remote-as 100&lt;br /&gt;
 neighbor 10.10.10.10 route-map localonly out&lt;br /&gt;
&lt;br /&gt;
 neighbor 20.20.20.20 remote-as 200&lt;br /&gt;
 neighbor 20.20.20.20 route-map localonly out&lt;br /&gt;
&lt;br /&gt;
ip as-path access-list 10 permit ^$&lt;br /&gt;
&lt;br /&gt;
route-map localonly permit 10&lt;br /&gt;
 match as-path 10&lt;br /&gt;
end&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Inbound Filtering===&lt;br /&gt;
For at forhindre at man laver et black hole hvor trafik fra sig selv, til sig selv, ryger ud til ISP A og routed videre til ISP B hvorefter det kommer ind til dig selv igen, filtrere man sine egne ipadresser fra i indkomne routing updates. Derved sikrer man at ens netværk ikke kender andre veje til sig selv. &amp;lt;br/&amp;gt;&lt;br /&gt;
De 2 primære grupper man skal være opmærksom på:&lt;br /&gt;
*Martian adresse områder&lt;br /&gt;
**RFC 1918 adresser. Skal bruges internt i en virksomhed og aldrig komme ud på internettet. 10.0.0.0/8, 172.16.0.0/12 &amp;amp; 192.168.0.0/16&lt;br /&gt;
**Loopback adresser. 127.0.0.0/8 adresserne er reserveret til internt brug på en host, og skal derfor aldrig modtages udefra, eller routes.&lt;br /&gt;
**Host autokonfigurations blok. 169.254.0.0/16 adresse området skal bruges for automatisk adresse tildeling når en DHCP server ikke forefindes.&lt;br /&gt;
**0.0.0.0/8 adresser. 0.0.0.0/8 adresserne er ikke tildelt og selv om nogle firmaer bruger dem, skal de ikke findes på internettet.&lt;br /&gt;
**Test netværks adresser. 192.0.2.0/24 er reserveret for test og beregnet til brug i dokumentation og sample kode.&lt;br /&gt;
**Klasse D og E adresser. Klasse D adresser bruges til multicast og bør derfor ikke bruges til unicast routning. Klasse E adresser er reserveret og derfor ikke i brug. Klasse D adresser = 224.0.0.0/4. Klasse E adresser = 240.0.0.0/4&lt;br /&gt;
*Sit eget netværk, for at undgå black holing&lt;br /&gt;
Da vores offentlige adresser ikke er fastlagt har jeg ikke smidt dem i configurationen:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip prefix-list martians seq 5 deny 0.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 10 deny 10.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 15 deny 172.16.0.0/12 le 32 &lt;br /&gt;
ip prefix-list martians seq 20 deny 192.168.0.0/16 le 32 &lt;br /&gt;
ip prefix-list martians seq 25 deny 127.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 30 deny 169.254.0.0/16 le 32 &lt;br /&gt;
ip prefix-list martians seq 35 deny 192.0.2.0/24 le 32 &lt;br /&gt;
ip prefix-list martians seq 40 deny 224.0.0.0/4 le 32 &lt;br /&gt;
ip prefix-list martians seq 45 deny 240.0.0.0/4 le 32 &lt;br /&gt;
ip prefix-list martians seq 50 permit 0.0.0.0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Info trukket fra RFC1918&amp;lt;ref&amp;gt;http://www.isi.edu/in-notes/rfc1918.txt&amp;lt;/ref&amp;gt; &amp;amp; RFC3330&amp;lt;ref&amp;gt;http://www.rfc-editor.org/rfc/rfc3330.txt&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===DMZ===&lt;br /&gt;
Der oprettes DMZ zoner til hver logiske funktion, f.eks Mail og webservere i hver sin zone. For at samle og lette administration samles de forskellige zoner i en separat dmz context.&lt;br /&gt;
{|&lt;br /&gt;
|[[Image:dmz-context.png|300px|left|thumb]][[Image:FW-trekant.png|300px|right|thumb]]&lt;br /&gt;
|}&lt;br /&gt;
==WAN==&lt;br /&gt;
På Univeristets hospitalet installeres 2 alternativt fremførte 500Mbit MPLS linjer fra samme udbyder da det er her hele regionens patient data er centralizeret og den vil fungere som hub for de andre sygehuse i regionen. Hvert af de andre regions hospitaler får en redundant 100Mbit MPLS.&amp;lt;br/&amp;gt;&lt;br /&gt;
Nogle af de overvejelser vi har gjort os omkring MPLS linierne er at de måske skal være dynamiske. Det vil sige man får en hurtig forbindelse men gennemsnittet skal holdes under en given trafik mængde. Vi har snakket om det da gennemsnits trafikken sikkert ikke vil være mere en hvad en 50Mbit kunne klare, men skal man fx bruge en 4 GB fil ville det tage 4000*8/50=640=6 min 40 sekunder at overføre filen. Dette er lang tid hvis man skal bruge den her og nu. En måde man kan lave flex forbindelser er ved at installere en 500Mbit forbindelse, men at man kun bruger de 500Mbit i bursts, og at gennemsnitet skal ligge på 50Mbit eller under. Dette ville gøre at samme fil kun tog lidt over et minut at hente.&lt;br /&gt;
&lt;br /&gt;
===QoS===&lt;br /&gt;
I samarbejde med MPLS udbyderen tilkøbes der QoS for at så vidt muligt at kunne levere end to end traffik prioritering. Detaljerne om hvilke QoS muligheder der er vil afhænge af udbyderen men et eksempel kunne være 5 forskellige klasser baseret på IP precedence, med en kø dedikeret til IP telephony. Desværre har man sjældent som kunde nogen indflydelse på hvad der ryger i hvilke kører og båndbredde tildelingen. Så man må typisk remarkere pakkerne i sin edge.&lt;br /&gt;
Det kan skabe problemer hvis man skifter mpls udbyder da to selskaber sjældent benytter den samme QoS model, eller hvis man benytter 2 forskellige udbydere, da pakker skal markeres forskelligt.&lt;br /&gt;
&lt;br /&gt;
=Sikkerhed=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Network Management==&lt;br /&gt;
På alle netværks enheder opsættes syslog til en central server i datacenteret, for bedre at kunne overvåge udstyret og bistå i fejlfinding. Alle enheder sættes også i samme omgang til at rapportere ind til en MARS appliance boks også placeret i datacenteret, for at kunne give et mere komplet billede af en sikkerheds situation.&lt;br /&gt;
For at lette administration og configuration af sikkerheds enhederne installeres CSManger som giver et centralt adgangspunkt til udstyret.&lt;br /&gt;
&lt;br /&gt;
CiscoWorks benyttes til at håndtere configurations ændringer samt bistå som syslog server for at hutigt og effiktivt at kunne mitigere fejl på netværket.&lt;br /&gt;
SNMP traps for udvalgte begivenheder sendes til en central opsamler, her bør der benyttes SNMPv3 for at kunne benytte kryptering imodsætning til SNMPv1+2 hvor community strengene sendes i klar tekst. Et ressource monitorerings system opsamler via SNMPv3 statestik for de enkelte enheder såsom båndbredde, interface statistik, hukommelsesforbrug osv. Alle porte skal monitoreres selv access porte, da man så vil kunne se hvor eventuelle flaskehalse opstår.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Alt adgang til netværks enhederne håndteres med Tacacs mod en ACS server som authentikerer op imod AD'et. Gruppe politikker sættes op således at kun netværks administratorene har adgang. I de tilfælde hvor udstyret ikke kan nå acs eller Domain controllerne benyttes et lokalt brugernavn og password på de enkelte bokse. Der anbefales at der fastlægges en runtine hvor disse passwords med jævne mellemrum ændres.&lt;br /&gt;
&lt;br /&gt;
==IDS==&lt;br /&gt;
Intrusion Detection System(IDS) er en enhed der overvåger det netværkstrafik den får tilsendt, og via nogle algoritmer og kendte signaturer kan finde og overvåge skidt trafik og give alarmer når der skal tages affære.&amp;lt;br/&amp;gt;&lt;br /&gt;
Der placeres en IDS sensor på den offentlige side af netværket for at kunne monitorere eventuelle angreb udefra og man kan derved hurtigt og effiktivt tage hånd om problemer indefra og udefra herunder DoS og reconnacence. Dette kan involvere et tæt samarbejde med internet udbyderne.&lt;br /&gt;
Derudover tilknyttes der også IDS sensore til edge distribution da det er det centrale knudepunkt for data til og fra hele wan og dmz og remote access til enterprise campus.&lt;br /&gt;
&lt;br /&gt;
==Ekstern adgang==&lt;br /&gt;
Eksterne firmaer som skal have adgang til interne ressourcer håndteres med minimal belastning på IT afdelingen, som i praksis udeler et brugernavn, password, definerer de tilladte ip addresser, og en vejledning til hvordan de installerer og opsætter vpn klienten.&lt;br /&gt;
Løsningen består af vpn termination på en sæt ASA appliance bokse hvor der oprettes en access-liste til hvert firma eller person således at der kun er adgang til de nøvendige ressourcer og ikke hele det interne netværk. Til dette benyttes også en certificat server placeret i DMZ'en. Afhængigt af virksomhedens præferance kan Anyconnect&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080972e4f.shtml&amp;lt;/ref&amp;gt; klienten installeres permanent eller installere/afinstallere sig selv efter behov.&lt;br /&gt;
&lt;br /&gt;
Al vpn terminering sker på et sæt ASA bokse som sidder parallelt med internettet. Vpn loadbalancing slåes til for at udnytte de tilgændelige ressourcer bedst muligt. Det anbefales at kasserne er ens, men det er ikke et krav. Der kan tilmed benyttes en vpn concentrator i clusteret.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Eksempel på dele af configuration af et eksternt firma:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
access-list companyXXX line 1 extended permit ip any &amp;lt;ip address&amp;gt; &amp;lt;subnet mask&amp;gt;&lt;br /&gt;
&lt;br /&gt;
access-list companyXXX extended deny ip any any log disable&lt;br /&gt;
group-policy companyXXX internal&lt;br /&gt;
group-policy companyXXX attributes&lt;br /&gt;
 vpn-filter value companyXXX&lt;br /&gt;
 banner value companyXXX&lt;br /&gt;
&lt;br /&gt;
ldap attribute-map AD_to_group_map&lt;br /&gt;
  map-value memberOf CN=companyXXX,LDAPCN companyXXX&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For medarbejdere der arbejder hjemmefra eller som har behov for at tilgå interne ressourer fra andre netværk, benyttes microsofts indbyggede remote access klient, hvor al opsætning styres via gruppepolitikker i AD'et.&lt;br /&gt;
&lt;br /&gt;
==Firewall==&lt;br /&gt;
Firewallen skal bestå af 2 ASA 5540 som skal have et context (virtuel firewall) for hver net (StudNet, AdmNet, PaNet, MedNet) og det vil være med til at lave Active-Active. Når 2 ASA'er bliver bundled, ses de som en maskine, med en configuration, hvor man så deler context ud til hver af dem, så ASA 1 fx bliver aktiv for StudNet og PaNet, og ASA 2 bliver aktiv for AdmNet og MedNet, samt de er backup for hinanden.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Hver context er sin egen virtuelle firewall med seperate  sikkerhedspolitikker og fungerer som havde det været adskilt i fysisk seperate enheder. En ting man dog skal være opmærksom på er at når en asa er i firewall multimode understøttes følgende features ikke:&lt;br /&gt;
*VPN&lt;br /&gt;
*Dynamisk routings protocol&lt;br /&gt;
*QoS&lt;br /&gt;
*Multicast routing&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I vores foreslåede setup vil de forskellige context dele den offenlige ip addresse via et shared interface og nat tabellen bruges til classifier ind og på udgåede traffik klafficeres der på interfacet.&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/contexts.html#wp1133984&amp;lt;/ref&amp;gt;&lt;br /&gt;
[[Image:FW_context_out.png|300px|left|thumb]][[Image:FW_context_in.png|300px|center|thumb]]&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;lt;output omitted&amp;gt;&lt;br /&gt;
hostname(config-if)# interface gigabitethernet 0/1.1&lt;br /&gt;
hostname(config-subif)# vlan 101&lt;br /&gt;
hostname(config-subif)# context MedNet&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 0/1.1&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 1/1&lt;br /&gt;
hostname(config-if)# interface gigabitethernet 0/1.2&lt;br /&gt;
hostname(config-subif)# vlan 102&lt;br /&gt;
hostname(config-subif)# context StudNet&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 0/1.2&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 1/1&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
For at sikre os mod at brugerne i en context ikke tager alle firewallens ressourcer(cpu,ram) ved et overdrevet antal nat translations og samtidinge forbindelser tildeles hver context en procentdel af enhedens totale ressourcer. Det er dog ikke alle ressourcer hvor det kan lade sig gøre såsom antal hosts og application inspections.&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mngcntxt.html&amp;lt;/ref&amp;gt; Bemærk at tallene i følgende eksempel måske ikke er retvisende da det vil kræve en større indsigt i den pågældende virksomheds traffik mønster.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname(config)# class MedNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 40%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 3000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class AdmNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 2000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class PaNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 2000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class Default&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 9000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Referenceliste==&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:CCDP]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_Firewall&amp;diff=8078</id>
		<title>Opgave CCDP - Firewall</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_Firewall&amp;diff=8078"/>
				<updated>2009-08-13T11:43:39Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* DMZ */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{In progress}}&lt;br /&gt;
[[Opgave CCDP]]&lt;br /&gt;
[[Image:CCDP-Edge.png|800px|center|thumb|Enterprise Edge Design]]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
=Internet=&lt;br /&gt;
[[Image:CCDP-WAN.png|500px|right|thumb|Multihomed Single Boarder Router Architecture]]&lt;br /&gt;
Internet bliver leveret af 2 forskellige ISP'er med alternativt fremførte linier, for at sikre sig mod kabelbrud, eller interne routnings problemer. Vi kører Routning med de 2 ISP'er og importerer alle internet routes til vores internet switch.&amp;lt;br/&amp;gt;&lt;br /&gt;
Dette gør vi for at kunne vores sekundære ISP hvis den primære har routnings problemer, men kun for de routes det er nødvendige.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vores primære internet forbindelse bliver en 100Mbit, der bliver brugt til alt, dog med regler for at StudNet og PaNet maks kan bruge 50% så der altid er plads til dem der arbejder. Den sekundære ISP linie bliver en 50Mbit, som folk fint kan leve med, indtil den primære bliver fikset igen.&lt;br /&gt;
Skulle det vise sig at hastigheden bliver uacceptable kan linierne opgraderes.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For at sikre os at alt trafik løber den rigtige vej ud af vores netværk skal BGP localpreference værdien på den primære linie sættes op, så det altid er den der bliver valgt til udgående trafik. Ved BGP er der utrolig mange parametre man kan bruge for at styre trafikken ud af sit netværk, men knap så mange man kan bruge til indgående.&amp;lt;br/&amp;gt;&lt;br /&gt;
Nogle af dem man kan bruge er AS_PATH prepending. Det vil sige man tilføjer nogle dummy AS numre. Da BGP måler afstand i AS hops, vil den tage den korteste vej fra kilde til destination. Ved at lave AS_PATH prepending på det ene link, vil AS Hop længere ud i netværket bliver større og routen vil være knap så atraktiv.&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
For at sikre sig at alt trafik i en optimal situation kommer den rigtige vej ind i ens netværk, laver man AS_PATH prepending på det link der ikke skal bruges, linket vil så se ud som om det hat en længere AS_PATH til dit netværk og derfor mindre attrativ. Dette kan gøres sådan:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
router bgp 300&lt;br /&gt;
 network 10.0.0.0&lt;br /&gt;
&lt;br /&gt;
 neighbor 10.10.10.10 remote-as 100&lt;br /&gt;
&lt;br /&gt;
 neighbor 20.20.20.20 remote-as 200&lt;br /&gt;
 neighbor 20.20.20.20 route-map as_path_prepending out&lt;br /&gt;
&lt;br /&gt;
!Tilføjer 2 ekstra hops til dit netværk&lt;br /&gt;
route-map as_path_prepending permit 10&lt;br /&gt;
 set as-path prepend 300 300&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Filtrering af trafik===&lt;br /&gt;
Når man laver en multihomed løsning er der nogle faldgrupper man skal passe på. Hvis man ikke filtrerer på de AS numrer man importerer kan man importere sin egen routing tabel, gennem sin ISP og lave et loop. Eller hvis man ikke filtrere på de paths man sender vidre, kan man være transit AS for trafik der skal et andet sted hen. Lad mig komme med nogle eksepler.&lt;br /&gt;
&lt;br /&gt;
===Transit trafik filtrering===&lt;br /&gt;
Hvis man har flere ISP'er og kører fuld routning med dem via eBGP får man alle deres routes, for at forhindre trafik mellem AS 100 og AS 200 vil løbe igennem ens netværk kan man filtrere alle eksterne AS'er fra i de udgående AS_PATH's. Det vil sige at AS 100 kun kender til AS 300 gennem linket og AS 200 også kun kender til AS 300 gennem linket til vores enterprise netværk. Dette vil forhindre at de 2 ISP'er kender nogle andre veje igennem os end til AS 300.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
Et eksempel på configuration med transit trafik filtrering hvor man ikke sender nogle andre AS numre med i sine udgående routes.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
router bgp 300&lt;br /&gt;
 network 10.0.0.0&lt;br /&gt;
&lt;br /&gt;
 neighbor 10.10.10.10 remote-as 100&lt;br /&gt;
 neighbor 10.10.10.10 route-map localonly out&lt;br /&gt;
&lt;br /&gt;
 neighbor 20.20.20.20 remote-as 200&lt;br /&gt;
 neighbor 20.20.20.20 route-map localonly out&lt;br /&gt;
&lt;br /&gt;
ip as-path access-list 10 permit ^$&lt;br /&gt;
&lt;br /&gt;
route-map localonly permit 10&lt;br /&gt;
 match as-path 10&lt;br /&gt;
end&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Inbound Filtering===&lt;br /&gt;
For at forhindre at man laver et black hole hvor trafik fra sig selv, til sig selv, ryger ud til ISP A og routed videre til ISP B hvorefter det kommer ind til dig selv igen, filtrere man sine egne ipadresser fra i indkomne routing updates. Derved sikrer man at ens netværk ikke kender andre veje til sig selv. &amp;lt;br/&amp;gt;&lt;br /&gt;
De 2 primære grupper man skal være opmærksom på:&lt;br /&gt;
*Martian adresse områder&lt;br /&gt;
**RFC 1918 adresser. Skal bruges internt i en virksomhed og aldrig komme ud på internettet. 10.0.0.0/8, 172.16.0.0/12 &amp;amp; 192.168.0.0/16&lt;br /&gt;
**Loopback adresser. 127.0.0.0/8 adresserne er reserveret til internt brug på en host, og skal derfor aldrig modtages udefra, eller routes.&lt;br /&gt;
**Host autokonfigurations blok. 169.254.0.0/16 adresse området skal bruges for automatisk adresse tildeling når en DHCP server ikke forefindes.&lt;br /&gt;
**0.0.0.0/8 adresser. 0.0.0.0/8 adresserne er ikke tildelt og selv om nogle firmaer bruger dem, skal de ikke findes på internettet.&lt;br /&gt;
**Test netværks adresser. 192.0.2.0/24 er reserveret for test og beregnet til brug i dokumentation og sample kode.&lt;br /&gt;
**Klasse D og E adresser. Klasse D adresser bruges til multicast og bør derfor ikke bruges til unicast routning. Klasse E adresser er reserveret og derfor ikke i brug. Klasse D adresser = 224.0.0.0/4. Klasse E adresser = 240.0.0.0/4&lt;br /&gt;
*Sit eget netværk, for at undgå black holing&lt;br /&gt;
Da vores offentlige adresser ikke er fastlagt har jeg ikke smidt dem i configurationen:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip prefix-list martians seq 5 deny 0.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 10 deny 10.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 15 deny 172.16.0.0/12 le 32 &lt;br /&gt;
ip prefix-list martians seq 20 deny 192.168.0.0/16 le 32 &lt;br /&gt;
ip prefix-list martians seq 25 deny 127.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 30 deny 169.254.0.0/16 le 32 &lt;br /&gt;
ip prefix-list martians seq 35 deny 192.0.2.0/24 le 32 &lt;br /&gt;
ip prefix-list martians seq 40 deny 224.0.0.0/4 le 32 &lt;br /&gt;
ip prefix-list martians seq 45 deny 240.0.0.0/4 le 32 &lt;br /&gt;
ip prefix-list martians seq 50 permit 0.0.0.0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Info trukket fra RFC1918&amp;lt;ref&amp;gt;http://www.isi.edu/in-notes/rfc1918.txt&amp;lt;/ref&amp;gt; &amp;amp; RFC3330&amp;lt;ref&amp;gt;http://www.rfc-editor.org/rfc/rfc3330.txt&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===DMZ===&lt;br /&gt;
Der oprettes DMZ zoner til hver logiske funktion, f.eks Mail og webservere i hver sin zone. For at samle og lette administration samles de forskellige zoner i en separat dmz context.&lt;br /&gt;
[[Image:dmz-context.png|300px|left|thumb]][[Image:FW-trekant.png|300px|right|thumb]]&lt;br /&gt;
&lt;br /&gt;
==WAN==&lt;br /&gt;
På Univeristets hospitalet installeres 2 alternativt fremførte 500Mbit MPLS linjer fra samme udbyder da det er her hele regionens patient data er centralizeret og den vil fungere som hub for de andre sygehuse i regionen. Hvert af de andre regions hospitaler får en redundant 100Mbit MPLS.&amp;lt;br/&amp;gt;&lt;br /&gt;
Nogle af de overvejelser vi har gjort os omkring MPLS linierne er at de måske skal være dynamiske. Det vil sige man får en hurtig forbindelse men gennemsnittet skal holdes under en given trafik mængde. Vi har snakket om det da gennemsnits trafikken sikkert ikke vil være mere en hvad en 50Mbit kunne klare, men skal man fx bruge en 4 GB fil ville det tage 4000*8/50=640=6 min 40 sekunder at overføre filen. Dette er lang tid hvis man skal bruge den her og nu. En måde man kan lave flex forbindelser er ved at installere en 500Mbit forbindelse, men at man kun bruger de 500Mbit i bursts, og at gennemsnitet skal ligge på 50Mbit eller under. Dette ville gøre at samme fil kun tog lidt over et minut at hente.&lt;br /&gt;
&lt;br /&gt;
===QoS===&lt;br /&gt;
I samarbejde med MPLS udbyderen tilkøbes der QoS for at så vidt muligt at kunne levere end to end traffik prioritering. Detaljerne om hvilke QoS muligheder der er vil afhænge af udbyderen men et eksempel kunne være 5 forskellige klasser baseret på IP precedence, med en kø dedikeret til IP telephony. Desværre har man sjældent som kunde nogen indflydelse på hvad der ryger i hvilke kører og båndbredde tildelingen. Så man må typisk remarkere pakkerne i sin edge.&lt;br /&gt;
Det kan skabe problemer hvis man skifter mpls udbyder da to selskaber sjældent benytter den samme QoS model, eller hvis man benytter 2 forskellige udbydere, da pakker skal markeres forskelligt.&lt;br /&gt;
&lt;br /&gt;
=Sikkerhed=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Network Management==&lt;br /&gt;
På alle netværks enheder opsættes syslog til en central server i datacenteret, for bedre at kunne overvåge udstyret og bistå i fejlfinding. Alle enheder sættes også i samme omgang til at rapportere ind til en MARS appliance boks også placeret i datacenteret, for at kunne give et mere komplet billede af en sikkerheds situation.&lt;br /&gt;
For at lette administration og configuration af sikkerheds enhederne installeres CSManger som giver et centralt adgangspunkt til udstyret.&lt;br /&gt;
&lt;br /&gt;
CiscoWorks benyttes til at håndtere configurations ændringer samt bistå som syslog server for at hutigt og effiktivt at kunne mitigere fejl på netværket.&lt;br /&gt;
SNMP traps for udvalgte begivenheder sendes til en central opsamler, her bør der benyttes SNMPv3 for at kunne benytte kryptering imodsætning til SNMPv1+2 hvor community strengene sendes i klar tekst. Et ressource monitorerings system opsamler via SNMPv3 statestik for de enkelte enheder såsom båndbredde, interface statistik, hukommelsesforbrug osv. Alle porte skal monitoreres selv access porte, da man så vil kunne se hvor eventuelle flaskehalse opstår.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Alt adgang til netværks enhederne håndteres med Tacacs mod en ACS server som authentikerer op imod AD'et. Gruppe politikker sættes op således at kun netværks administratorene har adgang. I de tilfælde hvor udstyret ikke kan nå acs eller Domain controllerne benyttes et lokalt brugernavn og password på de enkelte bokse. Der anbefales at der fastlægges en runtine hvor disse passwords med jævne mellemrum ændres.&lt;br /&gt;
&lt;br /&gt;
==IDS==&lt;br /&gt;
Intrusion Detection System(IDS) er en enhed der overvåger det netværkstrafik den får tilsendt, og via nogle algoritmer og kendte signaturer kan finde og overvåge skidt trafik og give alarmer når der skal tages affære.&amp;lt;br/&amp;gt;&lt;br /&gt;
Der placeres en IDS sensor på den offentlige side af netværket for at kunne monitorere eventuelle angreb udefra og man kan derved hurtigt og effiktivt tage hånd om problemer indefra og udefra herunder DoS og reconnacence. Dette kan involvere et tæt samarbejde med internet udbyderne.&lt;br /&gt;
Derudover tilknyttes der også IDS sensore til edge distribution da det er det centrale knudepunkt for data til og fra hele wan og dmz og remote access til enterprise campus.&lt;br /&gt;
&lt;br /&gt;
==Ekstern adgang==&lt;br /&gt;
Eksterne firmaer som skal have adgang til interne ressourcer håndteres med minimal belastning på IT afdelingen, som i praksis udeler et brugernavn, password, definerer de tilladte ip addresser, og en vejledning til hvordan de installerer og opsætter vpn klienten.&lt;br /&gt;
Løsningen består af vpn termination på en sæt ASA appliance bokse hvor der oprettes en access-liste til hvert firma eller person således at der kun er adgang til de nøvendige ressourcer og ikke hele det interne netværk. Til dette benyttes også en certificat server placeret i DMZ'en. Afhængigt af virksomhedens præferance kan Anyconnect&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080972e4f.shtml&amp;lt;/ref&amp;gt; klienten installeres permanent eller installere/afinstallere sig selv efter behov.&lt;br /&gt;
&lt;br /&gt;
Al vpn terminering sker på et sæt ASA bokse som sidder parallelt med internettet. Vpn loadbalancing slåes til for at udnytte de tilgændelige ressourcer bedst muligt. Det anbefales at kasserne er ens, men det er ikke et krav. Der kan tilmed benyttes en vpn concentrator i clusteret.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Eksempel på dele af configuration af et eksternt firma:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
access-list companyXXX line 1 extended permit ip any &amp;lt;ip address&amp;gt; &amp;lt;subnet mask&amp;gt;&lt;br /&gt;
&lt;br /&gt;
access-list companyXXX extended deny ip any any log disable&lt;br /&gt;
group-policy companyXXX internal&lt;br /&gt;
group-policy companyXXX attributes&lt;br /&gt;
 vpn-filter value companyXXX&lt;br /&gt;
 banner value companyXXX&lt;br /&gt;
&lt;br /&gt;
ldap attribute-map AD_to_group_map&lt;br /&gt;
  map-value memberOf CN=companyXXX,LDAPCN companyXXX&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For medarbejdere der arbejder hjemmefra eller som har behov for at tilgå interne ressourer fra andre netværk, benyttes microsofts indbyggede remote access klient, hvor al opsætning styres via gruppepolitikker i AD'et.&lt;br /&gt;
&lt;br /&gt;
==Firewall==&lt;br /&gt;
Firewallen skal bestå af 2 ASA 5540 som skal have et context (virtuel firewall) for hver net (StudNet, AdmNet, PaNet, MedNet) og det vil være med til at lave Active-Active. Når 2 ASA'er bliver bundled, ses de som en maskine, med en configuration, hvor man så deler context ud til hver af dem, så ASA 1 fx bliver aktiv for StudNet og PaNet, og ASA 2 bliver aktiv for AdmNet og MedNet, samt de er backup for hinanden.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Hver context er sin egen virtuelle firewall med seperate  sikkerhedspolitikker og fungerer som havde det været adskilt i fysisk seperate enheder. En ting man dog skal være opmærksom på er at når en asa er i firewall multimode understøttes følgende features ikke:&lt;br /&gt;
*VPN&lt;br /&gt;
*Dynamisk routings protocol&lt;br /&gt;
*QoS&lt;br /&gt;
*Multicast routing&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I vores foreslåede setup vil de forskellige context dele den offenlige ip addresse via et shared interface og nat tabellen bruges til classifier ind og på udgåede traffik klafficeres der på interfacet.&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/contexts.html#wp1133984&amp;lt;/ref&amp;gt;&lt;br /&gt;
[[Image:FW_context_out.png|300px|left|thumb]][[Image:FW_context_in.png|300px|center|thumb]]&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;lt;output omitted&amp;gt;&lt;br /&gt;
hostname(config-if)# interface gigabitethernet 0/1.1&lt;br /&gt;
hostname(config-subif)# vlan 101&lt;br /&gt;
hostname(config-subif)# context MedNet&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 0/1.1&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 1/1&lt;br /&gt;
hostname(config-if)# interface gigabitethernet 0/1.2&lt;br /&gt;
hostname(config-subif)# vlan 102&lt;br /&gt;
hostname(config-subif)# context StudNet&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 0/1.2&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 1/1&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
For at sikre os mod at brugerne i en context ikke tager alle firewallens ressourcer(cpu,ram) ved et overdrevet antal nat translations og samtidinge forbindelser tildeles hver context en procentdel af enhedens totale ressourcer. Det er dog ikke alle ressourcer hvor det kan lade sig gøre såsom antal hosts og application inspections.&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mngcntxt.html&amp;lt;/ref&amp;gt; Bemærk at tallene i følgende eksempel måske ikke er retvisende da det vil kræve en større indsigt i den pågældende virksomheds traffik mønster.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname(config)# class MedNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 40%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 3000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class AdmNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 2000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class PaNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 2000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class Default&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 9000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Referenceliste==&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:CCDP]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:Dmz-context.png&amp;diff=8077</id>
		<title>File:Dmz-context.png</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:Dmz-context.png&amp;diff=8077"/>
				<updated>2009-08-13T11:42:42Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_Firewall&amp;diff=8056</id>
		<title>Opgave CCDP - Firewall</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_Firewall&amp;diff=8056"/>
				<updated>2009-08-13T10:44:42Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* DMZ */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{In progress}}&lt;br /&gt;
[[Opgave CCDP]]&lt;br /&gt;
[[Image:CCDP-Edge.png|800px|center|thumb|Enterprise Edge Design]]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
=Internet=&lt;br /&gt;
[[Image:CCDP-WAN.png|500px|right|thumb|Multihomed Single Boarder Router Architecture]]&lt;br /&gt;
Internet bliver leveret af 2 forskellige ISP'er med alternativt fremførte linier, for at sikre sig mod kabelbrud, eller interne routnings problemer. Vi kører Routning med de 2 ISP'er og importerer alle internet routes til vores internet switch.&amp;lt;br/&amp;gt;&lt;br /&gt;
Dette gør vi for at kunne vores sekundære ISP hvis den primære har routnings problemer, men kun for de routes det er nødvendige.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vores primære internet forbindelse bliver en 100Mbit, der bliver brugt til alt, dog med regler for at StudNet og PaNet maks kan bruge 50% så der altid er plads til dem der arbejder. Den sekundære ISP linie bliver en 50Mbit, som folk fint kan leve med, indtil den primære bliver fikset igen.&lt;br /&gt;
Skulle det vise sig at hastigheden bliver uacceptable kan linierne opgraderes.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For at sikre os at alt trafik løber den rigtige vej ud af vores netværk skal BGP localpreference værdien på den primære linie sættes op, så det altid er den der bliver valgt til udgående trafik. Ved BGP er der utrolig mange parametre man kan bruge for at styre trafikken ud af sit netværk, men knap så mange man kan bruge til indgående.&amp;lt;br/&amp;gt;&lt;br /&gt;
Nogle af dem man kan bruge er AS_PATH prepending. Det vil sige man tilføjer nogle dummy AS numre. Da BGP måler afstand i AS hops, vil den tage den korteste vej fra kilde til destination. Ved at lave AS_PATH prepending på det ene link, vil AS Hop længere ud i netværket bliver større og routen vil være knap så atraktiv.&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
For at sikre sig at alt trafik i en optimal situation kommer den rigtige vej ind i ens netværk, laver man AS_PATH prepending på det link der ikke skal bruges, linket vil så se ud som om det hat en længere AS_PATH til dit netværk og derfor mindre attrativ. Dette kan gøres sådan:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
router bgp 300&lt;br /&gt;
 network 10.0.0.0&lt;br /&gt;
&lt;br /&gt;
 neighbor 10.10.10.10 remote-as 100&lt;br /&gt;
&lt;br /&gt;
 neighbor 20.20.20.20 remote-as 200&lt;br /&gt;
 neighbor 20.20.20.20 route-map as_path_prepending out&lt;br /&gt;
&lt;br /&gt;
!Tilføjer 2 ekstra hops til dit netværk&lt;br /&gt;
route-map as_path_prepending permit 10&lt;br /&gt;
 set as-path prepend 300 300&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Filtrering af trafik===&lt;br /&gt;
Når man laver en multihomed løsning er der nogle faldgrupper man skal passe på. Hvis man ikke filtrerer på de AS numrer man importerer kan man importere sin egen routing tabel, gennem sin ISP og lave et loop. Eller hvis man ikke filtrere på de paths man sender vidre, kan man være transit AS for trafik der skal et andet sted hen. Lad mig komme med nogle eksepler.&lt;br /&gt;
&lt;br /&gt;
===Transit trafik filtrering===&lt;br /&gt;
Hvis man har flere ISP'er og kører fuld routning med dem via eBGP får man alle deres routes, for at forhindre trafik mellem AS 100 og AS 200 vil løbe igennem ens netværk kan man filtrere alle eksterne AS'er fra i de udgående AS_PATH's. Det vil sige at AS 100 kun kender til AS 300 gennem linket og AS 200 også kun kender til AS 300 gennem linket til vores enterprise netværk. Dette vil forhindre at de 2 ISP'er kender nogle andre veje igennem os end til AS 300.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
Et eksempel på configuration med transit trafik filtrering hvor man ikke sender nogle andre AS numre med i sine udgående routes.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
router bgp 300&lt;br /&gt;
 network 10.0.0.0&lt;br /&gt;
&lt;br /&gt;
 neighbor 10.10.10.10 remote-as 100&lt;br /&gt;
 neighbor 10.10.10.10 route-map localonly out&lt;br /&gt;
&lt;br /&gt;
 neighbor 20.20.20.20 remote-as 200&lt;br /&gt;
 neighbor 20.20.20.20 route-map localonly out&lt;br /&gt;
&lt;br /&gt;
ip as-path access-list 10 permit ^$&lt;br /&gt;
&lt;br /&gt;
route-map localonly permit 10&lt;br /&gt;
 match as-path 10&lt;br /&gt;
end&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Inbound Filtering===&lt;br /&gt;
For at forhindre at man laver et black hole hvor trafik fra sig selv, til sig selv, ryger ud til ISP A og routed videre til ISP B hvorefter det kommer ind til dig selv igen, filtrere man sine egne ipadresser fra i indkomne routing updates. Derved sikrer man at ens netværk ikke kender andre veje til sig selv. &amp;lt;br/&amp;gt;&lt;br /&gt;
De 2 primære grupper man skal være opmærksom på:&lt;br /&gt;
*Martian adresse områder&lt;br /&gt;
**RFC 1918 adresser. Skal bruges internt i en virksomhed og aldrig komme ud på internettet. 10.0.0.0/8, 172.16.0.0/12 &amp;amp; 192.168.0.0/16&lt;br /&gt;
**Loopback adresser. 127.0.0.0/8 adresserne er reserveret til internt brug på en host, og skal derfor aldrig modtages udefra, eller routes.&lt;br /&gt;
**Host autokonfigurations blok. 169.254.0.0/16 adresse området skal bruges for automatisk adresse tildeling når en DHCP server ikke forefindes.&lt;br /&gt;
**0.0.0.0/8 adresser. 0.0.0.0/8 adresserne er ikke tildelt og selv om nogle firmaer bruger dem, skal de ikke findes på internettet.&lt;br /&gt;
**Test netværks adresser. 192.0.2.0/24 er reserveret for test og beregnet til brug i dokumentation og sample kode.&lt;br /&gt;
**Klasse D og E adresser. Klasse D adresser bruges til multicast og bør derfor ikke bruges til unicast routning. Klasse E adresser er reserveret og derfor ikke i brug. Klasse D adresser = 224.0.0.0/4. Klasse E adresser = 240.0.0.0/4&lt;br /&gt;
*Sit eget netværk, for at undgå black holing&lt;br /&gt;
Da vores offentlige adresser ikke er fastlagt har jeg ikke smidt dem i configurationen:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip prefix-list martians seq 5 deny 0.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 10 deny 10.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 15 deny 172.16.0.0/12 le 32 &lt;br /&gt;
ip prefix-list martians seq 20 deny 192.168.0.0/16 le 32 &lt;br /&gt;
ip prefix-list martians seq 25 deny 127.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 30 deny 169.254.0.0/16 le 32 &lt;br /&gt;
ip prefix-list martians seq 35 deny 192.0.2.0/24 le 32 &lt;br /&gt;
ip prefix-list martians seq 40 deny 224.0.0.0/4 le 32 &lt;br /&gt;
ip prefix-list martians seq 45 deny 240.0.0.0/4 le 32 &lt;br /&gt;
ip prefix-list martians seq 50 permit 0.0.0.0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Info trukket fra RFC1918&amp;lt;ref&amp;gt;http://www.isi.edu/in-notes/rfc1918.txt&amp;lt;/ref&amp;gt; &amp;amp; RFC3330&amp;lt;ref&amp;gt;http://www.rfc-editor.org/rfc/rfc3330.txt&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===DMZ===&lt;br /&gt;
Der oprettes DMZ zoner til hver logiske funktion, f.eks Mail og webservere i hver sin zone. For at samle og lette administration samles de forskellige zoner i en separat dmz context.&lt;br /&gt;
[[Image:FW-trekant.png|300px|right|thumb]]&lt;br /&gt;
&lt;br /&gt;
==WAN==&lt;br /&gt;
På Univeristets hospitalet installeres 2 alternativt fremførte 500Mbit MPLS linjer fra samme udbyder da det er her hele regionens patient data er centralizeret og den vil fungere som hub for de andre sygehuse i regionen. Hvert af de andre regions hospitaler får en redundant 100Mbit MPLS.&amp;lt;br/&amp;gt;&lt;br /&gt;
Nogle af de overvejelser vi har gjort os omkring MPLS linierne er at de måske skal være dynamiske. Det vil sige man får en hurtig forbindelse men gennemsnittet skal holdes under en given trafik mængde. Vi har snakket om det da gennemsnits trafikken sikkert ikke vil være mere en hvad en 50Mbit kunne klare, men skal man fx bruge en 4 GB fil ville det tage 4000*8/50=640=6 min 40 sekunder at overføre filen. Dette er lang tid hvis man skal bruge den her og nu. En måde man kan lave flex forbindelser er ved at installere en 500Mbit forbindelse, men at man kun bruger de 500Mbit i bursts, og at gennemsnitet skal ligge på 50Mbit eller under. Dette ville gøre at samme fil kun tog lidt over et minut at hente.&lt;br /&gt;
&lt;br /&gt;
===QoS===&lt;br /&gt;
I samarbejde med MPLS udbyderen tilkøbes der QoS for at så vidt muligt at kunne levere end to end traffik prioritering. Detaljerne om hvilke QoS muligheder der er vil afhænge af udbyderen men et eksempel kunne være 5 forskellige klasser baseret på IP precedence, med en kø dedikeret til IP telephony. Desværre har man sjældent som kunde nogen indflydelse på hvad der ryger i hvilke kører og båndbredde tildelingen. Så man må typisk remarkere pakkerne i sin edge.&lt;br /&gt;
Det kan skabe problemer hvis man skifter mpls udbyder da to selskaber sjældent benytter den samme QoS model, eller hvis man benytter 2 forskellige udbydere, da pakker skal markeres forskelligt.&lt;br /&gt;
&lt;br /&gt;
=Sikkerhed=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Network Management==&lt;br /&gt;
På alle netværks enheder opsættes syslog til en central server i datacenteret, for bedre at kunne overvåge udstyret og bistå i fejlfinding. Alle enheder sættes også i samme omgang til at rapportere ind til en MARS appliance boks også placeret i datacenteret, for at kunne give et mere komplet billede af en sikkerheds situation.&lt;br /&gt;
For at lette administration og configuration af sikkerheds enhederne installeres CSManger som giver et centralt adgangspunkt til udstyret.&lt;br /&gt;
&lt;br /&gt;
CiscoWorks benyttes til at håndtere configurations ændringer samt bistå som syslog server for at hutigt og effiktivt at kunne mitigere fejl på netværket.&lt;br /&gt;
SNMP traps for udvalgte begivenheder sendes til en central opsamler, her bør der benyttes SNMPv3 for at kunne benytte kryptering imodsætning til SNMPv1+2 hvor community strengene sendes i klar tekst. Et ressource monitorerings system opsamler via SNMPv3 statestik for de enkelte enheder såsom båndbredde, interface statistik, hukommelsesforbrug osv. Alle porte skal monitoreres selv access porte, da man så vil kunne se hvor eventuelle flaskehalse opstår.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Alt adgang til netværks enhederne håndteres med Tacacs mod en ACS server som authentikerer op imod AD'et. Gruppe politikker sættes op således at kun netværks administratorene har adgang. I de tilfælde hvor udstyret ikke kan nå acs eller Domain controllerne benyttes et lokalt brugernavn og password på de enkelte bokse. Der anbefales at der fastlægges en runtine hvor disse passwords med jævne mellemrum ændres.&lt;br /&gt;
&lt;br /&gt;
==IDS==&lt;br /&gt;
Intrusion Detection System(IDS) er en enhed der overvåger det netværkstrafik den får tilsendt, og via nogle algoritmer og kendte signaturer kan finde og overvåge skidt trafik og give alarmer når der skal tages affære.&amp;lt;br/&amp;gt;&lt;br /&gt;
Der placeres en IDS sensor på den offentlige side af netværket for at kunne monitorere eventuelle angreb udefra og man kan derved hurtigt og effiktivt tage hånd om problemer indefra og udefra herunder DoS og reconnacence. Dette kan involvere et tæt samarbejde med internet udbyderne.&lt;br /&gt;
Derudover tilknyttes der også IDS sensore til edge distribution da det er det centrale knudepunkt for data til og fra hele wan og dmz og remote access til enterprise campus.&lt;br /&gt;
&lt;br /&gt;
==Ekstern adgang==&lt;br /&gt;
Eksterne firmaer som skal have adgang til interne ressourcer håndteres med minimal belastning på IT afdelingen, som i praksis udeler et brugernavn, password, definerer de tilladte ip addresser, og en vejledning til hvordan de installerer og opsætter vpn klienten.&lt;br /&gt;
Løsningen består af vpn termination på en sæt ASA appliance bokse hvor der oprettes en access-liste til hvert firma eller person således at der kun er adgang til de nøvendige ressourcer og ikke hele det interne netværk. Til dette benyttes også en certificat server placeret i DMZ'en. Afhængigt af virksomhedens præferance kan Anyconnect&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080972e4f.shtml&amp;lt;/ref&amp;gt; klienten installeres permanent eller installere/afinstallere sig selv efter behov.&lt;br /&gt;
&lt;br /&gt;
Al vpn terminering sker på et sæt ASA bokse som sidder parallelt med internettet. Vpn loadbalancing slåes til for at udnytte de tilgændelige ressourcer bedst muligt. Det anbefales at kasserne er ens, men det er ikke et krav. Der kan tilmed benyttes en vpn concentrator i clusteret.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Eksempel på dele af configuration af et eksternt firma:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
access-list companyXXX line 1 extended permit ip any &amp;lt;ip address&amp;gt; &amp;lt;subnet mask&amp;gt;&lt;br /&gt;
&lt;br /&gt;
access-list companyXXX extended deny ip any any log disable&lt;br /&gt;
group-policy companyXXX internal&lt;br /&gt;
group-policy companyXXX attributes&lt;br /&gt;
 vpn-filter value companyXXX&lt;br /&gt;
 banner value companyXXX&lt;br /&gt;
&lt;br /&gt;
ldap attribute-map AD_to_group_map&lt;br /&gt;
  map-value memberOf CN=companyXXX,LDAPCN companyXXX&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For medarbejdere der arbejder hjemmefra eller som har behov for at tilgå interne ressourer fra andre netværk, benyttes microsofts indbyggede remote access klient, hvor al opsætning styres via gruppepolitikker i AD'et.&lt;br /&gt;
&lt;br /&gt;
==Firewall==&lt;br /&gt;
Firewallen skal bestå af 2 ASA 5540 som skal have et context (virtuel firewall) for hver net (StudNet, AdmNet, PaNet, MedNet) og det vil være med til at lave Active-Active. Når 2 ASA'er bliver bundled, ses de som en maskine, med en configuration, hvor man så deler context ud til hver af dem, så ASA 1 fx bliver aktiv for StudNet og PaNet, og ASA 2 bliver aktiv for AdmNet og MedNet, samt de er backup for hinanden.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Hver context er sin egen virtuelle firewall med seperate  sikkerhedspolitikker og fungerer som havde det været adskilt i fysisk seperate enheder. En ting man dog skal være opmærksom på er at når en asa er i firewall multimode understøttes følgende features ikke:&lt;br /&gt;
*VPN&lt;br /&gt;
*Dynamisk routings protocol&lt;br /&gt;
*QoS&lt;br /&gt;
*Multicast routing&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I vores foreslåede setup vil de forskellige context dele den offenlige ip addresse via et shared interface og nat tabellen bruges til classifier ind og på udgåede traffik klafficeres der på interfacet.&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/contexts.html#wp1133984&amp;lt;/ref&amp;gt;&lt;br /&gt;
[[Image:FW_context_out.png|300px|left|thumb]][[Image:FW_context_in.png|300px|center|thumb]]&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;lt;output omitted&amp;gt;&lt;br /&gt;
hostname(config-if)# interface gigabitethernet 0/1.1&lt;br /&gt;
hostname(config-subif)# vlan 101&lt;br /&gt;
hostname(config-subif)# context MedNet&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 0/1.1&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 1/1&lt;br /&gt;
hostname(config-if)# interface gigabitethernet 0/1.2&lt;br /&gt;
hostname(config-subif)# vlan 102&lt;br /&gt;
hostname(config-subif)# context StudNet&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 0/1.2&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 1/1&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
For at sikre os mod at brugerne i en context ikke tager alle firewallens ressourcer(cpu,ram) ved et overdrevet antal nat translations og samtidinge forbindelser tildeles hver context en procentdel af enhedens totale ressourcer. Det er dog ikke alle ressourcer hvor det kan lade sig gøre såsom antal hosts og application inspections.&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mngcntxt.html&amp;lt;/ref&amp;gt; Bemærk at tallene i følgende eksempel måske ikke er retvisende da det vil kræve en større indsigt i den pågældende virksomheds traffik mønster.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname(config)# class MedNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 40%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 3000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class AdmNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 2000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class PaNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 2000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class Default&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 9000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Referenceliste==&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:CCDP]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_Firewall&amp;diff=8054</id>
		<title>Opgave CCDP - Firewall</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_Firewall&amp;diff=8054"/>
				<updated>2009-08-13T10:30:15Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* DMZ */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{In progress}}&lt;br /&gt;
[[Opgave CCDP]]&lt;br /&gt;
[[Image:CCDP-Edge.png|800px|center|thumb|Enterprise Edge Design]]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
=Internet=&lt;br /&gt;
[[Image:CCDP-WAN.png|500px|right|thumb|Multihomed Single Boarder Router Architecture]]&lt;br /&gt;
Internet bliver leveret af 2 forskellige ISP'er med alternativt fremførte linier, for at sikre sig mod kabelbrud, eller interne routnings problemer. Vi kører Routning med de 2 ISP'er og importerer alle internet routes til vores internet switch.&amp;lt;br/&amp;gt;&lt;br /&gt;
Dette gør vi for at kunne vores sekundære ISP hvis den primære har routnings problemer, men kun for de routes det er nødvendige.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vores primære internet forbindelse bliver en 100Mbit, der bliver brugt til alt, dog med regler for at StudNet og PaNet maks kan bruge 50% så der altid er plads til dem der arbejder. Den sekundære ISP linie bliver en 50Mbit, som folk fint kan leve med, indtil den primære bliver fikset igen.&lt;br /&gt;
Skulle det vise sig at hastigheden bliver uacceptable kan linierne opgraderes.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For at sikre os at alt trafik løber den rigtige vej ud af vores netværk skal BGP localpreference værdien på den primære linie sættes op, så det altid er den der bliver valgt til udgående trafik. Ved BGP er der utrolig mange parametre man kan bruge for at styre trafikken ud af sit netværk, men knap så mange man kan bruge til indgående.&amp;lt;br/&amp;gt;&lt;br /&gt;
Nogle af dem man kan bruge er AS_PATH prepending. Det vil sige man tilføjer nogle dummy AS numre. Da BGP måler afstand i AS hops, vil den tage den korteste vej fra kilde til destination. Ved at lave AS_PATH prepending på det ene link, vil AS Hop længere ud i netværket bliver større og routen vil være knap så atraktiv.&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
For at sikre sig at alt trafik i en optimal situation kommer den rigtige vej ind i ens netværk, laver man AS_PATH prepending på det link der ikke skal bruges, linket vil så se ud som om det hat en længere AS_PATH til dit netværk og derfor mindre attrativ. Dette kan gøres sådan:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
router bgp 300&lt;br /&gt;
 network 10.0.0.0&lt;br /&gt;
&lt;br /&gt;
 neighbor 10.10.10.10 remote-as 100&lt;br /&gt;
&lt;br /&gt;
 neighbor 20.20.20.20 remote-as 200&lt;br /&gt;
 neighbor 20.20.20.20 route-map as_path_prepending out&lt;br /&gt;
&lt;br /&gt;
!Tilføjer 2 ekstra hops til dit netværk&lt;br /&gt;
route-map as_path_prepending permit 10&lt;br /&gt;
 set as-path prepend 300 300&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Filtrering af trafik===&lt;br /&gt;
Når man laver en multihomed løsning er der nogle faldgrupper man skal passe på. Hvis man ikke filtrerer på de AS numrer man importerer kan man importere sin egen routing tabel, gennem sin ISP og lave et loop. Eller hvis man ikke filtrere på de paths man sender vidre, kan man være transit AS for trafik der skal et andet sted hen. Lad mig komme med nogle eksepler.&lt;br /&gt;
&lt;br /&gt;
===Transit trafik filtrering===&lt;br /&gt;
Hvis man har flere ISP'er og kører fuld routning med dem via eBGP får man alle deres routes, for at forhindre trafik mellem AS 100 og AS 200 vil løbe igennem ens netværk kan man filtrere alle eksterne AS'er fra i de udgående AS_PATH's. Det vil sige at AS 100 kun kender til AS 300 gennem linket og AS 200 også kun kender til AS 300 gennem linket til vores enterprise netværk. Dette vil forhindre at de 2 ISP'er kender nogle andre veje igennem os end til AS 300.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
Et eksempel på configuration med transit trafik filtrering hvor man ikke sender nogle andre AS numre med i sine udgående routes.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
router bgp 300&lt;br /&gt;
 network 10.0.0.0&lt;br /&gt;
&lt;br /&gt;
 neighbor 10.10.10.10 remote-as 100&lt;br /&gt;
 neighbor 10.10.10.10 route-map localonly out&lt;br /&gt;
&lt;br /&gt;
 neighbor 20.20.20.20 remote-as 200&lt;br /&gt;
 neighbor 20.20.20.20 route-map localonly out&lt;br /&gt;
&lt;br /&gt;
ip as-path access-list 10 permit ^$&lt;br /&gt;
&lt;br /&gt;
route-map localonly permit 10&lt;br /&gt;
 match as-path 10&lt;br /&gt;
end&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Inbound Filtering===&lt;br /&gt;
For at forhindre at man laver et black hole hvor trafik fra sig selv, til sig selv, ryger ud til ISP A og routed videre til ISP B hvorefter det kommer ind til dig selv igen, filtrere man sine egne ipadresser fra i indkomne routing updates. Derved sikrer man at ens netværk ikke kender andre veje til sig selv. &amp;lt;br/&amp;gt;&lt;br /&gt;
De 2 primære grupper man skal være opmærksom på:&lt;br /&gt;
*Martian adresse områder&lt;br /&gt;
**RFC 1918 adresser. Skal bruges internt i en virksomhed og aldrig komme ud på internettet. 10.0.0.0/8, 172.16.0.0/12 &amp;amp; 192.168.0.0/16&lt;br /&gt;
**Loopback adresser. 127.0.0.0/8 adresserne er reserveret til internt brug på en host, og skal derfor aldrig modtages udefra, eller routes.&lt;br /&gt;
**Host autokonfigurations blok. 169.254.0.0/16 adresse området skal bruges for automatisk adresse tildeling når en DHCP server ikke forefindes.&lt;br /&gt;
**0.0.0.0/8 adresser. 0.0.0.0/8 adresserne er ikke tildelt og selv om nogle firmaer bruger dem, skal de ikke findes på internettet.&lt;br /&gt;
**Test netværks adresser. 192.0.2.0/24 er reserveret for test og beregnet til brug i dokumentation og sample kode.&lt;br /&gt;
**Klasse D og E adresser. Klasse D adresser bruges til multicast og bør derfor ikke bruges til unicast routning. Klasse E adresser er reserveret og derfor ikke i brug. Klasse D adresser = 224.0.0.0/4. Klasse E adresser = 240.0.0.0/4&lt;br /&gt;
*Sit eget netværk, for at undgå black holing&lt;br /&gt;
Da vores offentlige adresser ikke er fastlagt har jeg ikke smidt dem i configurationen:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip prefix-list martians seq 5 deny 0.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 10 deny 10.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 15 deny 172.16.0.0/12 le 32 &lt;br /&gt;
ip prefix-list martians seq 20 deny 192.168.0.0/16 le 32 &lt;br /&gt;
ip prefix-list martians seq 25 deny 127.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 30 deny 169.254.0.0/16 le 32 &lt;br /&gt;
ip prefix-list martians seq 35 deny 192.0.2.0/24 le 32 &lt;br /&gt;
ip prefix-list martians seq 40 deny 224.0.0.0/4 le 32 &lt;br /&gt;
ip prefix-list martians seq 45 deny 240.0.0.0/4 le 32 &lt;br /&gt;
ip prefix-list martians seq 50 permit 0.0.0.0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Info trukket fra RFC1918&amp;lt;ref&amp;gt;http://www.isi.edu/in-notes/rfc1918.txt&amp;lt;/ref&amp;gt; &amp;amp; RFC3330&amp;lt;ref&amp;gt;http://www.rfc-editor.org/rfc/rfc3330.txt&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===DMZ===&lt;br /&gt;
Der oprettes DMZ zoner til hver logiske funktion, f.eks Mail og webservere i hver sin zone. På &lt;br /&gt;
[[Image:FW-trekant.png|300px|right|thumb]]&lt;br /&gt;
&lt;br /&gt;
==WAN==&lt;br /&gt;
På Univeristets hospitalet installeres 2 alternativt fremførte 500Mbit MPLS linjer fra samme udbyder da det er her hele regionens patient data er centralizeret og den vil fungere som hub for de andre sygehuse i regionen. Hvert af de andre regions hospitaler får en redundant 100Mbit MPLS.&amp;lt;br/&amp;gt;&lt;br /&gt;
Nogle af de overvejelser vi har gjort os omkring MPLS linierne er at de måske skal være dynamiske. Det vil sige man får en hurtig forbindelse men gennemsnittet skal holdes under en given trafik mængde. Vi har snakket om det da gennemsnits trafikken sikkert ikke vil være mere en hvad en 50Mbit kunne klare, men skal man fx bruge en 4 GB fil ville det tage 4000*8/50=640=6 min 40 sekunder at overføre filen. Dette er lang tid hvis man skal bruge den her og nu. En måde man kan lave flex forbindelser er ved at installere en 500Mbit forbindelse, men at man kun bruger de 500Mbit i bursts, og at gennemsnitet skal ligge på 50Mbit eller under. Dette ville gøre at samme fil kun tog lidt over et minut at hente.&lt;br /&gt;
&lt;br /&gt;
===QoS===&lt;br /&gt;
I samarbejde med MPLS udbyderen tilkøbes der QoS for at så vidt muligt at kunne levere end to end traffik prioritering. Detaljerne om hvilke QoS muligheder der er vil afhænge af udbyderen men et eksempel kunne være 5 forskellige klasser baseret på IP precedence, med en kø dedikeret til IP telephony. Desværre har man sjældent som kunde nogen indflydelse på hvad der ryger i hvilke kører og båndbredde tildelingen. Så man må typisk remarkere pakkerne i sin edge.&lt;br /&gt;
Det kan skabe problemer hvis man skifter mpls udbyder da to selskaber sjældent benytter den samme QoS model, eller hvis man benytter 2 forskellige udbydere, da pakker skal markeres forskelligt.&lt;br /&gt;
&lt;br /&gt;
=Sikkerhed=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Network Management==&lt;br /&gt;
På alle netværks enheder opsættes syslog til en central server i datacenteret, for bedre at kunne overvåge udstyret og bistå i fejlfinding. Alle enheder sættes også i samme omgang til at rapportere ind til en MARS appliance boks også placeret i datacenteret, for at kunne give et mere komplet billede af en sikkerheds situation.&lt;br /&gt;
For at lette administration og configuration af sikkerheds enhederne installeres CSManger som giver et centralt adgangspunkt til udstyret.&lt;br /&gt;
&lt;br /&gt;
CiscoWorks benyttes til at håndtere configurations ændringer samt bistå som syslog server for at hutigt og effiktivt at kunne mitigere fejl på netværket.&lt;br /&gt;
SNMP traps for udvalgte begivenheder sendes til en central opsamler, her bør der benyttes SNMPv3 for at kunne benytte kryptering imodsætning til SNMPv1+2 hvor community strengene sendes i klar tekst. Et ressource monitorerings system opsamler via SNMPv3 statestik for de enkelte enheder såsom båndbredde, interface statistik, hukommelsesforbrug osv. Alle porte skal monitoreres selv access porte, da man så vil kunne se hvor eventuelle flaskehalse opstår.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Alt adgang til netværks enhederne håndteres med Tacacs mod en ACS server som authentikerer op imod AD'et. Gruppe politikker sættes op således at kun netværks administratorene har adgang. I de tilfælde hvor udstyret ikke kan nå acs eller Domain controllerne benyttes et lokalt brugernavn og password på de enkelte bokse. Der anbefales at der fastlægges en runtine hvor disse passwords med jævne mellemrum ændres.&lt;br /&gt;
&lt;br /&gt;
==IDS==&lt;br /&gt;
Intrusion Detection System(IDS) er en enhed der overvåger det netværkstrafik den får tilsendt, og via nogle algoritmer og kendte signaturer kan finde og overvåge skidt trafik og give alarmer når der skal tages affære.&amp;lt;br/&amp;gt;&lt;br /&gt;
Der placeres en IDS sensor på den offentlige side af netværket for at kunne monitorere eventuelle angreb udefra og man kan derved hurtigt og effiktivt tage hånd om problemer indefra og udefra herunder DoS og reconnacence. Dette kan involvere et tæt samarbejde med internet udbyderne.&lt;br /&gt;
Derudover tilknyttes der også IDS sensore til edge distribution da det er det centrale knudepunkt for data til og fra hele wan og dmz og remote access til enterprise campus.&lt;br /&gt;
&lt;br /&gt;
==Ekstern adgang==&lt;br /&gt;
Eksterne firmaer som skal have adgang til interne ressourcer håndteres med minimal belastning på IT afdelingen, som i praksis udeler et brugernavn, password, definerer de tilladte ip addresser, og en vejledning til hvordan de installerer og opsætter vpn klienten.&lt;br /&gt;
Løsningen består af vpn termination på en sæt ASA appliance bokse hvor der oprettes en access-liste til hvert firma eller person således at der kun er adgang til de nøvendige ressourcer og ikke hele det interne netværk. Til dette benyttes også en certificat server placeret i DMZ'en. Afhængigt af virksomhedens præferance kan Anyconnect&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080972e4f.shtml&amp;lt;/ref&amp;gt; klienten installeres permanent eller installere/afinstallere sig selv efter behov.&lt;br /&gt;
&lt;br /&gt;
Al vpn terminering sker på et sæt ASA bokse som sidder parallelt med internettet. Vpn loadbalancing slåes til for at udnytte de tilgændelige ressourcer bedst muligt. Det anbefales at kasserne er ens, men det er ikke et krav. Der kan tilmed benyttes en vpn concentrator i clusteret.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Eksempel på dele af configuration af et eksternt firma:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
access-list companyXXX line 1 extended permit ip any &amp;lt;ip address&amp;gt; &amp;lt;subnet mask&amp;gt;&lt;br /&gt;
&lt;br /&gt;
access-list companyXXX extended deny ip any any log disable&lt;br /&gt;
group-policy companyXXX internal&lt;br /&gt;
group-policy companyXXX attributes&lt;br /&gt;
 vpn-filter value companyXXX&lt;br /&gt;
 banner value companyXXX&lt;br /&gt;
&lt;br /&gt;
ldap attribute-map AD_to_group_map&lt;br /&gt;
  map-value memberOf CN=companyXXX,LDAPCN companyXXX&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For medarbejdere der arbejder hjemmefra eller som har behov for at tilgå interne ressourer fra andre netværk, benyttes microsofts indbyggede remote access klient, hvor al opsætning styres via gruppepolitikker i AD'et.&lt;br /&gt;
&lt;br /&gt;
==Firewall==&lt;br /&gt;
Firewallen skal bestå af 2 ASA 5540 som skal have et context (virtuel firewall) for hver net (StudNet, AdmNet, PaNet, MedNet) og det vil være med til at lave Active-Active. Når 2 ASA'er bliver bundled, ses de som en maskine, med en configuration, hvor man så deler context ud til hver af dem, så ASA 1 fx bliver aktiv for StudNet og PaNet, og ASA 2 bliver aktiv for AdmNet og MedNet, samt de er backup for hinanden.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Hver context er sin egen virtuelle firewall med seperate  sikkerhedspolitikker og fungerer som havde det været adskilt i fysisk seperate enheder. En ting man dog skal være opmærksom på er at når en asa er i firewall multimode understøttes følgende features ikke:&lt;br /&gt;
*VPN&lt;br /&gt;
*Dynamisk routings protocol&lt;br /&gt;
*QoS&lt;br /&gt;
*Multicast routing&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I vores foreslåede setup vil de forskellige context dele den offenlige ip addresse via et shared interface og nat tabellen bruges til classifier ind og på udgåede traffik klafficeres der på interfacet.&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/contexts.html#wp1133984&amp;lt;/ref&amp;gt;&lt;br /&gt;
[[Image:FW_context_out.png|300px|left|thumb]][[Image:FW_context_in.png|300px|center|thumb]]&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;lt;output omitted&amp;gt;&lt;br /&gt;
hostname(config-if)# interface gigabitethernet 0/1.1&lt;br /&gt;
hostname(config-subif)# vlan 101&lt;br /&gt;
hostname(config-subif)# context MedNet&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 0/1.1&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 1/1&lt;br /&gt;
hostname(config-if)# interface gigabitethernet 0/1.2&lt;br /&gt;
hostname(config-subif)# vlan 102&lt;br /&gt;
hostname(config-subif)# context StudNet&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 0/1.2&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 1/1&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
For at sikre os mod at brugerne i en context ikke tager alle firewallens ressourcer(cpu,ram) ved et overdrevet antal nat translations og samtidinge forbindelser tildeles hver context en procentdel af enhedens totale ressourcer. Det er dog ikke alle ressourcer hvor det kan lade sig gøre såsom antal hosts og application inspections.&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mngcntxt.html&amp;lt;/ref&amp;gt; Bemærk at tallene i følgende eksempel måske ikke er retvisende da det vil kræve en større indsigt i den pågældende virksomheds traffik mønster.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname(config)# class MedNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 40%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 3000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class AdmNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 2000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class PaNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 2000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class Default&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 9000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Referenceliste==&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:CCDP]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_Firewall&amp;diff=8053</id>
		<title>Opgave CCDP - Firewall</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_Firewall&amp;diff=8053"/>
				<updated>2009-08-13T10:22:47Z</updated>
		
		<summary type="html">&lt;p&gt;Sahan109: /* Alternativer */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{In progress}}&lt;br /&gt;
[[Opgave CCDP]]&lt;br /&gt;
[[Image:CCDP-Edge.png|800px|center|thumb|Enterprise Edge Design]]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
=Internet=&lt;br /&gt;
[[Image:CCDP-WAN.png|500px|right|thumb|Multihomed Single Boarder Router Architecture]]&lt;br /&gt;
Internet bliver leveret af 2 forskellige ISP'er med alternativt fremførte linier, for at sikre sig mod kabelbrud, eller interne routnings problemer. Vi kører Routning med de 2 ISP'er og importerer alle internet routes til vores internet switch.&amp;lt;br/&amp;gt;&lt;br /&gt;
Dette gør vi for at kunne vores sekundære ISP hvis den primære har routnings problemer, men kun for de routes det er nødvendige.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vores primære internet forbindelse bliver en 100Mbit, der bliver brugt til alt, dog med regler for at StudNet og PaNet maks kan bruge 50% så der altid er plads til dem der arbejder. Den sekundære ISP linie bliver en 50Mbit, som folk fint kan leve med, indtil den primære bliver fikset igen.&lt;br /&gt;
Skulle det vise sig at hastigheden bliver uacceptable kan linierne opgraderes.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For at sikre os at alt trafik løber den rigtige vej ud af vores netværk skal BGP localpreference værdien på den primære linie sættes op, så det altid er den der bliver valgt til udgående trafik. Ved BGP er der utrolig mange parametre man kan bruge for at styre trafikken ud af sit netværk, men knap så mange man kan bruge til indgående.&amp;lt;br/&amp;gt;&lt;br /&gt;
Nogle af dem man kan bruge er AS_PATH prepending. Det vil sige man tilføjer nogle dummy AS numre. Da BGP måler afstand i AS hops, vil den tage den korteste vej fra kilde til destination. Ved at lave AS_PATH prepending på det ene link, vil AS Hop længere ud i netværket bliver større og routen vil være knap så atraktiv.&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
For at sikre sig at alt trafik i en optimal situation kommer den rigtige vej ind i ens netværk, laver man AS_PATH prepending på det link der ikke skal bruges, linket vil så se ud som om det hat en længere AS_PATH til dit netværk og derfor mindre attrativ. Dette kan gøres sådan:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
router bgp 300&lt;br /&gt;
 network 10.0.0.0&lt;br /&gt;
&lt;br /&gt;
 neighbor 10.10.10.10 remote-as 100&lt;br /&gt;
&lt;br /&gt;
 neighbor 20.20.20.20 remote-as 200&lt;br /&gt;
 neighbor 20.20.20.20 route-map as_path_prepending out&lt;br /&gt;
&lt;br /&gt;
!Tilføjer 2 ekstra hops til dit netværk&lt;br /&gt;
route-map as_path_prepending permit 10&lt;br /&gt;
 set as-path prepend 300 300&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Filtrering af trafik===&lt;br /&gt;
Når man laver en multihomed løsning er der nogle faldgrupper man skal passe på. Hvis man ikke filtrerer på de AS numrer man importerer kan man importere sin egen routing tabel, gennem sin ISP og lave et loop. Eller hvis man ikke filtrere på de paths man sender vidre, kan man være transit AS for trafik der skal et andet sted hen. Lad mig komme med nogle eksepler.&lt;br /&gt;
&lt;br /&gt;
===Transit trafik filtrering===&lt;br /&gt;
Hvis man har flere ISP'er og kører fuld routning med dem via eBGP får man alle deres routes, for at forhindre trafik mellem AS 100 og AS 200 vil løbe igennem ens netværk kan man filtrere alle eksterne AS'er fra i de udgående AS_PATH's. Det vil sige at AS 100 kun kender til AS 300 gennem linket og AS 200 også kun kender til AS 300 gennem linket til vores enterprise netværk. Dette vil forhindre at de 2 ISP'er kender nogle andre veje igennem os end til AS 300.&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
Et eksempel på configuration med transit trafik filtrering hvor man ikke sender nogle andre AS numre med i sine udgående routes.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
router bgp 300&lt;br /&gt;
 network 10.0.0.0&lt;br /&gt;
&lt;br /&gt;
 neighbor 10.10.10.10 remote-as 100&lt;br /&gt;
 neighbor 10.10.10.10 route-map localonly out&lt;br /&gt;
&lt;br /&gt;
 neighbor 20.20.20.20 remote-as 200&lt;br /&gt;
 neighbor 20.20.20.20 route-map localonly out&lt;br /&gt;
&lt;br /&gt;
ip as-path access-list 10 permit ^$&lt;br /&gt;
&lt;br /&gt;
route-map localonly permit 10&lt;br /&gt;
 match as-path 10&lt;br /&gt;
end&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Inbound Filtering===&lt;br /&gt;
For at forhindre at man laver et black hole hvor trafik fra sig selv, til sig selv, ryger ud til ISP A og routed videre til ISP B hvorefter det kommer ind til dig selv igen, filtrere man sine egne ipadresser fra i indkomne routing updates. Derved sikrer man at ens netværk ikke kender andre veje til sig selv. &amp;lt;br/&amp;gt;&lt;br /&gt;
De 2 primære grupper man skal være opmærksom på:&lt;br /&gt;
*Martian adresse områder&lt;br /&gt;
**RFC 1918 adresser. Skal bruges internt i en virksomhed og aldrig komme ud på internettet. 10.0.0.0/8, 172.16.0.0/12 &amp;amp; 192.168.0.0/16&lt;br /&gt;
**Loopback adresser. 127.0.0.0/8 adresserne er reserveret til internt brug på en host, og skal derfor aldrig modtages udefra, eller routes.&lt;br /&gt;
**Host autokonfigurations blok. 169.254.0.0/16 adresse området skal bruges for automatisk adresse tildeling når en DHCP server ikke forefindes.&lt;br /&gt;
**0.0.0.0/8 adresser. 0.0.0.0/8 adresserne er ikke tildelt og selv om nogle firmaer bruger dem, skal de ikke findes på internettet.&lt;br /&gt;
**Test netværks adresser. 192.0.2.0/24 er reserveret for test og beregnet til brug i dokumentation og sample kode.&lt;br /&gt;
**Klasse D og E adresser. Klasse D adresser bruges til multicast og bør derfor ikke bruges til unicast routning. Klasse E adresser er reserveret og derfor ikke i brug. Klasse D adresser = 224.0.0.0/4. Klasse E adresser = 240.0.0.0/4&lt;br /&gt;
*Sit eget netværk, for at undgå black holing&lt;br /&gt;
Da vores offentlige adresser ikke er fastlagt har jeg ikke smidt dem i configurationen:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ip prefix-list martians seq 5 deny 0.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 10 deny 10.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 15 deny 172.16.0.0/12 le 32 &lt;br /&gt;
ip prefix-list martians seq 20 deny 192.168.0.0/16 le 32 &lt;br /&gt;
ip prefix-list martians seq 25 deny 127.0.0.0/8 le 32 &lt;br /&gt;
ip prefix-list martians seq 30 deny 169.254.0.0/16 le 32 &lt;br /&gt;
ip prefix-list martians seq 35 deny 192.0.2.0/24 le 32 &lt;br /&gt;
ip prefix-list martians seq 40 deny 224.0.0.0/4 le 32 &lt;br /&gt;
ip prefix-list martians seq 45 deny 240.0.0.0/4 le 32 &lt;br /&gt;
ip prefix-list martians seq 50 permit 0.0.0.0/0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Info trukket fra RFC1918&amp;lt;ref&amp;gt;http://www.isi.edu/in-notes/rfc1918.txt&amp;lt;/ref&amp;gt; &amp;amp; RFC3330&amp;lt;ref&amp;gt;http://www.rfc-editor.org/rfc/rfc3330.txt&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===DMZ===&lt;br /&gt;
Der oprettes DMZ zoner efter hver funktion, f.eks Mail og webservere i hver sin.&lt;br /&gt;
[[Image:FW-trekant.png|300px|right|thumb]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==WAN==&lt;br /&gt;
På Univeristets hospitalet installeres 2 alternativt fremførte 500Mbit MPLS linjer fra samme udbyder da det er her hele regionens patient data er centralizeret og den vil fungere som hub for de andre sygehuse i regionen. Hvert af de andre regions hospitaler får en redundant 100Mbit MPLS.&amp;lt;br/&amp;gt;&lt;br /&gt;
Nogle af de overvejelser vi har gjort os omkring MPLS linierne er at de måske skal være dynamiske. Det vil sige man får en hurtig forbindelse men gennemsnittet skal holdes under en given trafik mængde. Vi har snakket om det da gennemsnits trafikken sikkert ikke vil være mere en hvad en 50Mbit kunne klare, men skal man fx bruge en 4 GB fil ville det tage 4000*8/50=640=6 min 40 sekunder at overføre filen. Dette er lang tid hvis man skal bruge den her og nu. En måde man kan lave flex forbindelser er ved at installere en 500Mbit forbindelse, men at man kun bruger de 500Mbit i bursts, og at gennemsnitet skal ligge på 50Mbit eller under. Dette ville gøre at samme fil kun tog lidt over et minut at hente.&lt;br /&gt;
&lt;br /&gt;
===QoS===&lt;br /&gt;
I samarbejde med MPLS udbyderen tilkøbes der QoS for at så vidt muligt at kunne levere end to end traffik prioritering. Detaljerne om hvilke QoS muligheder der er vil afhænge af udbyderen men et eksempel kunne være 5 forskellige klasser baseret på IP precedence, med en kø dedikeret til IP telephony. Desværre har man sjældent som kunde nogen indflydelse på hvad der ryger i hvilke kører og båndbredde tildelingen. Så man må typisk remarkere pakkerne i sin edge.&lt;br /&gt;
Det kan skabe problemer hvis man skifter mpls udbyder da to selskaber sjældent benytter den samme QoS model, eller hvis man benytter 2 forskellige udbydere, da pakker skal markeres forskelligt.&lt;br /&gt;
&lt;br /&gt;
=Sikkerhed=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Network Management==&lt;br /&gt;
På alle netværks enheder opsættes syslog til en central server i datacenteret, for bedre at kunne overvåge udstyret og bistå i fejlfinding. Alle enheder sættes også i samme omgang til at rapportere ind til en MARS appliance boks også placeret i datacenteret, for at kunne give et mere komplet billede af en sikkerheds situation.&lt;br /&gt;
For at lette administration og configuration af sikkerheds enhederne installeres CSManger som giver et centralt adgangspunkt til udstyret.&lt;br /&gt;
&lt;br /&gt;
CiscoWorks benyttes til at håndtere configurations ændringer samt bistå som syslog server for at hutigt og effiktivt at kunne mitigere fejl på netværket.&lt;br /&gt;
SNMP traps for udvalgte begivenheder sendes til en central opsamler, her bør der benyttes SNMPv3 for at kunne benytte kryptering imodsætning til SNMPv1+2 hvor community strengene sendes i klar tekst. Et ressource monitorerings system opsamler via SNMPv3 statestik for de enkelte enheder såsom båndbredde, interface statistik, hukommelsesforbrug osv. Alle porte skal monitoreres selv access porte, da man så vil kunne se hvor eventuelle flaskehalse opstår.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Alt adgang til netværks enhederne håndteres med Tacacs mod en ACS server som authentikerer op imod AD'et. Gruppe politikker sættes op således at kun netværks administratorene har adgang. I de tilfælde hvor udstyret ikke kan nå acs eller Domain controllerne benyttes et lokalt brugernavn og password på de enkelte bokse. Der anbefales at der fastlægges en runtine hvor disse passwords med jævne mellemrum ændres.&lt;br /&gt;
&lt;br /&gt;
==IDS==&lt;br /&gt;
Intrusion Detection System(IDS) er en enhed der overvåger det netværkstrafik den får tilsendt, og via nogle algoritmer og kendte signaturer kan finde og overvåge skidt trafik og give alarmer når der skal tages affære.&amp;lt;br/&amp;gt;&lt;br /&gt;
Der placeres en IDS sensor på den offentlige side af netværket for at kunne monitorere eventuelle angreb udefra og man kan derved hurtigt og effiktivt tage hånd om problemer indefra og udefra herunder DoS og reconnacence. Dette kan involvere et tæt samarbejde med internet udbyderne.&lt;br /&gt;
Derudover tilknyttes der også IDS sensore til edge distribution da det er det centrale knudepunkt for data til og fra hele wan og dmz og remote access til enterprise campus.&lt;br /&gt;
&lt;br /&gt;
==Ekstern adgang==&lt;br /&gt;
Eksterne firmaer som skal have adgang til interne ressourcer håndteres med minimal belastning på IT afdelingen, som i praksis udeler et brugernavn, password, definerer de tilladte ip addresser, og en vejledning til hvordan de installerer og opsætter vpn klienten.&lt;br /&gt;
Løsningen består af vpn termination på en sæt ASA appliance bokse hvor der oprettes en access-liste til hvert firma eller person således at der kun er adgang til de nøvendige ressourcer og ikke hele det interne netværk. Til dette benyttes også en certificat server placeret i DMZ'en. Afhængigt af virksomhedens præferance kan Anyconnect&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080972e4f.shtml&amp;lt;/ref&amp;gt; klienten installeres permanent eller installere/afinstallere sig selv efter behov.&lt;br /&gt;
&lt;br /&gt;
Al vpn terminering sker på et sæt ASA bokse som sidder parallelt med internettet. Vpn loadbalancing slåes til for at udnytte de tilgændelige ressourcer bedst muligt. Det anbefales at kasserne er ens, men det er ikke et krav. Der kan tilmed benyttes en vpn concentrator i clusteret.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Eksempel på dele af configuration af et eksternt firma:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
access-list companyXXX line 1 extended permit ip any &amp;lt;ip address&amp;gt; &amp;lt;subnet mask&amp;gt;&lt;br /&gt;
&lt;br /&gt;
access-list companyXXX extended deny ip any any log disable&lt;br /&gt;
group-policy companyXXX internal&lt;br /&gt;
group-policy companyXXX attributes&lt;br /&gt;
 vpn-filter value companyXXX&lt;br /&gt;
 banner value companyXXX&lt;br /&gt;
&lt;br /&gt;
ldap attribute-map AD_to_group_map&lt;br /&gt;
  map-value memberOf CN=companyXXX,LDAPCN companyXXX&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For medarbejdere der arbejder hjemmefra eller som har behov for at tilgå interne ressourer fra andre netværk, benyttes microsofts indbyggede remote access klient, hvor al opsætning styres via gruppepolitikker i AD'et.&lt;br /&gt;
&lt;br /&gt;
==Firewall==&lt;br /&gt;
Firewallen skal bestå af 2 ASA 5540 som skal have et context (virtuel firewall) for hver net (StudNet, AdmNet, PaNet, MedNet) og det vil være med til at lave Active-Active. Når 2 ASA'er bliver bundled, ses de som en maskine, med en configuration, hvor man så deler context ud til hver af dem, så ASA 1 fx bliver aktiv for StudNet og PaNet, og ASA 2 bliver aktiv for AdmNet og MedNet, samt de er backup for hinanden.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Hver context er sin egen virtuelle firewall med seperate  sikkerhedspolitikker og fungerer som havde det været adskilt i fysisk seperate enheder. En ting man dog skal være opmærksom på er at når en asa er i firewall multimode understøttes følgende features ikke:&lt;br /&gt;
*VPN&lt;br /&gt;
*Dynamisk routings protocol&lt;br /&gt;
*QoS&lt;br /&gt;
*Multicast routing&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I vores foreslåede setup vil de forskellige context dele den offenlige ip addresse via et shared interface og nat tabellen bruges til classifier ind og på udgåede traffik klafficeres der på interfacet.&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/contexts.html#wp1133984&amp;lt;/ref&amp;gt;&lt;br /&gt;
[[Image:FW_context_out.png|300px|left|thumb]][[Image:FW_context_in.png|300px|center|thumb]]&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;lt;output omitted&amp;gt;&lt;br /&gt;
hostname(config-if)# interface gigabitethernet 0/1.1&lt;br /&gt;
hostname(config-subif)# vlan 101&lt;br /&gt;
hostname(config-subif)# context MedNet&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 0/1.1&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 1/1&lt;br /&gt;
hostname(config-if)# interface gigabitethernet 0/1.2&lt;br /&gt;
hostname(config-subif)# vlan 102&lt;br /&gt;
hostname(config-subif)# context StudNet&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 0/1.2&lt;br /&gt;
hostname(config-ctx)# allocate-interface gigabitethernet 1/1&lt;br /&gt;
&amp;lt;output omitted&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
For at sikre os mod at brugerne i en context ikke tager alle firewallens ressourcer(cpu,ram) ved et overdrevet antal nat translations og samtidinge forbindelser tildeles hver context en procentdel af enhedens totale ressourcer. Det er dog ikke alle ressourcer hvor det kan lade sig gøre såsom antal hosts og application inspections.&amp;lt;ref&amp;gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mngcntxt.html&amp;lt;/ref&amp;gt; Bemærk at tallene i følgende eksempel måske ikke er retvisende da det vil kræve en større indsigt i den pågældende virksomheds traffik mønster.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
hostname(config)# class MedNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 40%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 3000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class AdmNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 2000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class PaNet&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 2000&lt;br /&gt;
&lt;br /&gt;
hostname(config)# class Default&lt;br /&gt;
hostname(config-class)# limit-resource conns 20%&lt;br /&gt;
hostname(config-class)# limit-resource hosts 9000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Referenceliste==&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:CCDP]]&lt;/div&gt;</summary>
		<author><name>Sahan109</name></author>	</entry>

	</feed>