<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://mars.merhot.dk/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Zhadu</id>
		<title>Teknologisk videncenter - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="http://mars.merhot.dk/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Zhadu"/>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php/Special:Contributions/Zhadu"/>
		<updated>2026-04-09T12:02:02Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.29.0</generator>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9005</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9005"/>
				<updated>2009-09-14T08:53:21Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01RTVG==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179984&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jcK0$h6.iMf2Chj5ZSmadD8YJb1&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zK2S$Cg6yVpoyI0jjfuRuy6XBb1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 ip address 172.16.254.2 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.2 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 ip address 172.17.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 metric 255 subnets&lt;br /&gt;
 network 172.17.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.1 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.1 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.2 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65002 65002 65002 65002 65002 65002 65002&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179832&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179994&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.6 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180096&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==VIA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vtp domain BEO-LY&lt;br /&gt;
vtp mode transparent&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
vlan 2,8-9 &lt;br /&gt;
!&lt;br /&gt;
vlan 10&lt;br /&gt;
 name LYOLAN&lt;br /&gt;
!&lt;br /&gt;
vlan 11 &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to VIA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to VI02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.1.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.1.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179912&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AAA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AAA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.2.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.2.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180064&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA02SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$e4ZP$h.AoOqEe1T8g2tm1rGjtj/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zzrV$FHjI7ZjZ6S9ZWJ8IFxfPQ1&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description VIFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA01SWCO1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_VIA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.3 255.255.255.0&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.3 255.255.255.0&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.3 255.255.255.0&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.3 255.255.255.0&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
!&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWCO&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$CjQy$2ViWy5DbihxoJ1X.HcDyh1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$U0Sf$m2vxqz9Xpz/ZIGE21E7HY.&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2 priority 24576&lt;br /&gt;
spanning-tree vlan 8 priority 24576&lt;br /&gt;
spanning-tree vlan 9 priority 24576&lt;br /&gt;
spanning-tree vlan 10 priority 24576&lt;br /&gt;
spanning-tree vlan 11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_VIA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 no ip address&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.17.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.1.2 255.255.255.0&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 2 ip 192.168.1.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.17.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 8 ip 172.17.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.17.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 9 ip 172.17.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.17.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 10 ip 172.17.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.17.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.17.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 no ip redirects&lt;br /&gt;
 standby 11 ip 172.17.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 subnets&lt;br /&gt;
 network 172.17.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.1.0 0.0.0.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.17.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.17.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.17.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.17.255.2 route-map 65002-RMAP-OUT out&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 10 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
access-list 101 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
access-list 101 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
access-list 101 permit ip any any&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9001</id>
		<title>PengeBanken</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=PengeBanken&amp;diff=9001"/>
				<updated>2009-09-14T08:25:31Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PengeBanken&lt;br /&gt;
Konfig filer&lt;br /&gt;
&lt;br /&gt;
==AAA01SWCO==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWCO&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$rCMy$qRGETbYap5f9zcvVrWQpn/&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$JYrG$a8l5k1cKm/ydAS.5t.OpV/&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos min-reserve 5 170&lt;br /&gt;
mls qos min-reserve 6 85&lt;br /&gt;
mls qos min-reserve 7 51&lt;br /&gt;
mls qos min-reserve 8 34&lt;br /&gt;
mls qos&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,8-11 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description AAFS01&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AAA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AAA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,8-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_TDC MPLS&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.18.255.1 255.255.255.252&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 switchport mode dynamic desirable&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 ip address dhcp&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.2.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.2.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.18.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.18.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.18.9.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.18.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.18.10.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.18.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.18.11.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.18.8.11&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.18.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.18.0.0 0.0.255.255 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 neighbor 172.18.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.18.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.18.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.18.255.2 route-map 65003-RMAP-OUT out&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-OUT&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179326&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service config&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$C.7u$pLtmCcZ97WTe/1WNff1aP0&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$LTCn$DMDN3cY4cPSvI/FtXN7C9.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Til_Aarhus&lt;br /&gt;
 ip address 172.16.254.6 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.3 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.18.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65003 metric 255 subnets&lt;br /&gt;
 network 172.18.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65003&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.5 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.5 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.5 route-map 65003-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.3 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 5 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65003-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65003-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65003-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65003 65003 65003 65003 65003 65003 65003&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 length 0&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01FW==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01FW&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jo1B$nWomz1YE6pfKxf2fsIEbL/&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authentication ppp default if-needed group radius none&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
no ip domain lookup&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vpdn enable&lt;br /&gt;
!&lt;br /&gt;
vpdn-group VPN&lt;br /&gt;
! Default PPTP VPDN group&lt;br /&gt;
 accept-dialin&lt;br /&gt;
  protocol pptp&lt;br /&gt;
  virtual-template 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$QJJ1$jRbgh4QRTKIss5u1jaRPg1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map type inspect match-any OUTSIDE-DMZ-CMAP&lt;br /&gt;
 match protocol http&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
class-map type inspect match-any INSIDE-OUTSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
 match protocol icmp&lt;br /&gt;
class-map type inspect match-any OUTSIDE-INSIDE-CMAP&lt;br /&gt;
 match protocol tcp&lt;br /&gt;
 match protocol udp&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-DMZ-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
policy-map type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
 class type inspect INSIDE-OUTSIDE-CMAP&lt;br /&gt;
  inspect&lt;br /&gt;
 class class-default&lt;br /&gt;
  drop log&lt;br /&gt;
policy-map type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
 class type inspect OUTSIDE-INSIDE-CMAP&lt;br /&gt;
  drop log&lt;br /&gt;
 class class-default&lt;br /&gt;
!&lt;br /&gt;
zone security INSIDE&lt;br /&gt;
zone security OUTSIDE&lt;br /&gt;
zone security DMZ&lt;br /&gt;
zone-pair security INSIDE-OUTSIDE-ZPAIR source INSIDE destination OUTSIDE&lt;br /&gt;
 service-policy type inspect INSIDE-OUTSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-INSIDE-ZPAIR source OUTSIDE destination INSIDE&lt;br /&gt;
 service-policy type inspect OUTSIDE-INSIDE-PMAP&lt;br /&gt;
zone-pair security OUTSIDE-DMZ-ZPAIR source OUTSIDE destination DMZ&lt;br /&gt;
 service-policy type inspect OUTSIDE-DMZ-PMAP&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.2&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilAalborg address 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.2&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Viborg&lt;br /&gt;
crypto map PB_crypto_Map 20 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.3&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel2_til_Aalborg&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 description Tunnel1_til_Viborg&lt;br /&gt;
 ip address 172.16.254.1 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.2&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel2&lt;br /&gt;
 description Tunnel2_til_Aalborg&lt;br /&gt;
 ip address 172.16.254.5 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.3&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Loopback0&lt;br /&gt;
 ip address 192.168.255.10 255.255.255.0&lt;br /&gt;
 zone-member security DMZ&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description internet&lt;br /&gt;
 ip address 10.1.1.1 255.255.255.0&lt;br /&gt;
 ip nat outside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security OUTSIDE&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 ip address 172.16.255.10 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip route-cache flow&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Virtual-Template1 &lt;br /&gt;
 ip address 172.16.253.1 255.255.255.0&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 peer default ip address pool VPN-Pool&lt;br /&gt;
 ppp encrypt mppe auto&lt;br /&gt;
 ppp authentication ms-chap ms-chap-v2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.22 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.14 255.255.255.252&lt;br /&gt;
 ip nat inside&lt;br /&gt;
 ip virtual-reassembly&lt;br /&gt;
 zone-member security INSIDE&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 passive-interface Tunnel1&lt;br /&gt;
 passive-interface Tunnel2&lt;br /&gt;
 network 172.16.255.10 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.14 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.22 0.0.0.0 area 0&lt;br /&gt;
 default-information originate&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 neighbor 172.16.254.2 remote-as 65002&lt;br /&gt;
 neighbor 172.16.254.6 remote-as 65003&lt;br /&gt;
 !&lt;br /&gt;
 address-family ipv4&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.2 activate&lt;br /&gt;
 neighbor 172.16.254.6 activate&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
 no synchronization&lt;br /&gt;
 exit-address-family&lt;br /&gt;
!&lt;br /&gt;
ip local pool VPN-Pool 172.16.253.10 172.16.253.200&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 10.1.1.254&lt;br /&gt;
!&lt;br /&gt;
ip flow-export source FastEthernet0/1&lt;br /&gt;
ip flow-export version 5&lt;br /&gt;
ip flow-export destination 172.16.241.17 9000&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
ip nat inside source list 10 interface FastEthernet0/0 overload&lt;br /&gt;
ip nat inside source static tcp 192.168.255.10 80 interface FastEthernet0/0 80&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Viborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.2&lt;br /&gt;
ip access-list extended Tunnel2_til_Aalborg&lt;br /&gt;
 permit gre host 10.1.1.1 host 10.1.1.3&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 10 permit 172.16.241.15&lt;br /&gt;
access-list 10 permit 172.16.0.0 0.15.255.255&lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
snmp-server host 172.16.241.17 version 2c PengeBanken &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17178263&lt;br /&gt;
ntp server 217.198.208.66&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$YV94$HOlo8yju4M0iEUg5.PrWu.&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$uLI5$fbqYcgEAGYN9aJopMZbs0.&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description TDC_MPLS&lt;br /&gt;
 ip address 172.16.255.1 255.255.255.252&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 ip address 172.16.255.5 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 auto qos voip trust &lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1.101&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/0&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport access vlan 990&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/1&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 switchport access vlan 991&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/2&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1/3&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan990&lt;br /&gt;
 ip address 172.16.255.18 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
interface Vlan991&lt;br /&gt;
 ip address 172.16.255.13 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65001 subnets&lt;br /&gt;
 network 172.16.255.1 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.5 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.13 0.0.0.0 area 0&lt;br /&gt;
 network 172.16.255.18 0.0.0.0 area 0&lt;br /&gt;
!&lt;br /&gt;
router bgp 65001&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute connected&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.255.2 remote-as 65000&lt;br /&gt;
 neighbor 172.16.255.2 description TDC_MPLS&lt;br /&gt;
 neighbor 172.16.255.2 next-hop-self&lt;br /&gt;
 neighbor 172.16.255.2 soft-reconfiguration inbound&lt;br /&gt;
 neighbor 172.16.255.2 route-map 65000-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 10 deny 172.18.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 15 deny 192.168.2.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 20 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65000-PLIST-OUT seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
snmp-server community PengeBanken RO&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65000-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65000-PLIST-OUT&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 password cisco&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp clock-period 17179809&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==AHA01SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$vBG2$emquo5iIZpvTzxCkqzzWv0&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$S9Eb$TFTuP.RZAaTb9mJrha.7m0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-201700352&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-201700352&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-201700352&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-201700352&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3232.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 24576&lt;br /&gt;
spanning-tree vlan 240-242 priority 28672&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.17 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA02SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.9 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.2 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
 standby 2 priority 110&lt;br /&gt;
 standby 2 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
 standby 7 priority 110&lt;br /&gt;
 standby 7 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
 standby 8 priority 110&lt;br /&gt;
 standby 8 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.2 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
 standby 9 priority 110&lt;br /&gt;
 standby 9 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.2 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
 standby 10 priority 110&lt;br /&gt;
 standby 10 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.2 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
 standby 11 priority 110&lt;br /&gt;
 standby 11 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.2 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029105&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWCO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.2&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWCO&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$GxFl$DbYT2MdQ4yNpD7UJ9Iv1S1&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$m/MH$fgaAuE./eyP8ThL58GW/N0&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
system mtu routing 1500&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
ip routing&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
mls qos srr-queue input bandwidth 90 10&lt;br /&gt;
mls qos srr-queue input threshold 1 8 16&lt;br /&gt;
mls qos srr-queue input threshold 2 34 66&lt;br /&gt;
mls qos srr-queue input buffers 67 33 &lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 2 1&lt;br /&gt;
mls qos srr-queue input cos-map queue 1 threshold 3 0&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 1 2&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7&lt;br /&gt;
mls qos srr-queue input cos-map queue 2 threshold 3 3 5&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos srr-queue input dscp-map queue 1 threshold 3 32&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output cos-map queue 1 threshold 3 5&lt;br /&gt;
mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7&lt;br /&gt;
mls qos srr-queue output cos-map queue 3 threshold 3 2 4&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 2 1&lt;br /&gt;
mls qos srr-queue output cos-map queue 4 threshold 3 0&lt;br /&gt;
mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;br /&gt;
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23&lt;br /&gt;
mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 1 8&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15&lt;br /&gt;
mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7&lt;br /&gt;
mls qos queue-set output 1 threshold 1 138 138 92 138&lt;br /&gt;
mls qos queue-set output 1 threshold 2 138 138 92 400&lt;br /&gt;
mls qos queue-set output 1 threshold 3 36 77 100 318&lt;br /&gt;
mls qos queue-set output 1 threshold 4 20 50 67 400&lt;br /&gt;
mls qos queue-set output 2 threshold 1 149 149 100 149&lt;br /&gt;
mls qos queue-set output 2 threshold 2 118 118 100 235&lt;br /&gt;
mls qos queue-set output 2 threshold 3 41 68 100 272&lt;br /&gt;
mls qos queue-set output 2 threshold 4 42 72 100 242&lt;br /&gt;
mls qos queue-set output 1 buffers 10 10 26 54&lt;br /&gt;
mls qos queue-set output 2 buffers 16 6 17 61&lt;br /&gt;
mls qos&lt;br /&gt;
!&lt;br /&gt;
crypto pki trustpoint TP-self-signed-3566145536&lt;br /&gt;
 enrollment selfsigned&lt;br /&gt;
 subject-name cn=IOS-Self-Signed-Certificate-3566145536&lt;br /&gt;
 revocation-check none&lt;br /&gt;
 rsakeypair TP-self-signed-3566145536&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto pki certificate chain TP-self-signed-3566145536&lt;br /&gt;
 certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
spanning-tree etherchannel guard misconfig&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
spanning-tree vlan 2,7-11 priority 28672&lt;br /&gt;
spanning-tree vlan 240-242 priority 24576&lt;br /&gt;
!&lt;br /&gt;
vlan internal allocation policy ascending&lt;br /&gt;
!&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_AHA01RTVG&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description Til_AHA01FW&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.21 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description Til_AHA01SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description Til_AHA02SWSL&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description Til_AHA01SWOP&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree guard root&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description Til_AHA01SWCO&lt;br /&gt;
 switchport trunk encapsulation dot1q&lt;br /&gt;
 switchport trunk allowed vlan 2,7-11,240-242&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description Til_AHA01RT&lt;br /&gt;
 no switchport&lt;br /&gt;
 ip address 172.16.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 description Management&lt;br /&gt;
 ip address 192.168.0.3 255.255.255.0&lt;br /&gt;
 standby 2 ip 192.168.0.1&lt;br /&gt;
 standby 2 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan7&lt;br /&gt;
 description IT-administration&lt;br /&gt;
 ip address 172.16.0.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 7 ip 172.16.0.1&lt;br /&gt;
 standby 7 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan8&lt;br /&gt;
 description Common_Services&lt;br /&gt;
 ip address 172.16.8.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 8 ip 172.16.8.1&lt;br /&gt;
 standby 8 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan9&lt;br /&gt;
 description Administration&lt;br /&gt;
 ip address 172.16.9.3 255.255.255.0&lt;br /&gt;
 ip access-group Administration in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 9 ip 172.16.9.1&lt;br /&gt;
 standby 9 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan10&lt;br /&gt;
 description BankRaadgiver&lt;br /&gt;
 ip address 172.16.10.3 255.255.255.0&lt;br /&gt;
 ip access-group Bank in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 10 ip 172.16.10.1&lt;br /&gt;
 standby 10 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan11&lt;br /&gt;
 description IP-Telefoni&lt;br /&gt;
 ip address 172.16.11.3 255.255.255.0&lt;br /&gt;
 ip access-group Telefoni in&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 11 ip 172.16.11.1&lt;br /&gt;
 standby 11 timers msec 200 msec 800&lt;br /&gt;
!&lt;br /&gt;
interface Vlan240&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.240.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 240 ip 172.16.240.1&lt;br /&gt;
 standby 240 timers msec 200 msec 800&lt;br /&gt;
 standby 240 priority 110&lt;br /&gt;
 standby 240 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan241&lt;br /&gt;
 description Servere&lt;br /&gt;
 ip address 172.16.241.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 241 ip 172.16.241.1&lt;br /&gt;
 standby 241 timers msec 200 msec 800&lt;br /&gt;
 standby 241 priority 110&lt;br /&gt;
 standby 241 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
interface Vlan242&lt;br /&gt;
 description CallManager&lt;br /&gt;
 ip address 172.16.242.3 255.255.255.0&lt;br /&gt;
 ip helper-address 172.16.241.11&lt;br /&gt;
 standby 242 ip 172.16.242.1&lt;br /&gt;
 standby 242 timers msec 200 msec 800&lt;br /&gt;
 standby 242 priority 110&lt;br /&gt;
 standby 242 preempt delay minimum 300&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 network 172.16.0.0 0.0.255.255 area 0&lt;br /&gt;
 network 192.168.0.0 0.0.0.255 area 0&lt;br /&gt;
!&lt;br /&gt;
ip classless&lt;br /&gt;
ip http server&lt;br /&gt;
ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Administration&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Bank&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.3.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
ip access-list extended Telefoni&lt;br /&gt;
 permit ip any 172.16.240.0 0.0.7.255&lt;br /&gt;
 deny   ip any 172.0.1.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.2.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.4.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.5.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.6.0 0.255.248.255&lt;br /&gt;
 deny   ip any 172.0.7.0 0.255.248.255&lt;br /&gt;
 permit ip any any&lt;br /&gt;
!&lt;br /&gt;
ip radius source-interface Vlan2 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 36029150&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==VIA01RT==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.4&lt;br /&gt;
service timestamps debug datetime msec&lt;br /&gt;
service timestamps log datetime msec&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01RT&lt;br /&gt;
!&lt;br /&gt;
boot-start-marker&lt;br /&gt;
boot-end-marker&lt;br /&gt;
!&lt;br /&gt;
enable secret 5 $1$jcK0$h6.iMf2Chj5ZSmadD8YJb1&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local &lt;br /&gt;
!&lt;br /&gt;
aaa session-id common&lt;br /&gt;
!&lt;br /&gt;
resource policy&lt;br /&gt;
!&lt;br /&gt;
ip cef&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip domain name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
voice-card 0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$zK2S$Cg6yVpoyI0jjfuRuy6XBb1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
class-map match-any MissionCritical-Trust&lt;br /&gt;
 match ip dscp af31 &lt;br /&gt;
class-map match-any VoIP-RTP-Trust&lt;br /&gt;
 match ip dscp ef &lt;br /&gt;
class-map match-any VoIP-Control-Trust&lt;br /&gt;
 match ip dscp cs3 &lt;br /&gt;
class-map match-any Management-Trust&lt;br /&gt;
 match ip dscp cs2 &lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
 class VoIP-RTP-Trust&lt;br /&gt;
  priority percent 25&lt;br /&gt;
 class VoIP-Control-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class MissionCritical-Trust&lt;br /&gt;
  bandwidth percent 40&lt;br /&gt;
 class Management-Trust&lt;br /&gt;
  bandwidth percent 5&lt;br /&gt;
 class class-default&lt;br /&gt;
  fair-queue&lt;br /&gt;
!&lt;br /&gt;
! &lt;br /&gt;
!&lt;br /&gt;
crypto isakmp policy 10&lt;br /&gt;
 encr aes 256&lt;br /&gt;
 authentication pre-share&lt;br /&gt;
 group 5&lt;br /&gt;
 lifetime 1000&lt;br /&gt;
crypto isakmp key MegetSikkerNoegleTilViborg address 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
crypto ipsec transform-set PB-TransformSet esp-3des esp-sha-hmac &lt;br /&gt;
!&lt;br /&gt;
crypto map PB_crypto_Map 10 ipsec-isakmp &lt;br /&gt;
 set peer 10.1.1.1&lt;br /&gt;
 set transform-set PB-TransformSet &lt;br /&gt;
 match address Tunnel1_til_Aarhus&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface Tunnel1&lt;br /&gt;
 ip address 172.16.254.2 255.255.255.252&lt;br /&gt;
 ip mtu 1420&lt;br /&gt;
 tunnel source FastEthernet0/0&lt;br /&gt;
 tunnel destination 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/0&lt;br /&gt;
 description Internet&lt;br /&gt;
 ip address 10.1.1.2 255.255.255.0&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 crypto map PB_crypto_Map&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description Til_VIA02SWCO&lt;br /&gt;
 ip address 172.17.255.6 255.255.255.252&lt;br /&gt;
 ip ospf network point-to-point&lt;br /&gt;
 ip ospf dead-interval minimal hello-multiplier 3&lt;br /&gt;
 duplex auto&lt;br /&gt;
 speed auto&lt;br /&gt;
 service-policy output PbPolicy&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 no fair-queue&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/1/1&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 125000&lt;br /&gt;
!&lt;br /&gt;
interface Serial0/2/0&lt;br /&gt;
 no ip address&lt;br /&gt;
 shutdown&lt;br /&gt;
 clock rate 2000000&lt;br /&gt;
!&lt;br /&gt;
router ospf 1&lt;br /&gt;
 log-adjacency-changes&lt;br /&gt;
 redistribute bgp 65002 metric 255 subnets&lt;br /&gt;
 network 172.17.255.6 0.0.0.0 area 0&lt;br /&gt;
 default-information originate metric 255&lt;br /&gt;
!&lt;br /&gt;
router bgp 65002&lt;br /&gt;
 no synchronization&lt;br /&gt;
 bgp log-neighbor-changes&lt;br /&gt;
 redistribute static&lt;br /&gt;
 redistribute ospf 1 match internal external 1 external 2&lt;br /&gt;
 neighbor 172.16.254.1 remote-as 65001&lt;br /&gt;
 neighbor 172.16.254.1 description AHA01FW&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-IN in&lt;br /&gt;
 neighbor 172.16.254.1 route-map 65002-RMAP-OUT out&lt;br /&gt;
 default-information originate&lt;br /&gt;
 no auto-summary&lt;br /&gt;
!&lt;br /&gt;
ip route 10.1.1.1 255.255.255.255 FastEthernet0/0&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip http server&lt;br /&gt;
no ip http secure-server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended Tunnel1_til_Aarhus&lt;br /&gt;
 permit gre host 10.1.1.2 host 10.1.1.1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PLIST-OUT seq 10 permit 0.0.0.0/0 le 32&lt;br /&gt;
!&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 5 deny 172.17.0.0/16 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 15 deny 192.168.1.0/24 le 32&lt;br /&gt;
ip prefix-list 65002-PRE-IN seq 30 permit 0.0.0.0/0 le 32&lt;br /&gt;
ip radius source-interface FastEthernet0/1 &lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.7.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-IN permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PRE-IN&lt;br /&gt;
!&lt;br /&gt;
route-map 65002-RMAP-OUT permit 10&lt;br /&gt;
 match ip address prefix-list 65002-PLIST-OUT&lt;br /&gt;
 set as-path prepend 65002 65002 65002 65002 65002 65002 65002&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
!&lt;br /&gt;
control-plane&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line aux 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
!&lt;br /&gt;
scheduler allocate 20000 1000&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust dscp&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 7&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 speed 10&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179832&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA01SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA01SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.5 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179994&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AHA02SWSL==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AHA02SWSL&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 241&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Server &amp;gt;&lt;br /&gt;
 switchport access vlan 242&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AHA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AHA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.0.6 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.0.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180096&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==VIA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname VIA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
vtp domain BEO-LY&lt;br /&gt;
vtp mode transparent&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
vlan 2,8-9 &lt;br /&gt;
!&lt;br /&gt;
vlan 10&lt;br /&gt;
 name LYOLAN&lt;br /&gt;
!&lt;br /&gt;
vlan 11 &lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 8&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 service-policy input PbPolicy&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 macro description cisco-phone | cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to VIA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to VI02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.1.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.1.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
 transport input ssh&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17179912&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==AAA01SWOP==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
version 12.1&lt;br /&gt;
no service pad&lt;br /&gt;
service timestamps debug uptime&lt;br /&gt;
service timestamps log uptime&lt;br /&gt;
no service password-encryption&lt;br /&gt;
!&lt;br /&gt;
hostname AAA01SWOP&lt;br /&gt;
!&lt;br /&gt;
aaa new-model&lt;br /&gt;
aaa authentication login default group radius local&lt;br /&gt;
aaa authorization exec default group radius local&lt;br /&gt;
enable secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
!&lt;br /&gt;
username admin privilege 15 secret 5 $1$vAZW$oZgHRDs499pci.UOKjz7t.&lt;br /&gt;
wrr-queue bandwidth 10 20 70 1&lt;br /&gt;
wrr-queue cos-map 1 0 1&lt;br /&gt;
wrr-queue cos-map 2 2 4&lt;br /&gt;
wrr-queue cos-map 3 3 6 7&lt;br /&gt;
wrr-queue cos-map 4 5&lt;br /&gt;
errdisable recovery cause psecure-violation&lt;br /&gt;
errdisable recovery interval 600&lt;br /&gt;
!&lt;br /&gt;
class-map match-all ManagementSNMP&lt;br /&gt;
  match access-group name MatchSNMP&lt;br /&gt;
class-map match-all ManagementNF&lt;br /&gt;
  match access-group name MatchNF&lt;br /&gt;
class-map match-all MissionCritical&lt;br /&gt;
  match access-group name MatchBANK&lt;br /&gt;
class-map match-all ManagementRDP&lt;br /&gt;
  match access-group name MatchRDP&lt;br /&gt;
class-map match-all ManagementSSH&lt;br /&gt;
  match access-group name MatchSSH&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map PbPolicy&lt;br /&gt;
  class MissionCritical&lt;br /&gt;
    set ip dscp 26&lt;br /&gt;
  class ManagementRDP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSNMP&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementNF&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
  class ManagementSSH&lt;br /&gt;
    set ip dscp 16&lt;br /&gt;
!&lt;br /&gt;
mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;br /&gt;
ip subnet-zero&lt;br /&gt;
!&lt;br /&gt;
ip domain-name pengebanken.dk&lt;br /&gt;
ip name-server 172.16.241.11&lt;br /&gt;
ip ssh time-out 120&lt;br /&gt;
ip ssh authentication-retries 3&lt;br /&gt;
ip ssh version 2&lt;br /&gt;
!&lt;br /&gt;
no file verify auto&lt;br /&gt;
!&lt;br /&gt;
spanning-tree mode rapid-pvst&lt;br /&gt;
no spanning-tree optimize bpdu transmission&lt;br /&gt;
spanning-tree extend system-id&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/1&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/2&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/3&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/4&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/5&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/6&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/7&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/8&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/9&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/10&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/11&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/12&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/13&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/14&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/15&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/16&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/17&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/18&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/19&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/20&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/21&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/22&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/23&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface FastEthernet0/24&lt;br /&gt;
 description &amp;lt; Office-Phone &amp;gt;&lt;br /&gt;
 switchport access vlan 9&lt;br /&gt;
 switchport mode access&lt;br /&gt;
 switchport voice vlan 11&lt;br /&gt;
 switchport port-security&lt;br /&gt;
 switchport port-security maximum 2&lt;br /&gt;
 switchport port-security aging time 2&lt;br /&gt;
 switchport port-security aging type inactivity&lt;br /&gt;
 mls qos trust device cisco-phone&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip cisco-phone&lt;br /&gt;
 macro description cisco-phone&lt;br /&gt;
 spanning-tree portfast&lt;br /&gt;
 spanning-tree bpduguard enable&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/1&lt;br /&gt;
 description &amp;lt;Uplink to AAA01SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet0/2&lt;br /&gt;
 description &amp;lt;Uplink to AAA02SWCO &amp;gt;&lt;br /&gt;
 switchport mode trunk&lt;br /&gt;
 mls qos trust cos&lt;br /&gt;
 auto qos voip trust&lt;br /&gt;
!&lt;br /&gt;
interface Vlan1&lt;br /&gt;
 no ip address&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
 shutdown&lt;br /&gt;
!&lt;br /&gt;
interface Vlan2&lt;br /&gt;
 ip address 192.168.2.4 255.255.255.0&lt;br /&gt;
 no ip route-cache&lt;br /&gt;
!&lt;br /&gt;
ip default-gateway 192.168.2.1&lt;br /&gt;
ip http server&lt;br /&gt;
!&lt;br /&gt;
ip access-list extended MatchBANK&lt;br /&gt;
 permit tcp any any eq 8439&lt;br /&gt;
ip access-list extended MatchNF&lt;br /&gt;
 permit udp any any eq 9000&lt;br /&gt;
ip access-list extended MatchRDP&lt;br /&gt;
 permit tcp any any eq 3389&lt;br /&gt;
ip access-list extended MatchSNMP&lt;br /&gt;
 permit udp any any eq 167&lt;br /&gt;
ip access-list extended MatchSSH&lt;br /&gt;
 permit tcp any any eq 22&lt;br /&gt;
ip radius source-interface Vlan2&lt;br /&gt;
access-list 1 permit 172.16.241.17&lt;br /&gt;
access-list 1 permit 172.16.0.0 0.0.0.255&lt;br /&gt;
snmp-server community PengeBanken RO 1&lt;br /&gt;
radius-server host 172.16.241.11 auth-port 1645 acct-port 1646 key PengeBanken&lt;br /&gt;
radius-server retransmit 3&lt;br /&gt;
!&lt;br /&gt;
line con 0&lt;br /&gt;
line vty 0 4&lt;br /&gt;
 access-class 1 in&lt;br /&gt;
 length 0&lt;br /&gt;
 transport input ssh&lt;br /&gt;
line vty 5 15&lt;br /&gt;
!&lt;br /&gt;
ntp clock-period 17180064&lt;br /&gt;
ntp server 172.16.255.10&lt;br /&gt;
!&lt;br /&gt;
end&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8126</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8126"/>
				<updated>2009-08-13T19:37:30Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* IP og VLAN Plan */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*Core design&lt;br /&gt;
Core'en er bygget op af fire L3 switche, som er delt op over to lokationer. I hver lokation er switchene forbundet via etherchannels.&amp;lt;br/&amp;gt;&lt;br /&gt;
Grunden for de to lokationer, er for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblocke er bygget op af de to lag, Access og Destribution. I vores Access lag har vi valgt L2 switche, udelukkende på grund af økonomiske årsager.&amp;lt;br/&amp;gt;&lt;br /&gt;
På Access laget opsættes der 802.1x som godkender op imod en NAC server, hvilket der bliver skrevet mere om i &amp;quot;IP og VLAN Plan&amp;quot;&amp;lt;br/&amp;gt;&lt;br /&gt;
fra hver Access switch er der en redundant forbindelse til Distributions laget, som består af to L3 switche.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Distributions switchene er forbundet med et enkelt link, hvilket tillader summerization af routes mellem switchene.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock beregninger&lt;br /&gt;
Vi går ud fra, at der er 3500 aktive bruger på netværket.&lt;br /&gt;
Med hver switchblock, er hardware mæssigt mulighed for 23 Access switche, og med 22 frie porte per switch, giver det en fysisk mulighed for 506 brugere per switchblock.&amp;lt;br/&amp;gt;&lt;br /&gt;
Ved at devidere 3500 med 506, er det minimum brug for 7 switchblocke. Vi har så valgt at bruge 10 switchblocke, for at kunne dække et stort nok område, samt ikke makse switchblockende helt ud.&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Core har fået følgende net: 10.0.0.0/24&amp;lt;br/&amp;gt;&lt;br /&gt;
Hvert switchblock har følgende net: 10.OSPF-AREA.VLAN.0/24 - f.eks VLAN 1, på switchblock med ospf area 1, har 10.1.1.0/24 nettet.&amp;lt;br/&amp;gt;&lt;br /&gt;
Der bliver også uddelt et switchblock range samt et ospf area til hver af filialerne.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8125</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8125"/>
				<updated>2009-08-13T19:30:55Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* IP og VLAN Plan */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*Core design&lt;br /&gt;
Core'en er bygget op af fire L3 switche, som er delt op over to lokationer. I hver lokation er switchene forbundet via etherchannels.&amp;lt;br/&amp;gt;&lt;br /&gt;
Grunden for de to lokationer, er for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblocke er bygget op af de to lag, Access og Destribution. I vores Access lag har vi valgt L2 switche, udelukkende på grund af økonomiske årsager.&amp;lt;br/&amp;gt;&lt;br /&gt;
På Access laget opsættes der 802.1x som godkender op imod en NAC server, hvilket der bliver skrevet mere om i &amp;quot;IP og VLAN Plan&amp;quot;&amp;lt;br/&amp;gt;&lt;br /&gt;
fra hver Access switch er der en redundant forbindelse til Distributions laget, som består af to L3 switche.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Distributions switchene er forbundet med et enkelt link, hvilket tillader summerization af routes mellem switchene.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock beregninger&lt;br /&gt;
Vi går ud fra, at der er 3500 aktive bruger på netværket.&lt;br /&gt;
Med hver switchblock, er hardware mæssigt mulighed for 23 Access switche, og med 22 frie porte per switch, giver det en fysisk mulighed for 506 brugere per switchblock.&amp;lt;br/&amp;gt;&lt;br /&gt;
Ved at devidere 3500 med 506, er det minimum brug for 7 switchblocke. Vi har så valgt at bruge 10 switchblocke, for at kunne dække et stort nok område, samt ikke makse switchblockende helt ud.&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Core har fået følgende net: 10.0.0.0/24&amp;lt;br/&amp;gt;&lt;br /&gt;
Hvert switchblock har følgende net: 10.OSPF-AREA.VLAN.0/24 - f.eks VLAN 1, på switchblock med ospf area 1, har 10.1.1.0/24 nettet.&amp;lt;br/&amp;gt;&lt;br /&gt;
Der bliver også uddelt et switchblock range samt et ospf area til hver af filialerne.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8124</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8124"/>
				<updated>2009-08-13T19:29:39Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* IP og VLAN Plan */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*Core design&lt;br /&gt;
Core'en er bygget op af fire L3 switche, som er delt op over to lokationer. I hver lokation er switchene forbundet via etherchannels.&amp;lt;br/&amp;gt;&lt;br /&gt;
Grunden for de to lokationer, er for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblocke er bygget op af de to lag, Access og Destribution. I vores Access lag har vi valgt L2 switche, udelukkende på grund af økonomiske årsager.&amp;lt;br/&amp;gt;&lt;br /&gt;
På Access laget opsættes der 802.1x som godkender op imod en NAC server, hvilket der bliver skrevet mere om i &amp;quot;IP og VLAN Plan&amp;quot;&amp;lt;br/&amp;gt;&lt;br /&gt;
fra hver Access switch er der en redundant forbindelse til Distributions laget, som består af to L3 switche.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Distributions switchene er forbundet med et enkelt link, hvilket tillader summerization af routes mellem switchene.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock beregninger&lt;br /&gt;
Vi går ud fra, at der er 3500 aktive bruger på netværket.&lt;br /&gt;
Med hver switchblock, er hardware mæssigt mulighed for 23 Access switche, og med 22 frie porte per switch, giver det en fysisk mulighed for 506 brugere per switchblock.&amp;lt;br/&amp;gt;&lt;br /&gt;
Ved at devidere 3500 med 506, er det minimum brug for 7 switchblocke. Vi har så valgt at bruge 10 switchblocke, for at kunne dække et stort nok område, samt ikke makse switchblockende helt ud.&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&lt;br /&gt;
Core har fået følgende net: 10.0.0.0/24&amp;lt;br/&amp;gt;&lt;br /&gt;
Hvert switchblock har følgende net: 10.OSPF-AREA.VLAN.0/24 - f.eks VLAN 1, på switchblock med ospf area 1, har 10.1.1.0/24 nettet.&amp;lt;br/&amp;gt;&lt;br /&gt;
Der bliver også uddelt et switchblock range samt et ospf area til hver af filialerne.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8123</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8123"/>
				<updated>2009-08-13T19:23:40Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* IP og VLAN Plan */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*Core design&lt;br /&gt;
Core'en er bygget op af fire L3 switche, som er delt op over to lokationer. I hver lokation er switchene forbundet via etherchannels.&amp;lt;br/&amp;gt;&lt;br /&gt;
Grunden for de to lokationer, er for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblocke er bygget op af de to lag, Access og Destribution. I vores Access lag har vi valgt L2 switche, udelukkende på grund af økonomiske årsager.&amp;lt;br/&amp;gt;&lt;br /&gt;
På Access laget opsættes der 802.1x som godkender op imod en NAC server, hvilket der bliver skrevet mere om i &amp;quot;IP og VLAN Plan&amp;quot;&amp;lt;br/&amp;gt;&lt;br /&gt;
fra hver Access switch er der en redundant forbindelse til Distributions laget, som består af to L3 switche.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Distributions switchene er forbundet med et enkelt link, hvilket tillader summerization af routes mellem switchene.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock beregninger&lt;br /&gt;
Vi går ud fra, at der er 3500 aktive bruger på netværket.&lt;br /&gt;
Med hver switchblock, er hardware mæssigt mulighed for 23 Access switche, og med 22 frie porte per switch, giver det en fysisk mulighed for 506 brugere per switchblock.&amp;lt;br/&amp;gt;&lt;br /&gt;
Ved at devidere 3500 med 506, er det minimum brug for 7 switchblocke. Vi har så valgt at bruge 10 switchblocke, for at kunne dække et stort nok område, samt ikke makse switchblockende helt ud.&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&lt;br /&gt;
Core har fået følgende net: 10.0.0.0/24&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:OSPF.jpg&amp;diff=8122</id>
		<title>File:OSPF.jpg</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:OSPF.jpg&amp;diff=8122"/>
				<updated>2009-08-13T19:19:01Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: uploaded a new version of &amp;quot;Image:OSPF.jpg&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8121</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8121"/>
				<updated>2009-08-13T19:07:57Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*Core design&lt;br /&gt;
Core'en er bygget op af fire L3 switche, som er delt op over to lokationer. I hver lokation er switchene forbundet via etherchannels.&amp;lt;br/&amp;gt;&lt;br /&gt;
Grunden for de to lokationer, er for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblocke er bygget op af de to lag, Access og Destribution. I vores Access lag har vi valgt L2 switche, udelukkende på grund af økonomiske årsager.&amp;lt;br/&amp;gt;&lt;br /&gt;
På Access laget opsættes der 802.1x som godkender op imod en NAC server, hvilket der bliver skrevet mere om i &amp;quot;IP og VLAN Plan&amp;quot;&amp;lt;br/&amp;gt;&lt;br /&gt;
fra hver Access switch er der en redundant forbindelse til Distributions laget, som består af to L3 switche.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Distributions switchene er forbundet med et enkelt link, hvilket tillader summerization af routes mellem switchene.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock beregninger&lt;br /&gt;
Vi går ud fra, at der er 3500 aktive bruger på netværket.&lt;br /&gt;
Med hver switchblock, er hardware mæssigt mulighed for 23 Access switche, og med 22 frie porte per switch, giver det en fysisk mulighed for 506 brugere per switchblock.&amp;lt;br/&amp;gt;&lt;br /&gt;
Ved at devidere 3500 med 506, er det minimum brug for 7 switchblocke. Vi har så valgt at bruge 10 switchblocke, for at kunne dække et stort nok område, samt ikke makse switchblockende helt ud.&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8120</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8120"/>
				<updated>2009-08-13T19:07:30Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*Core design&lt;br /&gt;
Core'en er bygget op af fire L3 switche, som er delt op over to lokationer. I hver lokation er switchene forbundet via etherchannels.&amp;lt;br/&amp;gt;&lt;br /&gt;
Grunden for de to lokationer, er for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblocke er bygget op af de to lag, Access og Destribution. I vores Access lag har vi valgt L2 switche, udelukkende på grund af økonomiske årsager.&amp;lt;br/&amp;gt;&lt;br /&gt;
På Access laget opsættes der 802.1x som godkender op imod en NAC server, hvilket der bliver skrevet mere om i &amp;quot;IP og VLAN Plan&amp;quot;&amp;lt;br/&amp;gt;&lt;br /&gt;
fra hver Access switch er der en redundant forbindelse til Distributions laget, som består af to L3 switche.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Distributions switchene er forbundet med et enkelt link, hvilket tillader summerization af routes mellem switchene.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock beregninger&lt;br /&gt;
Vi går ud fra, at der er 3500 aktive bruger på netværket.&lt;br /&gt;
Med hver switchblock, er hardware mæssigt mulighed for 23 Access switche, og med 22 frie porte per switch, giver det en fysisk mulighed for 506 brugere per switchblock.&amp;lt;br/&amp;gt;&lt;br /&gt;
Ved at devidere 3500 med 506, er det minimum brug for 7 switchblocke. Vi har så valgt at bruge 10 switchblocke, for at kunne dække et stort nok område, samt ikke makse switchblockende helt ud.&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8119</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8119"/>
				<updated>2009-08-13T18:54:11Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*Core design&lt;br /&gt;
Core'en er bygget op af fire L3 switche, som er delt op over to lokationer. I hver lokation er switchene forbundet via etherchannels.&amp;lt;br/&amp;gt;&lt;br /&gt;
Grunden for de to lokationer, er for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblocke er bygget op af de to lag, Access og Destribution. I vores Access lag har vi valgt L2 switche, udelukkende på grund af økonomiske årsager.&amp;lt;br/&amp;gt;&lt;br /&gt;
På Access laget opsættes der 802.1x som godkender op imod en NAC server, hvilket der bliver skrevet mere om i &amp;quot;IP og VLAN Plan&amp;quot;&amp;lt;br/&amp;gt;&lt;br /&gt;
fra hver Access switch er der en redundant forbindelse til Distributions laget, som består af to L3 switche.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Distributions switchene er forbundet med et enkelt link, hvilket tillader summerization af routes mellem switchene.&lt;br /&gt;
&lt;br /&gt;
*Switchblock beregninger&lt;br /&gt;
Vi går ud fra, at der er 3500 aktive bruger på netværket.&lt;br /&gt;
Med hver switchblock, er hardware mæssigt mulighed for 23 Access switche, og med 22 frie porte per switch, giver det en fysisk mulighed for 506 brugere per switchblock.&amp;lt;br/&amp;gt;&lt;br /&gt;
Ved at devidere 3500 med 506, er det minimum brug for 7 switchblocke. Vi har så valgt at bruge 10 switchblocke, for at kunne dække et stort nok område, samt ikke makse switchblockende helt ud.&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8118</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8118"/>
				<updated>2009-08-13T17:03:34Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*Core design&lt;br /&gt;
Core'en er bygget op af fire L3 switche, som er delt op over to lokationer. I hver lokation er switchene forbundet via etherchannels.&amp;lt;br/&amp;gt;&lt;br /&gt;
Grunden for de to lokationer, er for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblocke er bygget op af de to lag, Access og Destribution. I vores Access lag har vi valgt L2 switche, udelukkende på grund af økonomiske årsager.&amp;lt;br/&amp;gt;&lt;br /&gt;
På Access laget opsættes der 802.1x som godkender op imod en NAC server, hvilket der bliver skrevet mere om i &amp;quot;IP og VLAN Plan&amp;quot;&amp;lt;br/&amp;gt;&lt;br /&gt;
fra hver Access switch er der en redundant forbindelse til Distributions laget, som består af to L3 switche.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Distributions switchene er forbundet med et enkelt link, hvilket tillader summerization af routes mellem switchene.&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8117</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8117"/>
				<updated>2009-08-13T17:00:07Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*Core design&lt;br /&gt;
Core'en er bygget op af fire L3 switche, som er delt op over to lokationer. I hver lokation er switchene forbundet via etherchannels.&amp;lt;br/&amp;gt;&lt;br /&gt;
Grunden for de to lokationer, er for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblocke er bygget op af de to lag, Access og Destribution. I vores Access lag har vi valgt L2 switche, udelukkende på grund af økonomiske grunde.&amp;lt;br/&amp;gt;&lt;br /&gt;
På Access laget opsættes der 802.1x som godkender op imod en NAC server, hvilket der bliver skrevet mere om i &amp;quot;IP og VLAN Plan&amp;quot;&amp;lt;br/&amp;gt;&lt;br /&gt;
fra hver Access switch er der en redundant forbindelse til Distributions laget, som består af to L3 switche.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Distributions switchene er forbundet med et enkelt link, hvilket tillader summerization af routes mellem switchene.&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8116</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8116"/>
				<updated>2009-08-13T16:43:27Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*Core design&lt;br /&gt;
Core'en er bygget op af fire L3 switche, som er delt op over to lokationer. I hver lokation er switchene forbundet via etherchannels.&amp;lt;br/&amp;gt;&lt;br /&gt;
Grunden for de to lokationer, er for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblocke er bygget op af de to lag, Access og Destribution. I vores Access lag har vi valgt L2 switche, udelukkende på grund af økonomiske grunde.&amp;lt;br/&amp;gt;&lt;br /&gt;
På Access laget opsættes der 802.1x som godkender op imod en NAC server, hvilket der bliver skrevet mere om i &amp;quot;IP og VLAN Plan&amp;quot;&amp;lt;br/&amp;gt;&lt;br /&gt;
fra hver Access switch er der en redundant forbindelse til Distributions laget, som består af to L3 switche.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Distributions switchene er forbundet med et enkelt link, hvilket tillader lokal summerization af routes.&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8115</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8115"/>
				<updated>2009-08-13T16:13:36Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*Core design&lt;br /&gt;
Core'en er bygget op af fire L3 switche, som er delt op over to lokationer. I hver lokation er switchene forbundet via etherchannels.&amp;lt;br/&amp;gt;&lt;br /&gt;
Grunden for de to lokationer, er for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
*Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblocke er bygget op af de to lag, Access og Destribution. I vores Access lag har vi valgt L2 switche, udelukkende på grund af økonomiske grunde.&amp;lt;br/&amp;gt;&lt;br /&gt;
På Access laget opsættes der 802.1x som godkender op imod en NAC server, hvilket der bliver skrevet mere om i &amp;quot;IP og VLAN Plan&amp;quot;&amp;lt;br/&amp;gt;&lt;br /&gt;
Fra hver Access switch er der en redundant forbindelse til Distributions laget, som består af to L3 switche.&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8114</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8114"/>
				<updated>2009-08-13T15:48:20Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Core design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Core'en er bygget op af fire L3 switche, som er delt op over to lokationer. I hver lokation er switchene forbundet via etherchannels.&amp;lt;br/&amp;gt;&lt;br /&gt;
Grunden for de to lokationer, er for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblock design bygger på Cisco's best practice, i det&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8113</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8113"/>
				<updated>2009-08-13T15:41:26Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&amp;lt;br/&amp;gt;&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Core design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblock design bygger på Cisco's best practice, i det&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8112</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8112"/>
				<updated>2009-08-13T15:41:08Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Core design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan nå netværket rundt, selvom en etherchannel inde i core'en gik ned.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblock design bygger på Cisco's best practice, i det&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8111</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8111"/>
				<updated>2009-08-13T15:39:14Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
Udstyr brugt i design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 2950 L2 switche.&amp;lt;br/&amp;gt;&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Core design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at core'ens &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblock design bygger på Cisco's best practice, i det&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8110</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8110"/>
				<updated>2009-08-13T15:37:00Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
Udstyr brugt i design:&lt;br /&gt;
Cisco 2950 L2 switche.&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Core design:&amp;lt;br/&amp;gt;&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at core'ens &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblock design bygger på Cisco's best practice, i det&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8109</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8109"/>
				<updated>2009-08-13T13:02:48Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
Udstyr brugt i design:&lt;br /&gt;
Cisco 2950 L2 switche.&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Core design:&lt;br /&gt;
Vores core design bygger meget på Scalability, Reliability og Security.&lt;br /&gt;
&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&lt;br /&gt;
&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at core'ens &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblock design bygger på Cisco's best practice, i det&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8107</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8107"/>
				<updated>2009-08-13T12:55:00Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
Udstyr brugt i design:&lt;br /&gt;
Cisco 2950 L2 switche.&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Core design:&lt;br /&gt;
&lt;br /&gt;
Vores core design bygger meget på Scalability, Reliability og Security.&lt;br /&gt;
&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&lt;br /&gt;
&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at flere links mellem Core og Switchbloke blev destrueret.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblock design bygger på Cisco's best practice, i det&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8106</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8106"/>
				<updated>2009-08-13T12:54:36Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
Udstyr brugt i design:&lt;br /&gt;
Cisco 2950 L2 switche.&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&lt;br /&gt;
&lt;br /&gt;
Core design:&lt;br /&gt;
&lt;br /&gt;
Vores core design bygger meget på Scalability, Reliability og Security.&lt;br /&gt;
&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&lt;br /&gt;
&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb reserve links, i tilfælde af nedbrud.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at flere links mellem Core og Switchbloke blev destrueret.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblock design bygger på Cisco's best practice, i det&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet. Det har også været diskuteret at spanne, men det er ikke best practice, og VRF'er gir nogle problemer, og kræver mere administration.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8103</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8103"/>
				<updated>2009-08-13T12:51:54Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* IP og VLAN Plan */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
Udstyr brugt i design:&lt;br /&gt;
Cisco 2950 L2 switche.&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&lt;br /&gt;
&lt;br /&gt;
Core design:&lt;br /&gt;
&lt;br /&gt;
Vores core design bygger meget på Scalability, Reliability og Security.&lt;br /&gt;
&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&lt;br /&gt;
&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb links, som kun bruges som reserve links.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at flere links mellem Core og Switchbloke blev destrueret.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblock design bygger på Cisco's best practice, i det&lt;br /&gt;
&lt;br /&gt;
=IP og VLAN Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
I netværket har vi valgt at køre ren IP/L3 fra distribution og opefter. Linket mellem distribusions switchene kører også Lag3. Dvs. vi spanner ikke VLANS ud over vores netværk. For at kunne holde nettene adskilt laver vi access lister med de Wildcards der står defineret i billedet.&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8100</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8100"/>
				<updated>2009-08-13T12:47:31Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
Udstyr brugt i design:&lt;br /&gt;
Cisco 2950 L2 switche.&lt;br /&gt;
Cisco 3560 L3 switche.&lt;br /&gt;
&lt;br /&gt;
Vi foreslår dog at man køber to styks Cisco 6500 series switche til Core'en.&lt;br /&gt;
&lt;br /&gt;
Core design:&lt;br /&gt;
&lt;br /&gt;
Vores core design bygger meget på Scalability, Reliability og Security.&lt;br /&gt;
&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&lt;br /&gt;
&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb links, som kun bruges som reserve links.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at flere links mellem Core og Switchbloke blev destrueret.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblock design bygger på Cisco's best practice, i det&lt;br /&gt;
&lt;br /&gt;
=IP Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8097</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8097"/>
				<updated>2009-08-13T12:45:25Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
&lt;br /&gt;
Core design:&lt;br /&gt;
&lt;br /&gt;
Vores core design bygger meget på Scalability, Reliability og Security.&lt;br /&gt;
&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&lt;br /&gt;
&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb links, som kun bruges som reserve links.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at flere links mellem Core og Switchbloke blev destrueret.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblock design bygger på Cisco's best practice, i det&lt;br /&gt;
=IP Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8092</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8092"/>
				<updated>2009-08-13T11:58:38Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
=IP Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
&lt;br /&gt;
Core design:&lt;br /&gt;
&lt;br /&gt;
Vores core design bygger meget på Scalability, Reliability og Security.&lt;br /&gt;
&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&lt;br /&gt;
&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb links, som kun bruges som reserve links.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at flere links mellem Core og Switchbloke blev destrueret.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
Vores switchblock design bygger på Cisco's best practice, i det&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8091</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8091"/>
				<updated>2009-08-13T11:57:29Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* IP Plan */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
=IP Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|500px|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
&lt;br /&gt;
Core design:&lt;br /&gt;
&lt;br /&gt;
Vores core design bygger meget på Scalability, Reliability og Security.&lt;br /&gt;
&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&lt;br /&gt;
&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb links, som kun bruges som reserve links.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at flere links mellem Core og Switchbloke blev destrueret.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8089</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8089"/>
				<updated>2009-08-13T11:57:12Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* IP Plan */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
=IP Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|center|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
&lt;br /&gt;
Core design:&lt;br /&gt;
&lt;br /&gt;
Vores core design bygger meget på Scalability, Reliability og Security.&lt;br /&gt;
&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&lt;br /&gt;
&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb links, som kun bruges som reserve links.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at flere links mellem Core og Switchbloke blev destrueret.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8088</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8088"/>
				<updated>2009-08-13T11:56:56Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* IP Plan */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
=IP Plan=&lt;br /&gt;
[[image:IP PLAN.jpg|right|thumb|Accessliste opdeling|]]&lt;br /&gt;
* IP net = 10.0.0.0/8&lt;br /&gt;
* Core/Access = 10.0.0.0/9&lt;br /&gt;
* Datacenter = 10.128.0.0/10&lt;br /&gt;
* Edge = 10.192.0.0/10&lt;br /&gt;
&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
&lt;br /&gt;
Core design:&lt;br /&gt;
&lt;br /&gt;
Vores core design bygger meget på Scalability, Reliability og Security.&lt;br /&gt;
&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&lt;br /&gt;
&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb links, som kun bruges som reserve links.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at flere links mellem Core og Switchbloke blev destrueret.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8083</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8083"/>
				<updated>2009-08-13T11:49:47Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
&lt;br /&gt;
Core design:&lt;br /&gt;
&lt;br /&gt;
Vores core design bygger meget på Scalability, Reliability og Security.&lt;br /&gt;
&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&lt;br /&gt;
&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb links, som kun bruges som reserve links.&amp;lt;br/&amp;gt;&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at flere links mellem Core og Switchbloke blev destrueret.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:OSPF.jpg&amp;diff=8081</id>
		<title>File:OSPF.jpg</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:OSPF.jpg&amp;diff=8081"/>
				<updated>2009-08-13T11:47:15Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: uploaded a new version of &amp;quot;Image:OSPF.jpg&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8076</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8076"/>
				<updated>2009-08-13T11:41:40Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: /* Core og Switchblock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
&lt;br /&gt;
Core design:&lt;br /&gt;
&lt;br /&gt;
Vores core design bygger meget på Scalability, Reliability og Security.&lt;br /&gt;
&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&lt;br /&gt;
&lt;br /&gt;
De to core lokationer er forbundet med to 1Gb links, som kun bruges som reserve links.&lt;br /&gt;
De to reserve links, sikre at data stadigvæk kan sendes rundt, selvom at flere links mellem Core og Switchbloke blev destrueret.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8069</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8069"/>
				<updated>2009-08-13T11:15:04Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
Vi har prøvet så vidt muligt at inkorporere kundens eksisterende udstyr i vores design.&lt;br /&gt;
&lt;br /&gt;
Core design:&lt;br /&gt;
&lt;br /&gt;
Vores core design bygger meget på Scalability, Reliability og Security.&lt;br /&gt;
&lt;br /&gt;
Core'en er delt op over to lokationer, for at minimere sansynligheden for nedbrud ved f. eks brand.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
Switchblock design&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8066</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8066"/>
				<updated>2009-08-13T11:04:50Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
*Core design&lt;br /&gt;
&lt;br /&gt;
*Switchblock design&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|center|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8065</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8065"/>
				<updated>2009-08-13T11:04:33Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
=Core og Switchblock=&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|center|thumb|Core design with attached Switchblock]]&lt;br /&gt;
*Core design&lt;br /&gt;
&lt;br /&gt;
*Switchblock design&lt;br /&gt;
&lt;br /&gt;
=OSPF area opdeling=&lt;br /&gt;
[[Image:OSPF.jpg|300px|right|thumb|Indeling af OSPF Areas]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:IP_PLAN.jpg&amp;diff=8064</id>
		<title>File:IP PLAN.jpg</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:IP_PLAN.jpg&amp;diff=8064"/>
				<updated>2009-08-13T10:57:12Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:OSPF.jpg&amp;diff=8063</id>
		<title>File:OSPF.jpg</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:OSPF.jpg&amp;diff=8063"/>
				<updated>2009-08-13T10:56:59Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8061</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8061"/>
				<updated>2009-08-13T10:53:42Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|right|thumb|Core design with attached Switchblock]]&lt;br /&gt;
*Core design&lt;br /&gt;
&lt;br /&gt;
*Switchblock design&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8060</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8060"/>
				<updated>2009-08-13T10:51:21Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Opgave CCDP]]&lt;br /&gt;
[[Image:CORE&amp;amp;DIST.jpg|600px|right|thumb|Core design with attached Switchblock]]&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:CORE%26DIST.jpg&amp;diff=8058</id>
		<title>File:CORE&amp;DIST.jpg</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:CORE%26DIST.jpg&amp;diff=8058"/>
				<updated>2009-08-13T10:46:15Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8037</id>
		<title>Opgave CCDP - IP Plan og Core</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=Opgave_CCDP_-_IP_Plan_og_Core&amp;diff=8037"/>
				<updated>2009-08-13T09:02:14Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: New page: Ehm.  It just works :D&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Ehm.&lt;br /&gt;
&lt;br /&gt;
It just works :D&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	<entry>
		<id>http://mars.merhot.dk/w/index.php?title=File:Eem_white_paper.pdf&amp;diff=3370</id>
		<title>File:Eem white paper.pdf</title>
		<link rel="alternate" type="text/html" href="http://mars.merhot.dk/w/index.php?title=File:Eem_white_paper.pdf&amp;diff=3370"/>
				<updated>2009-04-07T11:18:17Z</updated>
		
		<summary type="html">&lt;p&gt;Zhadu: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Zhadu</name></author>	</entry>

	</feed>