
sh run
Building configuration...
Current configuration : 4997 bytes
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
hostname PRN-BJ-3560
!
enable secret 5 $1$xIN9$63jIcr9fwxeCf5wDaQM951
!
username wuhan privilege 15 secret 5 $1$udlv$ZCHIFMaMYZ3yhLxI24snt1
username tech secret 5 $1$UOs.$FIJseKuvztRvY2h0USbZE0
no aaa new-model
system mtu routing 1500
ip subnet-zero
ip routing
ip dhcp excluded-address 192.168.20.1 192.168.20.29
ip dhcp excluded-address 192.168.20.181 192.168.20.254
ip dhcp excluded-address 192.168.18.1 192.168.18.29
ip dhcp excluded-address 172.20.10.1 172.20.10.29
ip dhcp excluded-address 172.20.10.181 172.20.10.254
ip dhcp excluded-address 192.168.18.181 192.168.18.254
!
ip dhcp pool GUEST
network 192.168.20.0 255.255.255.0
default-router 192.168.20.254
dns-server 202.106.196.115 202.106.0.20
lease 0 8
!
ip dhcp pool OFFICE
network 192.168.18.0 255.255.255.0
default-router 192.168.18.254
dns-server 202.106.196.115 202.106.0.20
lease 0 8
!
ip dhcp pool USVPN
network 172.20.10.0 255.255.255.0
default-router 172.20.10.254
dns-server 202.106.196.115 202.106.0.20
lease 0 8
!
!
!
no file verify auto
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
interface GigabitEthernet0/1
description " Link to ASA5510 E0/1 "
switchport access vlan 2
!
interface GigabitEthernet0/2
switchport access vlan 19
switchport mode access
!
interface GigabitEthernet0/3
switchport access vlan 19
switchport mode access
!
interface GigabitEthernet0/4
switchport access vlan 19
switchport mode access
!
interface GigabitEthernet0/5
switchport access vlan 19
switchport mode access
!
interface GigabitEthernet0/6
switchport access vlan 19
switchport mode access
!
interface GigabitEthernet0/7
switchport access vlan 19
switchport mode access
!
interface GigabitEthernet0/8
switchport access vlan 19
switchport mode access
!
interface GigabitEthernet0/9
switchport access vlan 19
switchport mode access
!
interface GigabitEthernet0/10
switchport access vlan 19
switchport mode access
interface GigabitEthernet0/11
switchport access vlan 19
switchport mode access
!
interface GigabitEthernet0/12
switchport access vlan 19
switchport mode access
!
interface GigabitEthernet0/13
switchport access vlan 19
switchport mode access
!
interface GigabitEthernet0/14
description " Link to PRN-BJ-2960A G0/1 "
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport mode trunk
!
interface GigabitEthernet0/15
description " Link to PRN-BJ-2960B G0/1 "
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport mode trunk
!
interface GigabitEthernet0/16
description ap1
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport mode trunk
!
interface GigabitEthernet0/17
description ap2
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport mode trunk
!
interface GigabitEthernet0/18
description " Link to PRN-BJ-2960C G0/1 "
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport mode trunk
!
interface GigabitEthernet0/19
shutdown
!
interface GigabitEthernet0/20
shutdown
!
interface GigabitEthernet0/21
shutdown
!
interface GigabitEthernet0/22
shutdown
!
interface GigabitEthernet0/23
shutdown
!
interface GigabitEthernet0/24
shutdown
!
interface GigabitEthernet0/25
shutdown
!
interface GigabitEthernet0/26
shutdown
!
interface GigabitEthernet0/27
shutdown
interface GigabitEthernet0/28
shutdown
!
interface Vlan1
description " USVPN VLAN "
ip address 172.20.10.254 255.255.255.0
!
interface Vlan2
description " MANAGERMENT VLAN "
ip address 172.20.1.2 255.255.255.0
!
interface Vlan18
description " OFFICE VLAN "
ip address 192.168.18.254 255.255.255.0
!
interface Vlan19
description " SERVER VLAN "
ip address 192.168.19.254 255.255.255.0
!
interface Vlan20
description " GUEST VLAN "
ip address 192.168.20.254 255.255.255.0
ip access-group 100 in
!
ip classless
ip route 0.0.0.0 0.0.0.0 172.20.1.1
ip http server
!
access-list 100 deny ip 192.168.20.0 0.0.0.255 192.168.18.0 0.0.0.255
access-list 100 deny ip 192.168.20.0 0.0.0.255 172.20.10.0 0.0.0.255
access-list 100 deny ip 192.168.20.0 0.0.0.255 192.168.19.0 0.0.0.255
access-list 100 deny tcp 192.168.20.0 0.0.0.255 172.20.1.0 0.0.0.255 eq www
access-list 100 deny icmp 192.168.20.0 0.0.0.255 172.20.1.0 0.0.0.255
access-list 100 deny tcp 192.168.20.0 0.0.0.255 172.20.1.0 0.0.0.255 eq telnet
access-list 100 deny tcp 192.168.20.0 0.0.0.255 172.20.1.0 0.0.0.255 eq 22
access-list 100 permit tcp 192.168.20.0 0.0.0.255 any eq 1863 --------------(MSN)
access-list 100 deny tcp 192.168.20.0 0.0.0.255 any range 1025 65535
access-list 100 deny udp 192.168.20.0 0.0.0.255 any range 1025 65535
access-list 100 permit ip any any
!
control-plane
!
!
line con 0
logging synchronous
line vty 0 4
password 7 11190B0B161001
login local
line vty 5 15
no login
!
end
PRN-BJ-3560# sh ver
Cisco IOS Software, C3560 Software (C3560-IPBASE-M), Version 12.2(35)SE5, RELEASE SOFTWARE (fc1)
Copyright (c) 1986-2007 by Cisco Systems, Inc.
Compiled Thu 19-Jul-07 18:15 by nachen
Image text-base: 0x00003000, data-base: 0x01100000
ROM: Bootstrap program is C3560 boot loader
BOOTLDR: C3560 Boot Loader (C3560-HBOOT-M) Version 12.2(25r)SEE4, RELEASE SOFTWARE (fc1)
PRN-BJ-3560 uptime is 6 hours, 12 minutes
System returned to ROM by power-on
System image file is "flash:c3560-ipbase-mz.122-35.SE5/c3560-ipbase-mz.122-35.SE5.bin"
cisco WS-C3560G-24TS (PowerPC405) processor (revision D0) with 122880K/8184K bytes of memory.
Processor board ID FOC1324Z61W
Last reset from power-on
5 Virtual Ethernet interfaces
28 Gigabit Ethernet interfaces
The password-recovery mechanism is enabled.
512K bytes of flash-simulated non-volatile configuration memory.
Base ethernet MAC Address : 00:26:51:10:F5:00
Motherboard assembly number : 73-10215-04
Power supply part number : 341-0098-02
Motherboard serial number : FOC13243678
Power supply serial number : AZS132505KV
Model revision number : D0
Motherboard revision number : D0
Model number : WS-C3560G-24TS-S
System serial number : FOC1324Z61W
Top Assembly Part Number : 800-26851-01
Top Assembly Revision Number : D0
Version ID : V03
CLEI Code Number : CNMW200ARC
Hardware Board Revision Number : 0x09
Switch Ports Model SW Version SW Image
------ ----- ----- ---------- ----------
* 1 28 WS-C3560G-24TS 12.2(35)SE5 C3560-IPBASE-M
Configuration register is 0xF
PRN-BJ-3560#show vlan
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Gi0/19, Gi0/20, Gi0/21, Gi0/22
Gi0/23, Gi0/24, Gi0/25, Gi0/26
Gi0/27, Gi0/28
2 Managerment active Gi0/1
18 Office active
19 Server active Gi0/2, Gi0/3, Gi0/4, Gi0/5
Gi0/6, Gi0/7, Gi0/8, Gi0/9
Gi0/10, Gi0/11, Gi0/12, Gi0/13
20 Guest active
1002 fddi-default act/unsup
1003 trcrf-default act/unsup
1004 fddinet-default act/unsup
1005 trbrf-default act/unsup
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1 enet 100001 1500 - - - - - 0 0
2 enet 100002 1500 - - - - - 0 0
18 enet 100018 1500 - - - - - 0 0
19 enet 100019 1500 - - - - - 0 0
PRN-BJ-3560#sh vtp status
VTP Version : 2
Configuration Revision : 5
Maximum VLANs supported locally : 1005
Number of existing VLANs : 9
|
|