Building configuration... Current configuration : 5690 bytes ! ! Last configuration change at 12:17:54 GMT+1 Fri Feb 26 2010 ! NVRAM config last updated at 11:09:09 GMT+1 Fri Feb 26 2010 ! version 12.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption ! hostname R2 ! boot-start-marker warm-reboot boot-end-marker ! logging message-counter syslog ! no aaa new-model memory-size iomem 15 clock timezone GMT+1 1 ! dot11 syslog ip source-route ip cef ! ! ! ! ip domain name ipexpert.com ip vrf VRF ! no ipv6 cef ntp master 2 ! multilink bundle-name authenticated ! ! ! ! ! voice-card 0 ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! crypto pki server IOS_CA database archive pem password 7 08285C4B1109000506 grant auto cdp-url http://8.9.50.2/cgi-bin/pkiclient.exe?operation=GetCRL auto-rollover ! crypto pki trustpoint IOS_CA revocation-check crl rsakeypair IOS_CA ! ! crypto pki certificate chain IOS_CA certificate ca 01 308201FB 30820164 A0030201 02020101 300D0609 2A864886 F70D0101 04050030 11310F30 0D060355 04030C06 494F535F 4341301E 170D3130 30323236 30363130 33315A17 0D313330 32323530 36313033 315A3011 310F300D 06035504 030C0649 4F535F43 4130819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281 8100CACA 4A9FE4E3 A5F36DAD 4A976ECD 1645A29F 136CE306 F98CB104 448467A7 0AE68220 0E6B2F19 DC932CE8 4809C99A B3FEE12B 13D89FF7 1F1BB5D5 9A5ED1F3 581933F5 107DF9C5 3721BCC2 8BC4A888 D481733D 8B71A871 A438406C 69A1A5F3 F8FB2649 CFCEA898 434A0CAF D0663D49 3811218C A58DBBE2 45C3BE68 AB918A2A 13CF0203 010001A3 63306130 0F060355 1D130101 FF040530 030101FF 300E0603 551D0F01 01FF0404 03020186 301F0603 551D2304 18301680 147E7672 E4160773 A58B5506 4B07CDDA 0C72C28B 03301D06 03551D0E 04160414 7E7672E4 160773A5 8B55064B 07CDDA0C 72C28B03 300D0609 2A864886 F70D0101 04050003 8181000D DE6E0703 6F921635 3DFBB36B FF14D3D5 3A0A586D E0EAC615 EBE88925 9CBE9FD3 BDF48F35 4B90A256 EA4D9CDE 720DA65B 76395C4F 8DDBC9CF F7754A1D D0A76A14 8307AD62 C48033E3 6B677AE4 90154E2F 55783EB4 9FA53EE6 588ABD73 FC670D92 96F1B0E8 F01EA635 7D337CBA 40BD9321 FFC6BE9F B70B8627 CB7FC7A2 A9A423 quit ! ! vtp domain CCIE vtp mode transparent archive log config hidekeys ! ! crypto isakmp policy 30 encr 3des authentication pre-share group 2 ! crypto isakmp policy 40 encr aes 192 authentication pre-share crypto isakmp key ipexpert address 8.9.2.10 crypto isakmp key ipexpert hostname r5.ipexpert.com crypto isakmp key ipexpert hostname R5.ipexpert.com ! ! crypto ipsec transform-set TSET-asa1 esp-3des esp-sha-hmac crypto ipsec transform-set SET4 esp-aes 192 esp-sha-hmac ! crypto dynamic-map DYNMAP 10 set transform-set SET4 match address 140 ! ! crypto map CMAP-v2 10 ipsec-isakmp set peer 8.9.2.10 set transform-set TSET-asa1 match address acl_vpn_asa1 qos pre-classify ! crypto map CMAP-v50 10 ipsec-isakmp dynamic DYNMAP ! ! ! vlan 2,7,9-13,16,22-23,26-27,42,48-49,59,67,72,89 ! vlan 100 name OPS-100 ! vlan 101 name OPS-101 ! vlan 102 name OPS-102 ! vlan 112,200 ! vlan 201 name R2-BB1 ! vlan 210,222,230,250,252,302,555 ! vlan 1004 bridge 0 stp type ieee ! ! class-map match-all VPN-QOS-CLASS match access-group 150 ! ! policy-map VPN-QOS class VPN-QOS-CLASS priority 200 ! ! ! ! ! interface Loopback3 ip address 192.168.3.2 255.255.255.0 ! interface Loopback20 ip vrf forwarding VRF ip address 192.168.20.2 255.255.255.0 ! interface Loopback30 ip address 192.168.30.2 255.255.255.0 ! interface GigabitEthernet0/0 no ip address shutdown duplex auto speed auto media-type rj45 ! interface GigabitEthernet0/1 ip address 8.9.2.2 255.255.255.0 duplex auto speed auto media-type rj45 crypto map CMAP-v2 service-policy output VPN-QOS ! interface Serial0/1/0 ip address 8.9.50.2 255.255.255.0 encapsulation frame-relay ip ospf network broadcast ip ospf priority 2 frame-relay map ip 8.9.50.5 205 broadcast frame-relay map ip 8.9.50.6 206 broadcast frame-relay map ip 8.9.50.4 204 broadcast no frame-relay inverse-arp crypto map CMAP-v50 ! interface Serial0/2/0 no ip address shutdown clock rate 2000000 ! interface FastEthernet1/0 shutdown ! interface FastEthernet1/1 shutdown ! interface FastEthernet1/2 shutdown ! interface FastEthernet1/3 shutdown ! interface FastEthernet1/4 shutdown ! interface FastEthernet1/5 shutdown ! interface FastEthernet1/6 shutdown ! interface FastEthernet1/7 shutdown ! interface FastEthernet1/8 shutdown ! interface FastEthernet1/9 shutdown ! interface FastEthernet1/10 shutdown ! interface FastEthernet1/11 shutdown ! interface FastEthernet1/12 shutdown ! interface FastEthernet1/13 shutdown ! interface FastEthernet1/14 shutdown ! interface FastEthernet1/15 shutdown ! interface Vlan1 no ip address ! router ospf 1 router-id 2.2.2.2 log-adjacency-changes network 8.9.2.2 0.0.0.0 area 1 network 8.9.50.2 0.0.0.0 area 0 ! ip forward-protocol nd ip route 10.1.1.0 255.255.255.0 8.9.2.10 ip route 10.5.5.0 255.255.255.0 8.9.50.5 ip http server no ip http secure-server ! ! ! ip access-list extended acl_vpn_asa1 permit ip 192.168.3.0 0.0.0.255 10.1.1.0 0.0.0.255 permit ip 192.168.30.0 0.0.0.255 10.1.1.0 0.0.0.255 ! access-list 140 permit ip 8.9.2.0 0.0.0.255 10.5.5.0 0.0.0.255 access-list 150 permit tcp 192.168.3.0 0.0.0.255 10.1.1.0 0.0.0.255 eq telnet access-list 150 permit tcp 192.168.3.0 0.0.0.255 eq telnet 10.1.1.0 0.0.0.255 ! ! ! ! ! ! control-plane ! ! ! ! mgcp fax t38 ecm mgcp behavior g729-variants static-pt ! ! ! ! ! alias exec srs show run | sect alias exec siib sh ip int brie | excl unassigned ! line con 0 exec-timeout 0 0 logging synchronous line aux 0 line vty 0 4 password cisco login ! scheduler allocate 20000 1000 end R2#