version 15.4 no service pad service tcp-keepalives-in service tcp-keepalives-out service timestamps debug datetime msec service timestamps log datetime localtime show-timezone service password-encryption ! hostname HUB2 ! boot-start-marker boot system flash:c3900-universalk9-mz.SPA.154-3.M9.bin boot-end-marker ! ! logging buffered 128000 enable secret ! aaa new-model ! ! aaa authentication login default group tacacs+ local-case aaa authorization exec default group tacacs+ local aaa accounting exec default start-stop group tacacs+ aaa accounting commands 15 default start-stop group tacacs+ aaa accounting network default start-stop group tacacs+ aaa accounting connection default start-stop group tacacs+ aaa accounting system default start-stop group tacacs+ ! ! ! ! ! aaa session-id common ! ! ! ! ! ! ! ! no ip source-route no ip gratuitous-arps ! ! ! ! ! ! ! ! no ip domain lookup ip cef no ipv6 cef ! ! multilink bundle-name authenticated ! ! ! ! ! archive log config hidekeys username ! redundancy ! ! ! ! ! ip tcp synwait-time 10 ! ! crypto isakmp policy 1 encr aes 256 authentication pre-share group 2 crypto isakmp key cisco address 0.0.0.0 crypto isakmp invalid-spi-recovery crypto isakmp keepalive 60 periodic ! ! crypto ipsec transform-set TRANS2 esp-aes esp-sha-hmac mode transport ! ! crypto ipsec profile dmvpn set transform-set TRANS2 ! ! ! ! ! ! interface Loopback0 ip address 111.189.12.2 255.255.255.255 no ip proxy-arp ! interface Tunnel0 description DMVPN bandwidth 1000000 ip address 111.111.12.2 255.255.0.0 no ip redirects no ip proxy-arp ip mtu 1400 ip authentication mode eigrp 60 md5 ip authentication key-chain eigrp 60 no ip next-hop-self eigrp 60 no ip split-horizon eigrp 60 ip nhrp authentication cisco ip nhrp map multicast dynamic ip nhrp map 111.111.0.2 111.100.0.2 ip nhrp map multicast 111.100.0.2 ip nhrp network-id 1000 ip nhrp holdtime 600 ip nhrp redirect ip summary-address eigrp 60 111.18.0.0 255.240.0.0 ip summary-address eigrp 60 111.189.0.0 255.255.224.0 delay 1000 tunnel source GigabitEthernet0/1 tunnel mode gre multipoint tunnel key 1000 tunnel protection ipsec profile dmvpn ! interface Embedded-Service-Engine0/0 no ip address shutdown ! interface GigabitEthernet0/0 no ip address no ip proxy-arp ip authentication mode eigrp 100 md5 duplex auto speed auto no cdp enable ! interface GigabitEthernet0/0.10 encapsulation dot1Q 10 ip address 111.66.12.1 255.255.255.224 no ip proxy-arp ip tcp adjust-mss 1360 no cdp enable ! interface GigabitEthernet0/0.11 encapsulation dot1Q 11 ip address 111.60.12.1 255.255.255.240 no ip proxy-arp ip tcp adjust-mss 1360 no cdp enable ! interface GigabitEthernet0/1 description FIBER TO CISCO 2960G ip address 111.100.12.2 255.255.255.0 no ip proxy-arp ip authentication mode eigrp 100 md5 duplex auto speed auto no cdp enable ! interface GigabitEthernet0/2 no ip address shutdown duplex auto speed auto no cdp enable ! ! router eigrp 60 network 111.66.12.0 0.0.0.31 network 111.60.12.0 0.0.0.15 network 111.189.12.2 0.0.0.0 network 111.111.0.0 0.0.255.255 ! ! router eigrp 100 network 111.100.0.0 0.0.255.255 redistribute connected ! ip forward-protocol nd ! no ip http server no ip http secure-server ! ip tftp source-interface Loopback0 ip tftp blocksize 8192 ip route 0.0.0.0 0.0.0.0 111.100.12.254 250 !