Building configuration... !! IOS XR Configuration 6.2.25 !! Last configuration change at Tue Jan 23 07:51:37 2018 by cisco ! hostname asr9k1_Master taskgroup otp task read network task read config-services task write network task execute network inherit taskgroup cisco-support ! usergroup otp taskgroup otp description ---OTP_taskgroup--- ! logging buffered 307200 telnet vrf mgmt ipv4 server max-servers 10 telnet vrf default ipv4 server max-servers 10 aaa server radius dynamic-author port 3799 client 172.17.53.27 vrf mgmt server-key ! client 172.17.57.37 vrf mgmt server-key ! ! username otp group otp password ! aaa group server radius AUTH deadtime 10 vrf mgmt throttle access 1000 access-timeout 3 accounting 0 server-private 172.17.57.37 auth-port 1812 acct-port 1813 key ! server-private 172.17.53.27 auth-port 1812 acct-port 1813 key ! ! vrf srg address-family ipv4 unicast ! ! vrf fake address-family ipv4 unicast ! ! vrf mgmt address-family ipv4 unicast ! ! address-family ipv4 unicast ! snmp-server interface MgmtEth0/RSP0/CPU0/0 ! snmp-server vrf mgmt ! dhcp ipv4 profile DHCP_RELAY relay helper-address vrf default 10.117.162.226 giaddr 10.111.122.254 helper-address vrf default 10.117.162.229 giaddr 10.111.122.254 ! interface Bundle-Ether91.403 relay profile DHCP_RELAY interface Bundle-Ether91.404 relay profile DHCP_RELAY interface Bundle-Ether91.412 relay profile DHCP_RELAY interface Bundle-Ether91.413 relay profile DHCP_RELAY interface Bundle-Ether91.414 relay profile DHCP_RELAY interface Bundle-Ether91.433 relay profile DHCP_RELAY interface Bundle-Ether91.564 relay profile DHCP_RELAY ! ntp server 172.17.0.1 prefer source MgmtEth0/RSP0/CPU0/0 update-calendar ! control-plane management-plane out-of-band vrf mgmt interface MgmtEth0/RSP0/CPU0/0 allow all peer address ipv4 10.1.0.0/23 address ipv4 172.17.0.0/24 address ipv4 172.17.53.0/24 ! allow SSH allow Telnet ! ! ! ! dynamic-template type ipsubscriber DYNTPL_IP_SUB_26 timeout idle 600 traffic inbound ipv4 unnumbered Loopback26 ipv4 access-group ACL_DENY_IN ingress ipv4 access-group ACL_DENY_OUT egress ! ! ipv4 access-list ACL_HTTP 10 permit tcp any any eq www 20 permit tcp any eq www any ! ipv4 access-list ACL_SNMP 10 permit ipv4 host 172.17.53.11 host 172.17.0.212 20 permit ipv4 172.17.0.0/24 host 172.17.0.212 30 permit ipv4 10.1.0.0/23 host 172.17.0.212 ! ipv4 access-list ACL_DENY_IN 100 deny ipv4 any any ! ipv4 access-list ACL_DENY_OUT 100 deny ipv4 any any ! ipv4 access-list ACL_PERMIT_ANY 10 permit ipv4 any any ! ipv4 access-list ACL_DENY_VOIP_IN 10 permit udp any eq bootps any eq bootpc 20 permit udp any eq bootpc any eq bootps 40 deny ipv4 any any ! ipv4 access-list ACL_DENY_VOIP_OUT 10 permit udp any eq bootps any eq bootpc 20 permit udp any eq bootpc any eq bootps 40 deny ipv4 any any ! ipv4 access-list ACL_PERMIT_ANY_IN 10 permit ipv4 any 10.10.25.0/24 200 deny ipv4 any 10.0.0.0/8 210 deny ipv4 any 172.16.0.0/12 220 deny ipv4 any 192.168.0.0/16 230 permit ipv4 any any ! ipv4 access-list HTTP_REDIRECT_ACL 10 permit tcp any any eq www 20 permit tcp any eq www any ! ipv4 access-list ACL_DENY_ACCESS_IN 900 permit ipv4 any any 1000 deny ipv4 any any ! ipv4 access-list ACL_PERMIT_ANY_OUT 10 permit ipv4 10.10.25.0/24 any 200 deny ipv4 10.0.0.0/8 any 210 deny ipv4 172.16.0.0/12 any 220 deny ipv4 192.168.0.0/16 any 230 permit ipv4 any any ! ipv4 access-list ACL_PERMIT_VOIP_IN 5 permit ipv4 any 10.117.174.0/24 10 permit ipv4 any 10.117.162.160/27 20 permit ipv4 any 10.117.175.0/24 30 permit udp any eq bootps any eq bootpc 40 permit udp any eq bootpc any eq bootps 50 permit ipv4 any 10.1.1.0/24 55 permit ipv4 10.0.0.0/8 10.0.0.0/8 60 deny ipv4 any any ! ipv4 access-list ACL_DENY_ACCESS_OUT 100 deny ipv4 any any 900 permit ipv4 any any ! ipv4 access-list ACL_PERMIT_VOIP_OUT 5 permit ipv4 10.117.174.0/24 any 10 permit ipv4 10.117.162.160/27 any 20 permit ipv4 10.117.175.0/24 any 30 permit udp any eq bootps any eq bootpc 40 permit udp any eq bootpc any eq bootps 50 permit ipv4 10.1.1.0/24 any 55 permit ipv4 10.0.0.0/8 10.0.0.0/8 60 deny ipv4 any any ! ipv4 access-list ACL_PERMIT_ALWAYS_NETS 10 permit ipv4 host 10.117.165.123 any 20 permit ipv4 host 10.117.174.112 any 30 permit ipv4 host 10.117.175.20 any 40 permit ipv4 any host 10.117.175.20 50 permit ipv4 any host 10.117.165.123 60 permit ipv4 any host 10.117.174.112 70 permit udp any host 10.117.162.226 eq domain 80 permit udp any host 10.117.162.227 eq domain 90 permit udp any host 10.117.162.228 eq domain 100 permit udp any host 10.117.162.229 eq domain 110 permit udp any host 10.117.162.230 eq domain 120 permit udp any host 10.117.162.231 eq domain 130 permit udp any host 10.117.162.140 eq domain 140 permit udp any host 10.117.163.210 eq domain 150 permit udp host 10.117.162.226 eq domain any 160 permit udp host 10.117.162.227 eq domain any 170 permit udp host 10.117.162.228 eq domain any 180 permit udp host 10.117.162.229 eq domain any 190 permit udp host 10.117.162.230 eq domain any 200 permit udp host 10.117.162.231 eq domain any 210 permit udp host 10.117.162.140 eq domain any 220 permit udp host 10.117.163.210 eq domain any 230 permit udp any eq bootps any eq bootpc 240 permit udp any eq bootpc any eq bootps ! class-map match-any CM_HTTP match access-group ipv4 HTTP_REDIRECT_ACL end-class-map ! class-map match-any CM_OPENGARDEN match access-group ipv4 ACL_PERMIT_ALWAYS_NETS end-class-map ! class-map match-any CM_PERMIT_ALL match access-group ipv4 ACL_PERMIT_ANY end-class-map ! class-map type traffic match-any CM_HTTP match access-group ipv4 HTTP_REDIRECT_ACL end-class-map ! class-map type traffic match-any CM_OPENGARDEN match access-group ipv4 ACL_PERMIT_ALWAYS_NETS end-class-map ! class-map type traffic match-any CM_PERMIT_ALL match access-group ipv4 ACL_PERMIT_ANY end-class-map ! policy-map QOS_64K_IN class CM_PERMIT_ALL police rate 64 kbps burst 12000 bytes peak-burst 24000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_128K_IN class CM_PERMIT_ALL police rate 128 kbps burst 24 kbytes peak-burst 48 kbytes ! ! class class-default ! end-policy-map ! policy-map QOS_256K_IN class CM_PERMIT_ALL police rate 256 kbps burst 48000 bytes peak-burst 96000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_512K_IN class CM_PERMIT_ALL police rate 512 kbps burst 96 kbytes peak-burst 192 kbytes ! ! class class-default ! end-policy-map ! policy-map QOS_64K_OUT class CM_PERMIT_ALL shape average 64 kbps ! class class-default ! end-policy-map ! policy-map QOS_750K_IN class CM_PERMIT_ALL police rate 750 kbps burst 140625 bytes peak-burst 281250 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_1000K_IN class CM_PERMIT_ALL police rate 1 mbps burst 187500 bytes peak-burst 375000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_128K_OUT class CM_PERMIT_ALL shape average 128 kbps ! class class-default ! end-policy-map ! policy-map QOS_1500K_IN class CM_PERMIT_ALL police rate 1500 kbps burst 281250 bytes peak-burst 562500 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_2000K_IN class CM_PERMIT_ALL police rate 2 mbps burst 375000 bytes peak-burst 750000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_256K_OUT class CM_PERMIT_ALL shape average 256 kbps ! class class-default ! end-policy-map ! policy-map QOS_3000K_IN class CM_PERMIT_ALL police rate 3 mbps burst 562500 bytes peak-burst 1125000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_4000K_IN class CM_PERMIT_ALL police rate 4 mbps burst 750000 bytes peak-burst 1500000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_5000K_IN class CM_PERMIT_ALL police rate 5 mbps burst 937500 bytes peak-burst 1875000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_512K_OUT class CM_PERMIT_ALL shape average 512 kbps ! class class-default ! end-policy-map ! policy-map QOS_6000K_IN class CM_PERMIT_ALL police rate 6 mbps burst 1125000 bytes peak-burst 2250000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_7000K_IN class CM_PERMIT_ALL police rate 7 mbps burst 1312500 bytes peak-burst 2625000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_750K_OUT class CM_PERMIT_ALL shape average 750 kbps ! class class-default ! end-policy-map ! policy-map QOS_8000K_IN class CM_PERMIT_ALL police rate 8 mbps burst 1500000 bytes peak-burst 3000000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_10000K_IN class CM_PERMIT_ALL police rate 10 mbps burst 1875000 bytes peak-burst 3750000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_1000K_OUT class CM_PERMIT_ALL shape average 1 mbps ! class class-default ! end-policy-map ! policy-map QOS_12000K_IN class CM_PERMIT_ALL police rate 12 mbps burst 2250000 bytes peak-burst 4500000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_15000K_IN class CM_PERMIT_ALL police rate 15 mbps burst 2812500 bytes peak-burst 5625000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_1500K_OUT class CM_PERMIT_ALL shape average 1500 kbps ! class class-default ! end-policy-map ! policy-map QOS_16000K_IN class CM_PERMIT_ALL police rate 16 mbps burst 3000000 bytes peak-burst 6000000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_20000K_IN class CM_PERMIT_ALL police rate 20 mbps burst 3750000 bytes peak-burst 7500000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_2000K_OUT class CM_PERMIT_ALL shape average 2 mbps ! class class-default ! end-policy-map ! policy-map QOS_25000K_IN class CM_PERMIT_ALL police rate 25 mbps burst 4687500 bytes peak-burst 9375000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_30000K_IN class CM_PERMIT_ALL police rate 30 mbps burst 5625000 bytes peak-burst 11250000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_3000K_OUT class CM_PERMIT_ALL shape average 3 mbps ! class class-default ! end-policy-map ! policy-map QOS_35000K_IN class CM_PERMIT_ALL police rate 35 mbps burst 6562500 bytes peak-burst 13125000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_40000K_IN class CM_PERMIT_ALL police rate 40 mbps burst 7500000 bytes peak-burst 15000000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_4000K_OUT class CM_PERMIT_ALL shape average 4 mbps ! class class-default ! end-policy-map ! policy-map QOS_50000K_IN class CM_PERMIT_ALL police rate 50 mbps burst 9375000 bytes peak-burst 18750000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_5000K_OUT class CM_PERMIT_ALL shape average 5 mbps ! class class-default ! end-policy-map ! policy-map QOS_55000K_IN class CM_PERMIT_ALL police rate 55 mbps burst 10312500 bytes peak-burst 20625000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_60000K_IN class CM_PERMIT_ALL police rate 60 mbps burst 11250000 bytes peak-burst 22500000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_6000K_OUT class CM_PERMIT_ALL shape average 6 mbps ! class class-default ! end-policy-map ! policy-map QOS_7000K_OUT class CM_PERMIT_ALL shape average 7 mbps ! class class-default ! end-policy-map ! policy-map QOS_8000K_OUT class CM_PERMIT_ALL shape average 8 mbps ! class class-default ! end-policy-map ! policy-map QOS_100000K_IN class CM_PERMIT_ALL police rate 100 mbps burst 18750000 bytes peak-burst 37500000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_10000K_OUT class CM_PERMIT_ALL shape average 10 mbps ! class class-default ! end-policy-map ! policy-map QOS_12000K_OUT class CM_PERMIT_ALL shape average 12 mbps ! class class-default ! end-policy-map ! policy-map QOS_150000K_IN class CM_PERMIT_ALL police rate 150 mbps burst 28125000 bytes peak-burst 56250000 bytes ! ! class class-default ! end-policy-map ! policy-map QOS_15000K_OUT class CM_PERMIT_ALL shape average 15 mbps ! class class-default ! end-policy-map ! policy-map QOS_16000K_OUT class CM_PERMIT_ALL shape average 16 mbps ! class class-default ! end-policy-map ! policy-map QOS_20000K_OUT class CM_PERMIT_ALL shape average 20 mbps ! class class-default ! end-policy-map ! policy-map QOS_25000K_OUT class CM_PERMIT_ALL shape average 25 mbps ! class class-default ! end-policy-map ! policy-map QOS_30000K_OUT class CM_PERMIT_ALL shape average 30 mbps ! class class-default ! end-policy-map ! policy-map QOS_35000K_OUT class CM_PERMIT_ALL shape average 35 mbps ! class class-default ! end-policy-map ! policy-map QOS_40000K_OUT class CM_PERMIT_ALL shape average 40 mbps ! class class-default ! end-policy-map ! policy-map QOS_50000K_OUT class CM_PERMIT_ALL shape average 50 mbps ! class class-default ! end-policy-map ! policy-map QOS_55000K_OUT class CM_PERMIT_ALL shape average 55 mbps ! class class-default ! end-policy-map ! policy-map QOS_60000K_OUT class CM_PERMIT_ALL shape average 60 mbps ! class class-default ! end-policy-map ! policy-map QOS_100000K_OUT class CM_PERMIT_ALL shape average 100 mbps ! class class-default shape average 8 kbps ! end-policy-map ! policy-map QOS_150000K_OUT class CM_PERMIT_ALL shape average 150 mbps ! class class-default ! end-policy-map ! policy-map type pbr PBR_PERMIT_ANY class type traffic CM_PERMIT_ALL transmit ! class type traffic class-default ! end-policy-map ! policy-map type pbr PBR_DENY_ACCESS class type traffic CM_OPENGARDEN transmit ! class type traffic CM_HTTP http-redirect http://10.117.175.20 ! class type traffic class-default drop ! end-policy-map ! interface Bundle-Ether91 description ---SRG1_BE--- ! interface Bundle-Ether91.403 description --_VLAN403-- ipv4 point-to-point ipv4 unnumbered Loopback26 service-policy type control subscriber PM_IPoE_26 encapsulation dot1q 403 ipsubscriber ipv4 l2-connected initiator dhcp initiator unclassified-source ! ! interface Bundle-Ether91.404 description --_VLAN404-- ipv4 point-to-point ipv4 unnumbered Loopback26 service-policy type control subscriber PM_IPoE_26 encapsulation dot1q 404 ipsubscriber ipv4 l2-connected initiator dhcp initiator unclassified-source ! ! interface Bundle-Ether91.412 description --_VLAN412-- ipv4 point-to-point ipv4 unnumbered Loopback26 service-policy type control subscriber PM_IPoE_26 encapsulation dot1q 412 ipsubscriber ipv4 l2-connected initiator dhcp initiator unclassified-source ! ! interface Bundle-Ether91.413 description --_VLAN413-- ipv4 point-to-point ipv4 unnumbered Loopback26 service-policy type control subscriber PM_IPoE_26 encapsulation dot1q 413 ipsubscriber ipv4 l2-connected initiator dhcp initiator unclassified-source ! ! interface Bundle-Ether91.414 description --_VLAN414-- ipv4 point-to-point ipv4 unnumbered Loopback26 service-policy type control subscriber PM_IPoE_26 encapsulation dot1q 414 ipsubscriber ipv4 l2-connected initiator dhcp initiator unclassified-source ! ! interface Bundle-Ether91.433 description --_VLAN433-- ipv4 point-to-point ipv4 unnumbered Loopback26 service-policy type control subscriber PM_IPoE_26 encapsulation dot1q 433 ipsubscriber ipv4 l2-connected initiator dhcp initiator unclassified-source ! ! interface Bundle-Ether91.564 description --_VLAN564-- ipv4 point-to-point ipv4 unnumbered Loopback26 service-policy type control subscriber PM_IPoE_26 encapsulation dot1q 564 ipsubscriber ipv4 l2-connected initiator dhcp initiator unclassified-source ! ! interface Bundle-Ether91.4093 description ---SRG1_track--- vrf srg ipv4 address 10.255.26.1 255.255.255.248 encapsulation dot1q 4093 ! interface Bundle-Ether92 description --PO_192_Nexus_BGP_4_ASR-- ! interface Bundle-Ether92.73 description ---7609_kir_bgp_ext--- ipv4 address 10.117.165.193 255.255.255.252 encapsulation dot1q 73 ! interface Bundle-Ether92.77 description ---7609_kir_bgp_int--- ipv4 address 10.117.165.197 255.255.255.252 encapsulation dot1q 77 ! interface Loopback26 ipv4 address 10.143.108.254 255.255.255.0 ipv4 address 10.122.122.254 255.255.255.0 secondary ipv4 address 10.227.194.254 255.255.255.0 secondary ipv4 address 10.227.195.254 255.255.255.0 secondary ipv4 address 10.227.209.254 255.255.255.0 secondary ipv4 address 10.227.247.254 255.255.255.0 secondary ipv4 address 10.227.251.254 255.255.255.0 secondary ipv4 address 10.243.108.254 255.255.255.0 secondary ipv4 address 10.243.109.254 255.255.255.0 secondary ipv4 address 10.252.8.254 255.255.255.0 secondary ipv4 address 10.252.9.254 255.255.255.0 secondary ipv4 address 10.252.10.254 255.255.255.0 secondary ipv4 address 10.252.11.254 255.255.255.0 secondary ipv4 address 10.252.12.254 255.255.255.0 secondary ipv4 address 10.252.13.254 255.255.255.0 secondary ipv4 address 10.252.14.254 255.255.255.0 secondary ipv4 address 10.252.15.254 255.255.255.0 secondary ipv4 address 10.252.44.254 255.255.255.0 secondary ipv4 address 10.252.45.254 255.255.255.0 secondary ipv4 address 10.252.46.254 255.255.255.0 secondary ipv4 address 10.252.47.254 255.255.255.0 secondary ipv4 address 10.252.48.254 255.255.255.0 secondary ipv4 address 10.252.49.254 255.255.255.0 secondary ipv4 address 10.252.50.254 255.255.255.0 secondary ipv4 address 10.252.51.254 255.255.255.0 secondary ipv4 address 10.252.52.254 255.255.255.0 secondary ipv4 address 10.252.53.254 255.255.255.0 secondary ipv4 address 10.252.54.254 255.255.255.0 secondary ipv4 address 10.252.55.254 255.255.255.0 secondary ipv4 address 10.111.122.254 255.255.255.0 secondary ipv4 address 10.143.109.254 255.255.255.0 secondary ipv4 address 10.117.194.254 255.255.255.0 secondary ipv4 address 10.117.195.254 255.255.255.0 secondary ipv4 address 10.117.209.254 255.255.255.0 secondary ipv4 address 10.117.247.254 255.255.255.0 secondary ipv4 address 10.117.251.254 255.255.255.0 secondary ! interface MgmtEth0/RSP0/CPU0/0 vrf mgmt ipv4 address 172.17.0.212 255.255.255.0 ! interface MgmtEth0/RSP0/CPU0/1 shutdown ! interface TenGigE0/0/2/0 description --csw-c3064-Master-1_eth1/9-- bundle id 92 mode passive ! interface TenGigE0/0/2/1 description --csw-c3064-Master-1_eth1/13-- bundle id 91 mode passive transceiver permit pid all ! interface TenGigE0/0/2/2 description --csw-c3064-Master-1_eth1/10-- bundle id 92 mode passive ! interface TenGigE0/0/2/3 description --csw-c3064-Master-1_eth1/14-- shutdown ! ! prefix-set RFC1918 10.0.0.0/8 le 30, 172.16.0.0/12 le 30, 192.168.0.0/16 le 30, 100.64.0.0/10 le 30 end-set ! prefix-set PS_SRG_MASTER 10.143.108.0/24, 10.227.194.0/24, 10.227.195.0/24, 10.227.209.0/24, 10.243.108.0/24, 10.243.109.0/24, 10.252.8.0/24, 10.252.9.0/24, 10.252.10.0/24, 10.252.11.0/24, 10.252.12.0/24, 10.252.13.0/24, 10.252.14.0/24, 10.252.15.0/24, 10.252.44.0/24, 10.252.45.0/24, 10.252.46.0/24, 10.252.47.0/24, 10.252.48.0/24, 10.252.49.0/24, 10.252.50.0/24, 10.252.51.0/24, 10.252.52.0/24, 10.252.53.0/24, 10.252.54.0/24, 10.252.55.0/24, 10.143.109.0/24, 10.117.194.0/24, 10.117.195.0/24, 10.117.209.0/24, 10.111.122.0/24, 10.122.122.0/24, 10.117.247.0/24, 10.227.247.0/24, 10.117.251.0/24, 10.227.251.0/24 end-set ! route-policy RP_IN pass end-policy ! route-policy RP_OUT if destination in PS_SRG_MASTER then set community (65533:20001) endif if destination in PS_SRG_SLAVE then set community (65533:20000) endif end-policy ! route-policy RP_EXT_OUT apply RP_OUT end-policy ! route-policy RP_INT_OUT apply RP_OUT end-policy ! route-policy SUBSCRIBERS_ROUTES if tag is 1 then pass endif end-policy ! router static address-family ipv4 unicast ! vrf mgmt address-family ipv4 unicast 0.0.0.0/0 172.17.0.254 ! ! ! router bgp 64701 bgp router-id 10.117.165.193 address-family ipv4 unicast redistribute connected <<--- I had to add this, because next row doesn't work redistribute subscriber route-policy SUBSCRIBERS_ROUTES ! neighbor 10.117.165.194 remote-as 65533 address-family ipv4 unicast send-community-ebgp route-policy RP_IN in route-policy RP_EXT_OUT out soft-reconfiguration inbound always ! ! neighbor 10.117.165.198 remote-as 65533 address-family ipv4 unicast send-community-ebgp route-policy RP_IN in route-policy RP_INT_OUT out soft-reconfiguration inbound always ! ! ! ipsla operation 26 type icmp echo vrf srg source address 10.255.26.1 destination address 10.255.26.3 timeout 3000 frequency 10 ! ! schedule operation 26 start-time now life forever ! ! track srg_1st_cluster type rtr 26 reachability delay up 60 delay down 40 ! aaa attribute format VLAN_MAC format-string length 253 "0%s.%s.%s" outer-vlan-id client-mac-address-raw addr ! aaa radius attribute nas-port format e SSAAAPPPPPVVVVVVVVVVVVVVVVVVVVVV type 40 aaa radius attribute nas-port format e SSAAAPPPPPQQQQQQQQQQQVVVVVVVVVVV type 41 aaa radius attribute nas-port format e PPPPPPPPVVVVVVVVVVVVVVVVUUUUUUUU type 43 aaa authorization subscriber default group AUTH aaa authentication subscriber default group AUTH subscriber redundancy source-interface Bundle-Ether92.77 group 1 preferred-role master virtual-mac 42ce.2400.0026 slave-mode hot hold-timer 5 peer 10.117.165.205 peer route-disable access-tracking srg_1st_cluster state-control-route ipv4 10.252.8.0/24 vrf default tag 1 state-control-route ipv4 10.252.9.0/24 vrf default tag 1 state-control-route ipv4 10.252.10.0/24 vrf default tag 1 state-control-route ipv4 10.252.11.0/24 vrf default tag 1 state-control-route ipv4 10.252.12.0/24 vrf default tag 1 state-control-route ipv4 10.252.13.0/24 vrf default tag 1 state-control-route ipv4 10.252.14.0/24 vrf default tag 1 state-control-route ipv4 10.252.15.0/24 vrf default tag 1 state-control-route ipv4 10.252.44.0/24 vrf default tag 1 state-control-route ipv4 10.252.45.0/24 vrf default tag 1 state-control-route ipv4 10.252.46.0/24 vrf default tag 1 state-control-route ipv4 10.252.47.0/24 vrf default tag 1 state-control-route ipv4 10.252.48.0/24 vrf default tag 1 state-control-route ipv4 10.252.49.0/24 vrf default tag 1 state-control-route ipv4 10.252.50.0/24 vrf default tag 1 state-control-route ipv4 10.252.51.0/24 vrf default tag 1 state-control-route ipv4 10.252.52.0/24 vrf default tag 1 state-control-route ipv4 10.252.53.0/24 vrf default tag 1 state-control-route ipv4 10.252.54.0/24 vrf default tag 1 state-control-route ipv4 10.252.55.0/24 vrf default tag 1 state-control-route ipv4 10.122.122.0/24 vrf default tag 1 state-control-route ipv4 10.227.194.0/24 vrf default tag 1 state-control-route ipv4 10.227.195.0/24 vrf default tag 1 state-control-route ipv4 10.227.209.0/24 vrf default tag 1 state-control-route ipv4 10.227.247.0/24 vrf default tag 1 state-control-route ipv4 10.227.251.0/24 vrf default tag 1 state-control-route ipv4 10.243.108.0/24 vrf default tag 1 state-control-route ipv4 10.243.109.0/24 vrf default tag 1 state-control-route ipv4 10.111.122.0/24 vrf default tag 1 state-control-route ipv4 10.143.108.0/24 vrf default tag 1 state-control-route ipv4 10.143.109.0/24 vrf default tag 1 state-control-route ipv4 10.117.194.0/24 vrf default tag 1 state-control-route ipv4 10.117.195.0/24 vrf default tag 1 state-control-route ipv4 10.117.209.0/24 vrf default tag 1 state-control-route ipv4 10.117.247.0/24 vrf default tag 1 state-control-route ipv4 10.117.251.0/24 vrf default tag 1 revertive-timer 2 maximum 3 interface-list interface Bundle-Ether91.403 id 403 interface Bundle-Ether91.404 id 404 interface Bundle-Ether91.412 id 412 interface Bundle-Ether91.413 id 413 interface Bundle-Ether91.414 id 414 interface Bundle-Ether91.433 id 433 interface Bundle-Ether91.564 id 564 ! class-map type control subscriber match-all NORESP_TIMER_CLASS match timer TIMER_NORESP match authen-status unauthenticated end-class-map ! ! ! ! ! class-map type control subscriber match-all UNAUTH_TIMER_CLASS match timer TIMER_UNAUTH match authen-status unauthenticated end-class-map ! class-map type control subscriber match-all AUTHFAIL_TIMER_CLASS match timer TIMER_FAIL match authen-status unauthenticated end-class-map ! policy-map type control subscriber PM_IPoE_26 event session-start match-first class type control subscriber class-default do-until-failure 10 set-timer TIMER_UNAUTH 1 20 activate dynamic-template DYNTPL_IP_SUB_26 30 authorize aaa list default format VLAN_MAC password ntsvector ! ! event authorization-failure match-first class type control subscriber class-default do-all 10 set-timer TIMER_FAIL 10 20 disconnect ! ! event authorization-no-response match-first class type control subscriber class-default do-all 10 set-timer TIMER_NORESP 2 ! ! event timer-expiry match-first class type control subscriber UNAUTH_TIMER_CLASS do-all 10 set-timer TIMER_UNAUTH 3 20 authorize aaa list default format VLAN_MAC password ntsvector ! class type control subscriber AUTHFAIL_TIMER_CLASS do-all 10 set-timer TIMER_FAIL 2 20 authorize aaa list default format VLAN_MAC password ntsvector ! class type control subscriber NORESP_TIMER_CLASS do-all 10 set-timer TIMER_NORESP 2 20 authorize aaa list default format VLAN_MAC password ntsvector ! ! end-policy-map ! end