# LOOP_DETECT
disable loopdetect
config loopdetect recover_timer 60 interval 10 mode port-based
config loopdetect log state enable
config loopdetect ports 1 state disable
config loopdetect ports 2 state disable
config loopdetect ports 3 state disable
config loopdetect ports 4 state disable
config loopdetect ports 5 state disable
config loopdetect ports 6 state disable
config loopdetect ports 7 state disable
config loopdetect ports 8 state disable
config loopdetect ports 9 state disable
config loopdetect ports 10 state disable
config loopdetect ports 11 state disable
config loopdetect ports 12 state disable
config loopdetect ports 13 state disable
config loopdetect ports 14 state disable
config loopdetect ports 15 state disable
config loopdetect ports 16 state disable
config loopdetect ports 17 state disable
config loopdetect ports 18 state disable
config loopdetect ports 19 state disable
config loopdetect ports 20 state disable
config loopdetect ports 21 state disable
config loopdetect ports 22 state disable
config loopdetect ports 23 state disable
config loopdetect ports 24 state disable
config loopdetect ports 25 state disable
config loopdetect ports 26 state disable
config loopdetect trap none
# TRAF-SEGMENTATION
config traffic_segmentation 1-11,14-24 forward_list 25-26
config traffic_segmentation 12 forward_list 13,25-26
config traffic_segmentation 13 forward_list 12,25-26
config traffic_segmentation 25-26 forward_list 1-26
# PORT
disable jumbo_frame
config jumbo_frame ports 1-26 state disable
config ports 1-2,4-6,8,12,14-15,20 speed auto capability_advertised 1000_full auto_negotiation remote_fault_advertised disable flow_control disable learning enable state enable mdix auto
config ports 3,7,9-11,16-18 speed auto capability_advertised 1000_full auto_negotiation remote_fault_advertised disable flow_control disable learning enable state disable mdix auto
config ports 13 speed auto capability_advertised 1000_full auto_negotiation remote_fault_advertised disable flow_control disable learning enable state enable mdix auto description N_ORB.008.RODIMC.2.A.SA1.A26
config ports 19 speed auto capability_advertised 1000_full auto_negotiation remote_fault_advertised disable flow_control disable learning enable state disable mdix auto description N_ORB.008.BREST.32.SA1.A28
# IGMP_MULTICAST_VLAN
config igmp_snooping multicast_vlan forward_unmatched disable
config igmp_snooping multicast_vlan auto_assign_vlan disable
# MLD_MULTICAST_VLAN
config mld_snooping multicast_vlan forward_unmatched disable
config mld_snooping multicast_vlan auto_assign_vlan disable
# VLAN
enable pvid auto_assign
config vlan default delete 1-26
config vlan default advertisement enable
create vlan VLAN2 tag 2
config vlan VLAN2 add tagged 23-26 advertisement disable
create vlan VLAN71 tag 71
config vlan VLAN71 add tagged 12-13 advertisement disable
create vlan VLAN72 tag 72
config vlan VLAN72 add tagged 5,19 advertisement disable
create vlan VLAN251 tag 251
config vlan VLAN251 add tagged 1-20,26
config vlan VLAN251 add untagged 22 advertisement disable
create vlan VLAN351 tag 351
config vlan VLAN351 add tagged 1-20,23-26 advertisement disable
create vlan VLAN781 tag 781
config vlan VLAN781 add tagged 5,19,25-26 advertisement disable
create vlan tv_mgmt tag 785
config vlan tv_mgmt add tagged 1-20,23-26
config vlan tv_mgmt add untagged 21 advertisement disable
disable gvrp
disable asymmetric_vlan
disable vlan_trunk
config port_vlan 1-20,23-24 gvrp_state enable ingress_checking enable acceptable_frame admit_all pvid 1
config port_vlan 21 gvrp_state enable ingress_checking enable acceptable_frame admit_all pvid 785
config port_vlan 22 gvrp_state enable ingress_checking enable acceptable_frame admit_all pvid 251
config port_vlan 25-26 gvrp_state disable ingress_checking enable acceptable_frame admit_all pvid 1
# FDB
config fdb aging_time 300
config fdb vlan_learning vlanid 1-2,71-72,251,351,781,785 state enable
# ADDRBIND
config address_binding dhcp_snoop max_entry ports 1 limit no_limit
config address_binding dhcp_snoop max_entry ports 2 limit no_limit
config address_binding dhcp_snoop max_entry ports 3 limit no_limit
config address_binding dhcp_snoop max_entry ports 4 limit no_limit
config address_binding dhcp_snoop max_entry ports 5 limit no_limit
config address_binding dhcp_snoop max_entry ports 6 limit no_limit
config address_binding dhcp_snoop max_entry ports 7 limit no_limit
config address_binding dhcp_snoop max_entry ports 8 limit no_limit
config address_binding dhcp_snoop max_entry ports 9 limit no_limit
config address_binding dhcp_snoop max_entry ports 10 limit no_limit
config address_binding dhcp_snoop max_entry ports 11 limit no_limit
config address_binding dhcp_snoop max_entry ports 12 limit no_limit
config address_binding dhcp_snoop max_entry ports 13 limit no_limit
config address_binding dhcp_snoop max_entry ports 14 limit no_limit
config address_binding dhcp_snoop max_entry ports 15 limit no_limit
config address_binding dhcp_snoop max_entry ports 16 limit no_limit
config address_binding dhcp_snoop max_entry ports 17 limit no_limit
config address_binding dhcp_snoop max_entry ports 18 limit no_limit
config address_binding dhcp_snoop max_entry ports 19 limit no_limit
config address_binding dhcp_snoop max_entry ports 20 limit no_limit
config address_binding dhcp_snoop max_entry ports 21 limit no_limit
config address_binding dhcp_snoop max_entry ports 22 limit no_limit
config address_binding dhcp_snoop max_entry ports 23 limit no_limit
config address_binding dhcp_snoop max_entry ports 24 limit no_limit
config address_binding dhcp_snoop max_entry ports 25 limit no_limit
config address_binding dhcp_snoop max_entry ports 26 limit no_limit
disable address_binding dhcp_snoop
disable address_binding trap_log
enable address_binding roaming
config address_binding dhcp_snoop_entry filename d:/dhcpsnp.cfg autosave enable
disable address_binding dhcp_snoop ipv6
disable address_binding dhcp_pd_snoop
disable address_binding nd_snoop
config address_binding dhcp_snoop max_entry ports 1-26 limit no_limit ipv6
config address_binding nd_snoop ports 1-26 max_entry no_limit
# NetBiosFilter
config filter netbios all state disable
config filter extensive_netbios all state disable
# DoS
config dos_prevention dos_type land_attack action drop state disable
config dos_prevention dos_type blat_attack action drop state disable
config dos_prevention dos_type tcp_null_scan action drop state disable
config dos_prevention dos_type tcp_xmasscan action drop state disable
config dos_prevention dos_type tcp_synfin action drop state disable
config dos_prevention dos_type tcp_syn_srcport_less_1024 action drop state disable
config dos_prevention dos_type ping_death_attack action drop state disable
config dos_prevention dos_type tcp_tiny_frag_attack action drop state disable
config dos_prevention trap disable
config dos_prevention log disable
# ND_SNOOPING
# DhcpServerScreening
config filter dhcp_server ports all state disable
config filter dhcp_server illegal_server_log_suppress_duration 5min
config filter dhcp_server trap disable
config filter dhcp_server log enable
# sRED
config dscp trust all state disable
config dscp map all dscp_dscp 0 to 0
config dscp map all dscp_dscp 1 to 1
config dscp map all dscp_dscp 2 to 2
config dscp map all dscp_dscp 3 to 3
config dscp map all dscp_dscp 4 to 4
config dscp map all dscp_dscp 5 to 5
config dscp map all dscp_dscp 6 to 6
config dscp map all dscp_dscp 7 to 7
config dscp map all dscp_dscp 8 to 8
config dscp map all dscp_dscp 9 to 9
config dscp map all dscp_dscp 10 to 10
config dscp map all dscp_dscp 11 to 11
config dscp map all dscp_dscp 12 to 12
config dscp map all dscp_dscp 13 to 13
config dscp map all dscp_dscp 14 to 14
config dscp map all dscp_dscp 15 to 15
config dscp map all dscp_dscp 16 to 16
config dscp map all dscp_dscp 17 to 17
config dscp map all dscp_dscp 18 to 18
config dscp map all dscp_dscp 19 to 19
config dscp map all dscp_dscp 20 to 20
config dscp map all dscp_dscp 21 to 21
config dscp map all dscp_dscp 22 to 22
config dscp map all dscp_dscp 23 to 23
config dscp map all dscp_dscp 24 to 24
config dscp map all dscp_dscp 25 to 25
config dscp map all dscp_dscp 26 to 26
config dscp map all dscp_dscp 27 to 27
config dscp map all dscp_dscp 28 to 28
config dscp map all dscp_dscp 29 to 29
config dscp map all dscp_dscp 30 to 30
config dscp map all dscp_dscp 31 to 31
config dscp map all dscp_dscp 32 to 32
config dscp map all dscp_dscp 33 to 33
config dscp map all dscp_dscp 34 to 34
config dscp map all dscp_dscp 35 to 35
config dscp map all dscp_dscp 36 to 36
config dscp map all dscp_dscp 37 to 37
config dscp map all dscp_dscp 38 to 38
config dscp map all dscp_dscp 39 to 39
config dscp map all dscp_dscp 40 to 40
config dscp map all dscp_dscp 41 to 41
config dscp map all dscp_dscp 42 to 42
config dscp map all dscp_dscp 43 to 43
config dscp map all dscp_dscp 44 to 44
config dscp map all dscp_dscp 45 to 45
config dscp map all dscp_dscp 46 to 46
config dscp map all dscp_dscp 47 to 47
config dscp map all dscp_dscp 48 to 48
config dscp map all dscp_dscp 49 to 49
config dscp map all dscp_dscp 50 to 50
config dscp map all dscp_dscp 51 to 51
config dscp map all dscp_dscp 52 to 52
config dscp map all dscp_dscp 53 to 53
config dscp map all dscp_dscp 54 to 54
config dscp map all dscp_dscp 55 to 55
config dscp map all dscp_dscp 56 to 56
config dscp map all dscp_dscp 57 to 57
config dscp map all dscp_dscp 58 to 58
config dscp map all dscp_dscp 59 to 59
config dscp map all dscp_dscp 60 to 60
config dscp map all dscp_dscp 61 to 61
config dscp map all dscp_dscp 62 to 62
config dscp map all dscp_dscp 63 to 63
config dscp map all dscp_priority 0-7 to 0
config dscp map all dscp_priority 8-15 to 1
config dscp map all dscp_priority 16-23 to 2
config dscp map all dscp_priority 24-31 to 3
config dscp map all dscp_priority 32-39 to 4
config dscp map all dscp_priority 40-47 to 5
config dscp map all dscp_priority 48-55 to 6
config dscp map all dscp_priority 56-63 to 7
# ARPSpoofingPrevention
# WRED
config wred profile default tcp green min_threshold 50 max_threshold 100 max_drop_rate 50
config wred profile default tcp yellow min_threshold 50 max_threshold 100 max_drop_rate 50
config wred profile default tcp red min_threshold 50 max_threshold 100 max_drop_rate 50
config wred profile default non_tcp green min_threshold 50 max_threshold 100 max_drop_rate 50
config wred profile default non_tcp yellow min_threshold 50 max_threshold 100 max_drop_rate 50
config wred profile default non_tcp red min_threshold 50 max_threshold 100 max_drop_rate 50
disable wred
config wred ports 1-26 cos 0 profile default
config wred ports 1-26 cos 0 weight 9
config wred ports 1-26 cos 1 profile default
config wred ports 1-26 cos 1 weight 9
config wred ports 1-26 cos 2 profile default
config wred ports 1-26 cos 2 weight 9
config wred ports 1-26 cos 3 profile default
config wred ports 1-26 cos 3 weight 9
config wred ports 1-26 cos 4 profile default
config wred ports 1-26 cos 4 weight 9
config wred ports 1-26 cos 5 profile default
config wred ports 1-26 cos 5 weight 9
config wred ports 1-26 cos 6 profile default
config wred ports 1-26 cos 6 weight 9
config wred ports 1-26 cos 7 profile default
config wred ports 1-26 cos 7 weight 9
# MAC_ADDRESS_TABLE_NOTIFICATION
disable mac_notification
config mac_notification interval 1 historysize 50
config mac_notification trap_type without_vlanid
config mac_notification ports 1-26 disable
# STP
config stp version rstp
config stp maxage 20 maxhops 20 forwarddelay 15 txholdcount 6 fbpdu disable hellotime 2 nni_bpdu_addr dot1ad
config stp priority 28672 instance_id 0
config stp ports 1-4,6-11,14,16-18 externalCost auto edge false p2p true state enable restricted_role false restricted_tcn false
config stp mst_ports 1-26 instance_id 0 internalCost auto priority 128
config stp ports 1-4,6-11,14,16-18 fbpdu enable
config stp ports 1-26 loop_guard false
config stp ports 5,12,15,19-20 externalCost auto edge false p2p true state disable restricted_role false restricted_tcn false
config stp ports 5,12-13,15,19-26 fbpdu disable
config stp ports 13,21-22,25-26 externalCost auto edge false p2p auto state disable restricted_role false restricted_tcn false
config stp ports 23-24 externalCost auto edge false p2p auto state enable restricted_role false restricted_tcn false
config stp mst_config_id name B8:A3:86:EE:A4:00 revision_level 0
config stp trap new_root enable
config stp trap topo_change enable
enable stp
disable stp multiprocess_rstp
# L2PT
disable l2protocol_tunnel
config l2protocol_tunnel ports all type none
# BPDU_PROTECTION
config bpdu_protection ports 21-22 state enable
config bpdu_protection ports 21-22 mode drop
config bpdu_protection ports 1-20,23-26 mode shutdown
# SAFEGUARD_ENGINE
config safeguard_engine state disable utilization rising 30 falling 20 trap_log disable mode fuzzy
# CPUPROTECT
disable cpu_protect
# TELNETS
enable telnet 23
# BCPING
enable broadcast_ping_reply
# MULTICAST_FILTER
# LACP
config link_aggregation algorithm mac_source
config lacp_port 1-26 mode passive
# IP
config ipif_mac_mapping ipif System mac_offset 0
config ipif System ipaddress 10.0.1.82/23 vlan VLAN2
config ipif System ipv6 state disable
config ipif System dhcpv6_client disable
config ipif System dhcpv6_client_pd disable
config ipif System proxy_arp disable local disable
config ipif_mac_mapping ipif mgmt_brest mac_offset 1
create ipif mgmt_brest 192.168.51.1/24 VLAN251 state enable
config ipif mgmt_brest proxy_arp disable local disable
config ipif mgmt_brest ipv6 state disable
config ipif mgmt_brest dhcpv6_client disable
config ipif mgmt_brest dhcpv6_client_pd disable
config ipif System ip_mtu 1500
config ipif mgmt_brest ip_mtu 1500
config ipif System ip_directed_broadcast disable
config ipif mgmt_brest ip_directed_broadcast disable
config ipif System dhcp_option12 state disable
disable autoconfig
# ERPS
create erps ring ring_71
config erps ring ring_71 ring_port west 12
config erps ring ring_71 ring_port east 13
config erps ring ring_71 ring_id 1
config erps ring ring_71 add instance 1
config erps instance 1 raps_vlan 71
config erps instance 1 timer wtr_time 1
config erps instance 1 protected_vlan add vlanid 251
config erps instance 1 protected_vlan add vlanid 351
config erps instance 1 protected_vlan add vlanid 785
create erps ring ring_72
config erps ring ring_72 ring_port west 5
config erps ring ring_72 ring_port east 19
config erps ring ring_72 ring_id 2
config erps ring ring_72 add instance 2
config erps instance 2 raps_vlan 72
config erps instance 2 timer wtr_time 1
config erps instance 2 protected_vlan add vlanid 251
config erps instance 2 protected_vlan add vlanid 351
config erps instance 2 protected_vlan add vlanid 781
config erps instance 2 protected_vlan add vlanid 785
config erps instance 1 state enable
config erps instance 2 state enable
config erps log enable
config erps version g.8032v1
enable erps
# IGMP_PROXY
config igmp_proxy upstream_if vlan vlanid 1
config igmp_proxy upstream_if source_ip 0.0.0.0
config igmp_proxy upstream_if unsolicited_report_interval 10
# MLD_PROXY
config mld_proxy upstream_if vlan vlanid 1
config mld_proxy upstream_if source_ip ::
config mld_proxy upstream_if unsolicited_report_interval 10
# UDP_HELPER
disable udp_helper
# WAC
disable wac
config wac authentication_page element login_window_title Authentication Login
config wac authentication_page element user_name_title User Name
config wac authentication_page element password_title Password
config wac authentication_page element logout_window_title Logout From The Network
config wac ports 1-26 aging_time 1440 idle_time infinite block_time 60
# LLDP
disable lldp
# TELNETC
# TFTPC
# MAC-based_Access_Control
disable mac_based_access_control
# MCFILTER
config multicast vlan_filtering_mode vlanid 1-2 filter_unregistered_groups
config multicast vlan_filtering_mode vlanid 251 filter_unregistered_groups
config multicast vlan_filtering_mode vlanid 351 filter_unregistered_groups
config multicast vlan_filtering_mode vlanid 781 filter_unregistered_groups
config multicast vlan_filtering_mode vlanid 785 filter_unregistered_groups
# COMPOUND_AUTHENTICATION
config authentication ports 1-26 auth_mode host_based
config authentication ports 1-26 multi_authen_methods none
enable authorization attributes
config authentication server failover block
config authentication mac_format case uppercase
config authentication mac_format delimiter none
config authentication mac_format delimiter number 5
# LLDP-MED
config lldp_med fast_start repeat_count 4
config lldp_med log state disable
config lldp_med notification topo_change ports 1 state disable
config lldp_med notification topo_change ports 2 state disable
config lldp_med notification topo_change ports 3 state disable
config lldp_med notification topo_change ports 4 state disable
config lldp_med notification topo_change ports 5 state disable
config lldp_med notification topo_change ports 6 state disable
config lldp_med notification topo_change ports 7 state disable
config lldp_med notification topo_change ports 8 state disable
config lldp_med notification topo_change ports 9 state disable
config lldp_med notification topo_change ports 10 state disable
config lldp_med notification topo_change ports 11 state disable
config lldp_med notification topo_change ports 12 state disable
config lldp_med notification topo_change ports 13 state disable
config lldp_med notification topo_change ports 14 state disable
config lldp_med notification topo_change ports 15 state disable
config lldp_med notification topo_change ports 16 state disable
config lldp_med notification topo_change ports 17 state disable
config lldp_med notification topo_change ports 18 state disable
config lldp_med notification topo_change ports 19 state disable
config lldp_med notification topo_change ports 20 state disable
config lldp_med notification topo_change ports 21 state disable
config lldp_med notification topo_change ports 22 state disable
config lldp_med notification topo_change ports 23 state disable
config lldp_med notification topo_change ports 24 state disable
config lldp_med notification topo_change ports 25 state disable
config lldp_med notification topo_change ports 26 state disable
# IGMP_SNOOPING
config igmp_snooping data_driven_learning max_learned_entry 120
# MLDSNP
config mld_snooping data_driven_learning max_learned_entry 120
# ACCESS_AUTHENTICATION_CONTROL
# DHCP_LOCAL_RELAY
disable dhcp_local_relay
# PTP
disable ptp
# DHCP_RELAY
disable dhcp_relay
# RIPng
disable ripng
# ARP
config arp_aging time 20
config gratuitous_arp send ipif_status_up disable
config gratuitous_arp send dup_ip_detected disable
config gratuitous_arp learning disable
# DNSR
disable dnsr
# VRRP
disable vrrp
disable vrrp ping
# PROUTE
# ROUTE
config route preference static 60
config route preference rip 100
config route preference default 1
create iproute default 10.0.0.1 1 primary
create iproute 192.168.51.0/255.255.255.0 10.0.0.1 1 primary
create route redistribute dst rip src static metric 0
create route redistribute dst rip src local metric 0
# RIP
enable rip
config rip timers update 30 timeout 180 garbage_collection 120
config rip ipif System authentication enable password tx_mode v2_only state enable
config rip ipif System authentication enable password rx_mode v2_only state enable
config rip ipif mgmt_brest authentication enable password tx_mode v2_only state disable
config rip ipif mgmt_brest authentication enable password rx_mode v2_only state disable
# DHCP_SERVER
disable dhcp class
disable dhcp_server
# RELAY6
config dhcpv6_relay hop_count 4
disable dhcpv6_relay