Foundet
set firewall all-ping ‘enable’
set firewall broadcast-ping ‘disable’
set firewall config-trap ‘disable’
set interfaces ethernet eth0 address ‘xxx.xxx.100.100/24’
set interfaces ethernet eth0 description ‘Local Connect’
set interfaces ethernet eth0 hw-id ‘b8:ac:6f:14:c2:16’
set interfaces ethernet eth1 address ‘xxx.xxx.56.187/29’
set interfaces ethernet eth1 description ‘ISP1’
set interfaces ethernet eth1 hw-id ‘b8:ac:6f:14:c2:18’
set interfaces ethernet eth2 hw-id ‘b8:ac:6f:14:c2:1a’
set interfaces ethernet eth3 hw-id ‘b8:ac:6f:14:c2:1c’
set interfaces ethernet eth3 vif 2138 address ‘xxx.xxx.2.98/30’
set interfaces ethernet eth3 vif 2138 description ‘ISP2-1’
set interfaces ethernet eth3 vif 2139 address ‘xxx.xxx.2.102/30’
set interfaces ethernet eth3 vif 2139 description ‘ISP2-2’
set interfaces ethernet eth4 disable
set interfaces ethernet eth4 duplex ‘full’
set interfaces ethernet eth4 hw-id ‘28:92:4a:af:31:b0’
set interfaces ethernet eth4 mtu ‘9000’
set interfaces ethernet eth4 speed ‘10000’
set interfaces ethernet eth5 address ‘xxx.xxx.176.1/23’
set interfaces ethernet eth5 address ‘xxx.xxx.88.1/24’
set interfaces ethernet eth5 address ‘xxx.xxx.24.1/23’
set interfaces ethernet eth5 address ‘xxx.xxx.182.1/24’
set interfaces ethernet eth5 address ‘xxx.xxx.177.1/24’
set interfaces ethernet eth5 address ‘xxx.xxx.25.1/24’
set interfaces ethernet eth5 address ‘xxx.xxx.181.1/24’
set interfaces ethernet eth5 description ‘10GB Port > Switch’
set interfaces ethernet eth5 disable-flow-control
set interfaces ethernet eth5 duplex ‘full’
set interfaces ethernet eth5 hw-id ‘28:92:4a:af:31:b4’
set interfaces ethernet eth5 speed ‘10000’
set interfaces ethernet eth5 vif 2200 address ‘xxx.xxx.24.249/30’
set interfaces loopback lo
Ower IPv4
set policy prefix-list IPv4-ISP2-OUT rule 100 action ‘permit’
set policy prefix-list IPv4-ISP2-OUT rule 100 description ‘AS33XXX’
set policy prefix-list IPv4-ISP2-OUT rule 100 prefix ‘xxx.xxx.181.0/24’
set policy prefix-list IPv4-ISP2-OUT rule 105 action ‘permit’
set policy prefix-list IPv4-ISP2-OUT rule 105 description ‘AS33XXX’
set policy prefix-list IPv4-ISP2-OUT rule 105 prefix ‘xxx.xxx.176.0/23’
set policy prefix-list IPv4-ISP2-OUT rule 106 action ‘permit’
set policy prefix-list IPv4-ISP2-OUT rule 106 description ‘AS33XXX’
set policy prefix-list IPv4-ISP2-OUT rule 106 prefix ‘xxx.xxx.88.0/24’
set policy prefix-list IPv4-ISP2-OUT rule 140 action ‘permit’
set policy prefix-list IPv4-ISP2-OUT rule 140 description ‘AS33XXX’
set policy prefix-list IPv4-ISP2-OUT rule 140 prefix ‘xxx.xxx.24.0/23’
set policy prefix-list IPv4-ISP2-OUT rule 150 action ‘permit’
set policy prefix-list IPv4-ISP2-OUT rule 150 description ‘AS33XXX’
set policy prefix-list IPv4-ISP2-OUT rule 150 prefix ‘xxx.xxx.182.0/24’
DownStreamer IPv4
set policy prefix-list IPv4-ISP2-OUT rule 170 action ‘permit’
set policy prefix-list IPv4-ISP2-OUT rule 170 description ‘HC - ASXXX’
set policy prefix-list IPv4-ISP2-OUT rule 170 prefix ‘xxx.xxx.26.0/24’
set policy prefix-list IPv4-ISP2-OUT rule 180 action ‘permit’
set policy prefix-list IPv4-ISP2-OUT rule 180 description ‘HC - ASXXX’
set policy prefix-list IPv4-ISP2-OUT rule 180 prefix ‘xxx.xxx.104.0/24’
set policy prefix-list IPv4-ISP2-OUT rule 190 action ‘permit’
set policy prefix-list IPv4-ISP2-OUT rule 190 description ‘HC - ASXXX’
set policy prefix-list IPv4-ISP2-OUT rule 190 prefix ‘xxx.xxx.105.0/24’
set policy prefix-list IPv4-HC-OUT rule 100 action ‘permit’
set policy prefix-list IPv4-HC-OUT rule 100 prefix ‘xxx.xxx.0.0/0’
Ower IPv4
set policy prefix-list IPv4-ISP1-OUT rule 100 action ‘permit’
set policy prefix-list IPv4-ISP1-OUT rule 100 description ‘AS33XXX’
set policy prefix-list IPv4-ISP1-OUT rule 100 prefix ‘xxx.xxx.181.0/24’
set policy prefix-list IPv4-ISP1-OUT rule 105 action ‘permit’
set policy prefix-list IPv4-ISP1-OUT rule 105 description ‘AS33XXX’
set policy prefix-list IPv4-ISP1-OUT rule 105 prefix ‘xxx.xxx.176.0/23’
set policy prefix-list IPv4-ISP1-OUT rule 140 action ‘permit’
set policy prefix-list IPv4-ISP1-OUT rule 140 description ‘AS33XXX’
set policy prefix-list IPv4-ISP1-OUT rule 140 prefix ‘xxx.xxx.24.0/23’
set policy prefix-list IPv4-ISP1-OUT rule 150 action ‘permit’
set policy prefix-list IPv4-ISP1-OUT rule 150 description ‘AS33XXX’
set policy prefix-list IPv4-ISP1-OUT rule 150 prefix ‘xxx.xxx.182.0/24’
set policy prefix-list IPv4-ISP1-OUT rule 160 action ‘permit’
set policy prefix-list IPv4-ISP1-OUT rule 160 description ‘AS33XXX’
set policy prefix-list IPv4-ISP1-OUT rule 160 prefix ‘xxx.xxx.88.0/24’
DownStreamer IPv4
set policy prefix-list IPv4-ISP1-OUT rule 170 action ‘permit’
set policy prefix-list IPv4-ISP1-OUT rule 170 description ‘HC - ASXXX’
set policy prefix-list IPv4-ISP1-OUT rule 170 prefix ‘xxx.xxx.26.0/24’
set policy prefix-list IPv4-ISP1-OUT rule 180 action ‘permit’
set policy prefix-list IPv4-ISP1-OUT rule 180 description ‘HC - ASXXX’
set policy prefix-list IPv4-ISP1-OUT rule 180 prefix ‘xxx.xxx.104.0/24’
set policy prefix-list IPv4-ISP1-OUT rule 190 action ‘permit’
set policy prefix-list IPv4-ISP1-OUT rule 190 description ‘HC - ASXXX’
set policy prefix-list IPv4-ISP1-OUT rule 190 prefix ‘xxx.xxx.105.0/24’
set policy route-map EXPORT
set policy route-map IPv4-NET-ISP2 rule 100 action ‘permit’
set policy route-map IPv4-NET-ISP2 rule 100 match ip address prefix-list ‘IPv4-ISP2-OUT’
set policy route-map IPv4-NET-ISP2 rule 105 action ‘permit’
set policy route-map IPv4-NET-ISP2 rule 105 match ip address prefix-list ‘IPv4-ISP2-OUT’
set policy route-map IPv4-NET-ISP2 rule 106 action ‘permit’
set policy route-map IPv4-NET-ISP2 rule 106 match ip address prefix-list ‘IPv4-ISP2-OUT’
set policy route-map IPv4-NET-ISP2 rule 140 action ‘permit’
set policy route-map IPv4-NET-ISP2 rule 140 match ip address prefix-list ‘IPv4-ISP2-OUT’
set policy route-map IPv4-NET-ISP2 rule 150 action ‘permit’
set policy route-map IPv4-NET-ISP2 rule 150 match ip address prefix-list ‘IPv4-ISP2-OUT’
set policy route-map IPv4-NET-ISP2 rule 170 action ‘permit’
set policy route-map IPv4-NET-ISP2 rule 170 match ip address prefix-list ‘IPv4-ISP2-OUT’
set policy route-map IPv4-NET-ISP2 rule 180 action ‘permit’
set policy route-map IPv4-NET-ISP2 rule 180 match ip address prefix-list ‘IPv4-ISP2-OUT’
set policy route-map IPv4-NET-ISP2 rule 190 action ‘permit’
set policy route-map IPv4-NET-ISP2 rule 190 match ip address prefix-list ‘IPv4-ISP2-OUT’
set policy route-map IPv4-NET-HC rule 100 action ‘permit’
set policy route-map IPv4-NET-HC rule 100 match ip address prefix-list ‘IPv4-HC-OUT’
set policy route-map IPv4-NET-ISP1 rule 100 action ‘permit’
set policy route-map IPv4-NET-ISP1 rule 100 match ip address prefix-list ‘IPv4-ISP1-OUT’
set policy route-map IPv4-NET-ISP1 rule 105 action ‘permit’
set policy route-map IPv4-NET-ISP1 rule 105 match ip address prefix-list ‘IPv4-ISP1-OUT’
set policy route-map IPv4-NET-ISP1 rule 106 action ‘permit’
set policy route-map IPv4-NET-ISP1 rule 106 match ip address prefix-list ‘IPv4-ISP1-OUT’
set policy route-map IPv4-NET-ISP1 rule 140 action ‘permit’
set policy route-map IPv4-NET-ISP1 rule 140 match ip address prefix-list ‘IPv4-ISP1-OUT’
set policy route-map IPv4-NET-ISP1 rule 150 action ‘permit’
set policy route-map IPv4-NET-ISP1 rule 150 match ip address prefix-list ‘IPv4-ISP1-OUT’
set policy route-map IPv4-NET-ISP1 rule 170 action ‘permit’
set policy route-map IPv4-NET-ISP1 rule 170 match ip address prefix-list ‘IPv4-ISP1-OUT’
set policy route-map IPv4-NET-ISP1 rule 180 action ‘permit’
set policy route-map IPv4-NET-ISP1 rule 180 match ip address prefix-list ‘IPv4-ISP1-OUT’
set policy route-map IPv4-NET-ISP1 rule 190 action ‘permit’
set policy route-map IPv4-NET-ISP1 rule 190 match ip address prefix-list ‘IPv4-ISP1-OUT’
set protocols bgp address-family ipv4-unicast network xxx.xxx.181.0/24
set protocols bgp address-family ipv4-unicast network xxx.xxx.24.0/23
set protocols bgp address-family ipv4-unicast network xxx.xxx.176.0/23
set protocols bgp address-family ipv4-unicast network xxx.xxx.182.0/24
set protocols bgp address-family ipv4-unicast network xxx.xxx.88.0/24
set protocols bgp local-as ‘339XX’
ISP1
set protocols bgp neighbor xxx.xxx.56.185 address-family ipv4-unicast route-map export ‘IPv4-NET-ISP1’
set protocols bgp neighbor xxx.xxx.56.185 address-family ipv4-unicast soft-reconfiguration inbound
set protocols bgp neighbor xxx.xxx.56.185 address-family ipv4-unicast weight ‘200’
set protocols bgp neighbor xxx.xxx.56.185 description ‘ISP1 National AS Neighbor’
set protocols bgp neighbor xxx.xxx.56.185 remote-as ‘87XX’
set protocols bgp neighbor xxx.xxx.56.185 update-source ‘xxx.xxx.56.187’
set protocols bgp neighbor xxx.xxx.56.186 address-family ipv4-unicast route-map export ‘IPv4-NET-ISP1’
set protocols bgp neighbor xxx.xxx.56.186 address-family ipv4-unicast soft-reconfiguration inbound
set protocols bgp neighbor xxx.xxx.56.186 address-family ipv4-unicast weight ‘200’
set protocols bgp neighbor xxx.xxx.56.186 description ‘ISP1 National AS Neighbor - Back-UP’
set protocols bgp neighbor xxx.xxx.56.186 remote-as ‘87XX’
set protocols bgp neighbor xxx.xxx.56.186 update-source ‘xxx.xxx.56.187’
set protocols bgp neighbor xxx.xxx.184.233 address-family ipv4-unicast route-map export ‘IPv4-NET-ISP1’
set protocols bgp neighbor xxx.xxx.184.233 address-family ipv4-unicast soft-reconfiguration inbound
set protocols bgp neighbor xxx.xxx.184.233 address-family ipv4-unicast weight ‘100’
set protocols bgp neighbor xxx.xxx.184.233 description ‘ISP1 International AS Neighbor’
set protocols bgp neighbor xxx.xxx.184.233 ebgp-multihop ‘255’
set protocols bgp neighbor xxx.xxx.184.233 remote-as ‘87XX’
set protocols bgp neighbor xxx.xxx.184.233 update-source ‘xxx.xxx.56.187’
US with Customer (Downstreamer)
set protocols bgp neighbor xxx.xxx.24.250 address-family ipv4-unicast route-map export ‘IPv4-NET-HC’
set protocols bgp neighbor xxx.xxx.24.250 address-family ipv4-unicast soft-reconfiguration
set protocols bgp neighbor xxx.xxx.24.250 address-family ipv4-unicast weight ‘200’
set protocols bgp neighbor xxx.xxx.24.250 description ‘US > HC’
set protocols bgp neighbor xxx.xxx.24.250 ebgp-multihop ‘2’
set protocols bgp neighbor xxx.xxx.24.250 remote-as ‘576XX’
set protocols bgp neighbor xxx.xxx.24.250 update-source ‘xxx.xxx.24.249’
ISP2
set protocols bgp neighbor xxx.xxx.2.97 address-family ipv4-unicast route-map export ‘IPv4-NET-ISP2’
set protocols bgp neighbor xxx.xxx.2.97 address-family ipv4-unicast soft-reconfiguration inbound
set protocols bgp neighbor xxx.xxx.2.97 address-family ipv4-unicast weight ‘200’
set protocols bgp neighbor xxx.xxx.2.97 description ‘ISP2 1’
set protocols bgp neighbor xxx.xxx.2.97 remote-as ‘66XX’
set protocols bgp neighbor xxx.xxx.2.97 update-source ‘xxx.xxx.2.98’
set protocols bgp neighbor xxx.xxx.2.101 address-family ipv4-unicast route-map export ‘IPv4-NET-ISP2’
set protocols bgp neighbor xxx.xxx.2.101 address-family ipv4-unicast soft-reconfiguration inbound
set protocols bgp neighbor xxx.xxx.2.101 address-family ipv4-unicast weight ‘200’
set protocols bgp neighbor xxx.xxx.2.101 description ‘ISP2 2’
set protocols bgp neighbor xxx.xxx.2.101 remote-as ‘66XX’
set protocols bgp neighbor xxx.xxx.2.101 update-source ‘xxx.xxx.2.102’
set protocols bgp neighbor xxx.xxx.200.12 address-family ipv4-unicast route-map export ‘IPv4-NET-ISP2’
set protocols bgp neighbor xxx.xxx.200.12 address-family ipv4-unicast soft-reconfiguration inbound
set protocols bgp neighbor xxx.xxx.200.12 address-family ipv4-unicast weight ‘100’
set protocols bgp neighbor xxx.xxx.200.12 description ‘ISP2 International’
set protocols bgp neighbor xxx.xxx.200.12 ebgp-multihop ‘255’
set protocols bgp neighbor xxx.xxx.200.12 remote-as ‘66XX’
set protocols bgp neighbor xxx.xxx.200.12 update-source ‘xxx.xxx.2.98’
set protocols bgp parameters log-neighbor-changes
set protocols ospf area 0 network ‘xxx.xxx.176.0/23’
set protocols ospf area 0 network ‘xxx.xxx.181.0/24’
set protocols ospf area 0 network ‘xxx.xxx.88.0/24’
set protocols ospf area 0 network ‘xxx.xxx.24.0/23’
set protocols ospf area 0 network ‘xxx.xxx.182.0/24’
set protocols ospf area xxx.xxx.0.0 area-type normal
set protocols ospf default-information originate always
set protocols ospf default-information originate metric ‘10’
set protocols ospf default-information originate metric-type ‘2’
set protocols ospf parameters abr-type ‘cisco’
set protocols static route xxx.xxx.181.0/24 blackhole distance ‘254’
set protocols static route xxx.xxx.24.0/23 blackhole distance ‘254’
set protocols static route xxx.xxx.176.0/23 blackhole distance ‘254’
set protocols static route xxx.xxx.182.0/24 blackhole distance ‘254’
set protocols static route xxx.xxx.88.0/24 blackhole distance ‘254’
set protocols static route xxx.xxx.200.12/32 next-hop xxx.xxx.2.97
set service ids ddos-protection alert-script ‘/usr/local/bin/notify_script.bash’
set service ids ddos-protection direction ‘in’
set service ids ddos-protection listen-interface ‘eth1’
set service ids ddos-protection listen-interface ‘eth3.2138’
set service ids ddos-protection listen-interface ‘eth3.2139’
set service ids ddos-protection mode mirror
set service ids ddos-protection network ‘xxx.xxx.176.0/23’
set service ids ddos-protection network ‘xxx.xxx.181.0/24’
set service ids ddos-protection network ‘xxx.xxx.24.0/23’
set service ids ddos-protection network ‘xxx.xxx.88.0/24’
set service ids ddos-protection network ‘xxx.xxx.182.0/24’
set service ids ddos-protection network ‘xxx.xxx.26.0/24’
set service ids ddos-protection network ‘xxx.xxx.104.0/24’
set service ids ddos-protection network ‘xxx.xxx.105.0/24’
set service ids ddos-protection threshold fps ‘3500’
set service ids ddos-protection threshold mbps ‘350’
set service ids ddos-protection threshold pps ‘25000’
set system config-management commit-revisions ‘100’
set system console device ttyS0 speed ‘115200’
set system flow-accounting interface ‘eth1’
set system flow-accounting interface ‘eth3.2138’
set system flow-accounting interface ‘eth3.2139’
set system ntp server 0.pool.ntp.org
set system ntp server 1.pool.ntp.org
set system ntp server 2.pool.ntp.org
set system syslog global facility all level ‘info’
set system syslog global facility protocols level ‘debug’