=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2025.05.
06 15:30:24 =~=~=~=~=~=~=~=~=~=~=~=
<KLCICCDCOTT00918WR01>sy
<KLCICCDCOTT00918WR01>system-view
System View: return to User View with Ctrl+Z.
[KLCICCDCOTT00918WR01]disp
[KLCICCDCOTT00918WR01]display cu
[KLCICCDCOTT00918WR01]display current-configuration
#
version 5.20.106, Release 2311, Standard
#
sysname KLCICCDCOTT00918WR01
#
clock timezone IST add 05:30:00
#
firewall enable
#
domain default enable isp
#
telnet server enable
#
dar p2p signature-file cfa0:/p2p_default.mtd
#
port-security enable
#
undo ip http enable
#
acl number 2101 name IMC
rule 0 permit source [Link] [Link]
#
acl number 3101 name IPSEC
rule 0 deny ip source [Link] [Link] destination [Link] [Link]
rule 1 deny ip source [Link] [Link] destination [Link] 0
rule 5 deny ip source [Link] [Link] destination [Link] [Link]
rule 10 permit ip source [Link] [Link] destination [Link] [Link]
acl number 3103 name LAN-PERMIT
rule 5 deny ip source [Link] [Link] destination [Link] [Link]
rule 10 permit ip source [Link] [Link]
rule 15 deny ip
#
vlan 1
#
radius scheme radius
server-type extended
primary authentication [Link]
primary accounting [Link]
secondary authentication [Link]
secondary accounting [Link]
key authentication cipher $c$3$OThEOkPE4WCh9QE/Pf/ytyfzDvAXwgmoPQ==
key accounting cipher $c$3$xRpk2/Mm/Br3R3kzDV64Xi8mlIl+JaULnA==
user-name-format without-domain
nas-ip [Link]
#
domain isp
---- More ---- authentication login radius-scheme radius local
authorization login radius-scheme radius local
accounting login radius-scheme radius local
access-limit disable
state active
idle-cut disable
self-service-url disable
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
ike proposal 1
encryption-algorithm 3des-cbc
authentication-algorithm md5
#
ike peer dop-concentrator
proposal 1
pre-shared-key cipher $c$3$O1qK5i0jxljpiq8d+4L44gwUsVgTBqIJmOKcAdzDaw==
remote-address [Link]
local-address [Link]
#
---- More ---- ipsec transform-set dop-security
encapsulation-mode tunnel
transform esp
esp encryption-algorithm 3des
#
ipsec policy dopipsec 1 isakmp
ike-peer dop-concentrator
transform-set dop-security
#
user-group system
group-attribute allow-guest
#
local-user admin
password cipher $c$3$IGFrr8UUTQQFJ9lCG9FYO1d1YbtPck8w
authorization-attribute level 3
service-type telnet
local-user conadmin
password cipher $c$3$p5Ap2yNFxBOt+uqNrO0F3UGFsVY/mo3nGtexDw==
authorization-attribute level 3
service-type ssh telnet
service-type web
local-user dopkerala
password cipher $c$3$qUcKq2iUkR0WBf6XcPAX/ZvtW1ao9I6HQKGJlRN/
---- More ---- authorization-attribute level 3
service-type ssh telnet
service-type web
#
cwmp
undo cwmp enable
#
interface Aux0
async mode flow
link-protocol ppp
#
interface Cellular0/0
async mode protocol
link-protocol ppp
#
interface NULL0
#
interface LoopBack0
description MANAGEMENT-INTERFACE
ip address [Link] [Link]
#
interface LoopBack1
description CRYPTO-INTERFACE
---- More ---- ip address [Link] [Link]
#
interface GigabitEthernet0/0
port link-mode route
description BSNL-WAN-INTERFACE
duplex full
speed 100
ip address [Link] [Link]
#
interface GigabitEthernet0/1
port link-mode route
description LAN_Interface
duplex full
speed 100
ip address [Link] [Link]
tcp mss 1350
#
bgp 65000
router-id [Link]
preference 50 50 50
import-route direct
undo synchronization
peer [Link] as-number 9829
---- More ---- peer [Link] description BSNL peering
peer [Link] route-policy Prefix-Out export
peer [Link] route-policy Pry-Prefix-In import
peer [Link] password cipher $c$3$tbA/haCh6IpqPJNrr6hkLTqq0e+C/AjrV0LG1niOi6+m/VY=
#
route-policy Prefix-Out permit node 10
if-match ip-prefix Loopback
route-policy Pry-Prefix-In permit node 10
if-match ip-prefix Default
apply local-preference 700
route-policy Pry-Prefix-In permit node 20
if-match ip-prefix dc-lan-prefix
apply local-preference 700
route-policy Pry-Prefix-In permit node 30
if-match ip-prefix dr-lan-prefix
apply local-preference 700
route-policy Scy-Prefix-In permit node 10
if-match ip-prefix Default
apply local-preference 600
route-policy Scy-Prefix-In permit node 20
if-match ip-prefix dc-lan-prefix
apply local-preference 600
route-policy Scy-Prefix-In permit node 30
---- More ---- if-match ip-prefix dr-lan-prefix
apply local-preference 600
#
#
voice-setup
#
sip
#
sip-server
#
call-rule-set
#
call-route
#
dial-program
default entity fax protocol standard-t38
default entity fax protocol standard-t38 hb-redundancy 0
default entity fax protocol standard-t38 lb-redundancy 0
#
aaa-client
#
ip ip-prefix Default index 10 permit [Link] 0
ip ip-prefix dr-lan-prefix index 10 permit [Link] 13
---- More ---- ip ip-prefix dc-lan-prefix index 10 permit [Link] 13
ip ip-prefix Loopback index 10 permit [Link] 32
ip ip-prefix Loopback index 15 permit [Link] 32
ip ip-prefix Loopback index 20 permit [Link] 28
ip ip-prefix Loopback index 25 permit [Link] 29
#
snmp-agent
snmp-agent local-engineid 800063A203CC3E5FDA5524
snmp-agent community write Wrd3P9yt5B acl 2101
snmp-agent community read mmtd0P2v43 acl 2101
snmp-agent sys-info contact 04662001371
snmp-agent sys-info location WEG28419
snmp-agent sys-info version v2c v3
snmp-agent group v3 dop write-view Wrd3P9yt5B acl 2101
snmp-agent target-host trap address udp-domain [Link] params securityname 3vrSud0P01rPa31 v3 privacy
snmp-agent target-host trap address udp-domain [Link] params securityname 3vrSud0P01rPa31 v3 privacy
snmp-agent usm-user v3 3vrSud0P01rPa31 dop cipher authentication-mode md5 $c$3$q9PXtlbPL1E/Fhd8di+k77uFgcQoyibSL
undo snmp-agent trap enable voice dial
snmp-agent trap source LoopBack0
#
header shell %
+--------------------------------------------------------------------------------------------+
This system is for the use of authorized users only.
---- More ---- Individuals using this system without authority or in excess of their
authority are subject to having all of the activities on this system
monitored and recorded by system personnel.
In the course of monitoring individuals improperly using system, or in the
course of system maintenance, the activities of authorized users may also be
monitored.
Anyone using this system expressly consents to such monitoring and is
advised if such monitoring reveals possible evidence of criminal activity,
system personnel may provide the evidence to law enforcement officials
+--------------------------------------------------------------------------------------------+%
#
ntp-service authentication enable
ntp-service authentication-keyid 42 authentication-mode md5 cipher $c$3$pcg8iitqwgSnKJU741NaTtw5NHZtJk9eiA==
ntp-service reliable authentication-keyid 42
ntp-service unicast-server [Link]
ntp-service unicast-server [Link]
#
ssh server enable
#
load xml-configuration
#
load tr069-configuration
#
---- More ---- user-interface con 0
user-interface tty 13
user-interface aux 0
user-interface vty 0 4
authentication-mode scheme
#
return
[KLCICCDCOTT00918WR01]
[KLCICCDCOTT00918WR01]
[KLCICCDCOTT00918WR01]
[KLCICCDCOTT00918WR01]
[KLCICCDCOTT00918WR01]
[KLCICCDCOTT00918WR01]
[KLCICCDCOTT00918WR01]
Pa31 v3 privacy
Pa31 v3 privacy
E/Fhd8di+k77uFgcQoyibSLGFYwO/PLf7UEw== privacy-mode des56 $c$3$LryML0m/yTkXScrASsK8A/jsznrzVMSmEGEthD3PCfZzqA== acl 21
Ttw5NHZtJk9eiA==
MSmEGEthD3PCfZzqA== acl 2101
I$=ZWH5YaK/&38_L+\.K$A!!
+------------------------------------------------------------------------------- +
This system is for the use of authorized users only.
Individuals using this system without authority or in excess of their
authority are subject to having all of the activities on this system
monitored and recorded by system personnel.
In the course of monitoring individuals improperly using system, or in the
course of system maintenance, the activities of authorized users may also be
monitored.
Anyone using this system expressly consents to such monitoring and is
advised if such monitoring reveals possible evidence of criminal activity,
system personnel may provide the evidence to law enforcement officials
+------------------------------------------------------------------------------- +
<KLCICPGHAMB00424WR01>sy
<KLCICPGHAMB00424WR01>system-view
System View: return to User View with Ctrl+Z.
[KLCICPGHAMB00424WR01]displ
[KLCICPGHAMB00424WR01]display cu
[KLCICPGHAMB00424WR01]display current-configuration
#
version 5.20.106, Release 2315, Standard
#
sysname KLCICPGHAMB00424WR01
#
clock timezone IST add 05:30:00
#
ip local policy-based-route internet-failover
#
firewall enable
#
domain default enable isp
#
telnet server enable
#
dar p2p signature-file cfa0:/p2p_default.mtd
#
port-security enable
#
undo ip http enable
#
password-recovery enable
#
acl number 2101 name IMC
rule 0 permit source [Link] [Link]
rule 10 permit source [Link] [Link]
#
acl number 3101 name IPSEC
rule 0 deny ip source [Link] [Link] destination [Link] [Link]
rule 1 deny ip source [Link] [Link] destination [Link] 0
rule 5 deny ip source [Link] [Link] destination [Link] [Link]
rule 10 permit ip source [Link] [Link] destination [Link] [Link]
acl number 3102 name DONGLE
rule 1 permit ip source [Link] 0 destination [Link] [Link]
rule 2 permit ip source [Link] 0 destination [Link] [Link]
rule 3 permit ip source [Link] 0 destination [Link] [Link]
rule 4 permit ip source [Link] 0 destination [Link] [Link]
rule 5 permit ip source [Link] 0 destination [Link] 0
rule 6 permit ip source [Link] 0 destination [Link] [Link]
rule 7 permit ip source [Link] 0 destination [Link] [Link]
rule 10 deny ip
acl number 3103 name LAN-PERMIT
rule 3 permit icmp source [Link] [Link] destination [Link] 0
rule 5 deny ip source [Link] [Link] destination [Link] [Link]
rule 10 permit ip source [Link] [Link]
rule 15 deny ip
acl number 3106 name IPSEC-DR
rule 10 deny ip source [Link] [Link] destination [Link] [Link]
rule 20 deny ip source [Link] [Link] destination [Link] 0
rule 30 deny ip source [Link] [Link] destination [Link] [Link]
rule 40 permit ip source [Link] [Link] destination [Link] [Link]
acl number 3107 name INTERNET-FAILOVER
rule 10 deny ip destination [Link] [Link]
rule 20 deny ip destination [Link] [Link]
rule 30 permit ip
acl number 3110 name MGMT-ACCESS
rule 10 permit ip source [Link] [Link]
rule 20 permit ip source [Link] [Link]
rule 30 permit ip source [Link] [Link]
rule 40 permit ip source [Link] [Link]
rule 50 permit ip source [Link] [Link]
rule 60 deny ip
#
vlan 1
#
radius scheme radius
server-type extended
primary authentication [Link]
primary accounting [Link]
secondary authentication [Link]
secondary authentication [Link]
secondary accounting [Link]
secondary accounting [Link]
key authentication cipher $c$3$FkjlfcW6ks3Nny0QriGE0RAQ7Rv7qphzJQ==
key accounting cipher $c$3$yIQpruxbxQ63hqEjbDRvhsTTY72Pim1FKw==
user-name-format without-domain
nas-ip [Link]
#
domain isp
authentication login radius-scheme radius local
authorization login radius-scheme radius local
accounting login radius-scheme radius local
access-limit disable
state active
idle-cut disable
self-service-url disable
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
ike proposal 1
encryption-algorithm 3des-cbc
authentication-algorithm md5
#
ike peer dop-concentrator
proposal 1
pre-shared-key cipher $c$3$9XCSCbnwqjB2OrVzD9RCmgmptRcziN07C35HVb8u2g==
remote-address [Link]
local-address [Link]
#
ike peer dop-concentrator-dr
proposal 1
pre-shared-key cipher $c$3$dlC+g4Y+3jKXXQujJc0JY071VyRIjWi47yaitwWrZQ==
remote-address [Link]
local-address [Link]
#
ipsec transform-set dop-security
encapsulation-mode tunnel
transform esp
esp authentication-algorithm md5
esp encryption-algorithm 3des
#
ipsec policy dopipsec 1 isakmp
security acl 3101
ike-peer dop-concentrator
transform-set dop-security
#
ipsec policy dopipsec 2 isakmp
security acl 3106
ike-peer dop-concentrator-dr
transform-set dop-security
#
policy-based-route internet-failover permit node 10
if-match acl 3107
#
user-group system
group-attribute allow-guest
#
local-user admin
password cipher $c$3$40gC1cxf/wIJNa1ufFPJsjKAof+QP5aV
authorization-attribute level 3
service-type telnet
local-user conadmin
password cipher $c$3$ysrE6/QWOG56i+NJMaN3BQmcI25sFcA7XLQGeg==
authorization-attribute level 3
service-type ssh telnet
service-type web
local-user dopnoc
password cipher $c$3$ydGbX2YSkdXP5p5jbSCIAd/k3S+ymtpFoKZzZLA2ug==
authorization-attribute level 3
service-type ssh telnet
service-type web
#
cwmp
undo cwmp enable
#
interface Aux0
async mode flow
link-protocol ppp
#
interface Cellular0/0
async mode protocol
link-protocol ppp
#
interface Dialer1
link-protocol ppp
ppp chap user id4912910059@[Link]
ppp chap password cipher $c$3$GdeHk3XZusCYR88jaSZCW+a2l7jpG0Yw+g+4
ip address ppp-negotiate
dialer user id4912910059@[Link]
dialer-group 1
dialer bundle 1
#
interface Ethernet0/0
port link-mode route
description SIFY-WAN
ip address [Link] [Link]
ip address [Link] [Link] sub
tcp mss 1300
#
interface Ethernet0/1
port link-mode route
description BSNL-WAN-INTERFACE
pppoe-client dial-bundle-number 1
duplex full
speed 100
#
interface NULL0
#
interface LoopBack0
description Management Interface
ip address [Link] [Link]
#
interface LoopBack1
description Crypto Interface.
ip address [Link] [Link]
#
interface Tunnel1
description Primary Tunnel
ip address [Link] [Link]
source [Link]
destination [Link]
keepalive 15 3
standby interface Tunnel2
#
interface Tunnel2
description Secondary Tunnel
ip address [Link] [Link]
source [Link]
destination [Link]
#
interface Tunnel3
description DR Primary Tunnel
ip address [Link] [Link]
source [Link]
destination [Link]
keepalive 15 3
standby interface Tunnel4
#
interface Tunnel4
description DR Secondary Tunnel
ip address [Link] [Link]
source [Link]
destination [Link]
#
nqa entry dopdc dcvpn
type icmp-echo
data-size 20
destination ip [Link]
frequency 5000
next-hop [Link]
reaction 1 checked-element probe-fail threshold-type consecutive 2 action-type trigger-only
#
nqa entry dopdr drvpn
type icmp-echo
data-size 20
destination ip [Link]
frequency 5000
next-hop [Link]
reaction 2 checked-element probe-fail threshold-type consecutive 2 action-type trigger-only
#
nqa entry internet failover
type icmp-echo
data-size 20
destination ip [Link]
frequency 30000
reaction 3 checked-element probe-fail threshold-type consecutive 2 action-type trigger-only
#
nqa entry nms1 pmms
type icmp-echo
data-size 20
destination ip [Link]
frequency 5000
source ip [Link]
#
nqa entry nms2 pmms
type icmp-echo
data-size 20
destination ip [Link]
frequency 5000
source ip [Link]
#
nqa entry nms3 pmms
type icmp-echo
data-size 20
destination ip [Link]
frequency 5000
source ip [Link]
#
nqa entry nms4 pmms
type icmp-echo
data-size 20
destination ip [Link]
frequency 5000
source ip [Link]
#
ip route-static [Link] [Link] Tunnel1 preference 30 description Primary Tunne l
ip route-static [Link] [Link] Tunnel2 description Backup Tunnel
ip route-static [Link] [Link] Tunnel3 preference 90 description DR Primary Tunnel
ip route-static [Link] [Link] Tunnel4 preference 120 description DR Backup Tunnel
ip route-static [Link] [Link] Tunnel1 preference 30 description DC Primary Tunnel
ip route-static [Link] [Link] Tunnel2 description DC Backup Tunnel
ip route-static [Link] [Link] [Link] track 1 preference 30 description Primary WAN
ip route-static [Link] [Link] [Link] description Secondary WAN
ip route-static [Link] [Link] Tunnel3 preference 30 description DR Primary Tunnel
ip route-static [Link] [Link] Tunnel4 description DR Backup Tunnel
ip route-static [Link] [Link] [Link] track 2 preference 30 description DR Primary WAN
ip route-static [Link] [Link] [Link] description DR Secondary WAN
ip route-static [Link] [Link] NULL0 description Track Failover
#
undo info-center source default channel 0
undo info-center source default channel 1
info-center loghost source LoopBack0
info-center loghost [Link]
info-center loghost [Link] facility local6
info-center loghost [Link] facility local6
#
snmp-agent
snmp-agent local-engineid 800063A20378485931B712
snmp-agent community write Wrd3P9yt5B acl 2101
snmp-agent community read mmtd0P2v43 acl 2101
snmp-agent sys-info contact <Customer Contact Number>
snmp-agent sys-info location WEG04861
snmp-agent sys-info version v2c v3
snmp-agent group v3 dop write-view Wrd3P9yt5B acl 2101
snmp-agent target-host trap address udp-domain [Link] params securityname 3vrSud0P01rPa31 v3 privacy
snmp-agent target-host trap address udp-domain [Link] params securityname 3vrSud0P01rPa31 v3 privacy
snmp-agent target-host trap address udp-domain [Link] params securityname 3vrSud0P01rPa31 v3 privacy
undo snmp-agent trap enable voice dial
snmp-agent trap source LoopBack0
#
track 1 nqa entry dopdc dcvpn reaction 1
track 2 nqa entry dopdr drvpn reaction 2
track 3 nqa entry internet failover reaction 3
#
header shell %
+-------------------------------------------------------------------------------+
This system is for the use of authorized users only.
Individuals using this system without authority or in excess of their
authority are subject to having all of the activities on this system
monitored and recorded by system personnel.
In the course of monitoring individuals improperly using system, or in the
course of system maintenance, the activities of authorized users may also be
monitored.
Anyone using this system expressly consents to such monitoring and is
advised if such monitoring reveals possible evidence of criminal activity,
system personnel may provide the evidence to law enforcement officials
+-------------------------------------------------------------------------------+%
#
nqa schedule nms2 pmms start-time now lifetime forever
nqa schedule nms3 pmms start-time now lifetime forever
nqa schedule nms4 pmms start-time now lifetime forever
nqa schedule dopdc dcvpn start-time now lifetime forever
nqa schedule dopdr drvpn start-time now lifetime forever
nqa schedule internet failover start-time now lifetime forever
#
ntp-service authentication enable
ntp-service source-interface LoopBack0
ntp-service authentication-keyid 42 authentication-mode md5 cipher $c$3$yXkRKmqqBh7aHqKAnNZOM37dRVFWuNe8Ww=
ntp-service reliable authentication-keyid 42
ntp-service unicast-server [Link] priority
ntp-service unicast-server [Link] priority
ntp-service unicast-server [Link]
ntp-service unicast-server [Link]
#
ssh server enable
#
dialer-rule 1 ip permit
#
load xml-configuration
#
load tr069-configuration
#
user-interface con 0
user-interface tty 13
modem both
user-interface aux 0
user-interface vty 0 4
acl 3110 inbound
authentication-mode scheme
idle-timeout 5 0
#
return
[KLCICPGHAMB00424WR01]
[KLCICPGHAMB00424WR01]
[KLCICPGHAMB00424WR01]
[KLCICPGHAMB00424WR01]
[KLCICPGHAMB00424WR01]
+
+
Primary WAN
DR Primary WAN
d0P01rPa31 v3 privacy
d0P01rPa31 v3 privacy
d0P01rPa31 v3 privacy
HqKAnNZOM37dRVFWuNe8Ww==