ISP1-22 — FULL CONFIG

en
conf t
!
hostname ISP1-22
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 exit
!
enable secret cisco
service password-encryption
!
interface e1/1
 description LINK-TO-ISP2-23
 duplex full
 ip address 200.1.222.1 255.255.255.252
 ip nat inside
 no shutdown
!
interface e1/0
 description LINK-TO-RT-EDGE-SILVER-21-10
 duplex full
 ip address 200.21.102.22 255.255.255.0
 ip nat inside
 no shutdown
!
interface e1/3
 description LINK-TO-RT-EDGE-BRONZE-31-16
 duplex full
 ip address 200.31.162.22 255.255.255.0
 ip nat inside
 no shutdown
!
interface e1/4
 description LINK-TO-RT-EDGE-DC-89-20
 duplex full
 ip address 200.89.202.22 255.255.255.0
 ip nat inside
 no shutdown
!
interface e1/5
 description LINK-TO-RT-EDGE-GOLD-11-01
 duplex full
 ip address 200.11.122.22 255.255.255.0
 ip nat inside
 no shutdown
!
router bgp 65000
 bgp log-neighbor-changes
 !
 neighbor 200.1.222.2 remote-as 65000
 neighbor 200.1.222.2 description iBGP-ISP2-23
 !
 neighbor 200.11.122.1 remote-as 1000
 neighbor 200.11.122.1 description GOLD-AS1000
 !
 neighbor 200.21.102.10 remote-as 2000
 neighbor 200.21.102.10 description SILVER-AS2000
 !
 neighbor 200.31.162.16 remote-as 3000
 neighbor 200.31.162.16 description BRONZE-AS3000
 !
 neighbor 200.89.202.20 remote-as 80000
 neighbor 200.89.202.20 description DC-AS80000
 neighbor 200.89.202.20 ttl-security hops 1
 !
 address-family ipv4
  neighbor 200.1.222.2 activate
  neighbor 200.1.222.2 next-hop-self
  !
  neighbor 200.11.122.1 activate
  neighbor 200.11.122.1 route-map RM-FROM-GOLD-01 in
  !
  neighbor 200.21.102.10 activate
  neighbor 200.21.102.10 route-map RM-FROM-SILVER-ISP1 in
  !
  neighbor 200.31.162.16 activate
  neighbor 200.31.162.16 route-map RM-FROM-BRONZE-ISP1 in
  !
  neighbor 200.89.202.20 activate
  neighbor 200.89.202.20 route-map RM-FROM-DC-ISP1 in
 exit-address-family
!
! GOLD
ip community-list standard CL-PRIMARY permit 100:200
ip community-list standard CL-SECONDARY permit 100:100
ip community-list standard CL-GUEST permit 100:300
!
! SILVER
ip community-list standard CL-SILVER-PRIMARY permit 200:200
ip community-list standard CL-SILVER-SECONDARY permit 200:100
!
! BRONZE
ip community-list standard CL-BRONZE-PRIMARY permit 300:200
ip community-list standard CL-BRONZE-SECONDARY permit 300:100
!
! DATACENTER
ip community-list standard CL-DC-PRIMARY permit 800:200
ip community-list standard CL-DC-SECONDARY permit 800:100
!
route-map RM-FROM-GOLD-01 permit 5
 match community CL-GUEST
 set local-preference 300
!
route-map RM-FROM-GOLD-01 permit 10
 match community CL-PRIMARY
 set local-preference 200
!
route-map RM-FROM-GOLD-01 permit 20
 match community CL-SECONDARY
 set local-preference 100
!
route-map RM-FROM-GOLD-01 permit 100
!
route-map RM-FROM-SILVER-ISP1 permit 10
 match community CL-SILVER-PRIMARY
 set local-preference 200
!
route-map RM-FROM-SILVER-ISP1 permit 20
 match community CL-SILVER-SECONDARY
 set local-preference 100
!
route-map RM-FROM-SILVER-ISP1 permit 100
!
route-map RM-FROM-BRONZE-ISP1 permit 10
 match community CL-BRONZE-PRIMARY
 set local-preference 200
!
route-map RM-FROM-BRONZE-ISP1 permit 20
 match community CL-BRONZE-SECONDARY
 set local-preference 100
!
route-map RM-FROM-BRONZE-ISP1 permit 100
!
route-map RM-FROM-DC-ISP1 permit 10
 match community CL-DC-PRIMARY
 set local-preference 200
!
route-map RM-FROM-DC-ISP1 permit 20
 match community CL-DC-SECONDARY
 set local-preference 100
!
route-map RM-FROM-DC-ISP1 permit 100
 set local-preference 200
!
end
wr mem

############################################################################################################################################################################

ISP2-23 — FULL CONFIG

en
conf t
!
hostname ISP2-23
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 exit
!
enable secret cisco
service password-encryption
!
interface e1/2
 description LINK-TO-ISP1-22
 duplex full
 ip address 200.1.222.2 255.255.255.252
 ip nat inside
 no shutdown
!
interface e1/0
 description LINK-TO-RT-EDGE-SILVER-21-11
 duplex full
 ip address 200.21.112.23 255.255.255.0
 ip nat inside
 no shutdown
!
interface e1/3
 description LINK-TO-RT-EDGE-BRONZE-31-16
 duplex full
 ip address 200.31.163.23 255.255.255.0
 ip nat inside
 no shutdown
!
interface e1/4
 description LINK-TO-RT-EDGE-DC-89-21
 duplex full
 ip address 200.89.212.23 255.255.255.0
 ip nat inside
 no shutdown
!
interface e1/5
 description LINK-TO-RT-EDGE-GOLD-11-02
 duplex full
 ip address 200.11.223.23 255.255.255.0
 ip nat inside
 no shutdown
!
interface e1/6
 description LINK-TO-PC-200.1.232.24
 duplex full
 ip address 200.1.232.23 255.255.255.0
 ip nat inside
 no shutdown
!
interface e1/1
 description INTERNET-OUTSIDE
 ip address 192.168.255.100 255.255.255.0
 ip nat outside
 no shutdown
!
ip access-list standard NAT-SITES
 deny 10.11.99.0 0.0.0.255
 deny 10.21.99.0 0.0.0.255
 deny 10.31.99.0 0.0.0.255
 deny 10.89.99.0 0.0.0.255
 permit any
!
ip nat inside source list NAT-SITES interface e1/1 overload
!
ip route 0.0.0.0 0.0.0.0 192.168.255.1
!
router bgp 65000
 bgp log-neighbor-changes
 !
 neighbor 200.1.222.1 remote-as 65000
 neighbor 200.1.222.1 description iBGP-ISP1-22
 !
 neighbor 200.11.223.2 remote-as 1000
 neighbor 200.11.223.2 description GOLD-AS1000
 !
 neighbor 200.21.112.11 remote-as 2000
 neighbor 200.21.112.11 description SILVER-AS2000
 !
 neighbor 200.31.163.16 remote-as 3000
 neighbor 200.31.163.16 description BRONZE-AS3000
 !
 neighbor 200.89.212.21 remote-as 80000
 neighbor 200.89.212.21 description DC-AS80000
 neighbor 200.89.212.21 ttl-security hops 1
 !
 address-family ipv4
  neighbor 200.1.222.1 activate
  neighbor 200.1.222.1 next-hop-self
  neighbor 200.1.222.1 route-map RM-NO-GUEST-OUT out
  !
  neighbor 200.11.223.2 activate
  neighbor 200.11.223.2 route-map RM-FROM-GOLD-02 in
  neighbor 200.11.223.2 route-map RM-NO-GUEST-OUT out
  !
  neighbor 200.21.112.11 activate
  neighbor 200.21.112.11 route-map RM-FROM-SILVER-ISP2 in
  neighbor 200.21.112.11 route-map RM-NO-GUEST-OUT out
  !
  neighbor 200.31.163.16 activate
  neighbor 200.31.163.16 route-map RM-FROM-BRONZE-ISP2 in
  neighbor 200.31.163.16 route-map RM-NO-GUEST-OUT out
  !
  neighbor 200.89.212.21 activate
  neighbor 200.89.212.21 route-map RM-FROM-DC-ISP2 in
  neighbor 200.89.212.21 route-map RM-NO-GUEST-OUT out
  !
  network 0.0.0.0
 exit-address-family
!
! GOLD
ip community-list standard CL-PRIMARY permit 100:200
ip community-list standard CL-SECONDARY permit 100:100
ip community-list standard CL-GUEST permit 100:300
!
! SILVER
ip community-list standard CL-SILVER-PRIMARY permit 200:200
ip community-list standard CL-SILVER-SECONDARY permit 200:100
!
! BRONZE
ip community-list standard CL-BRONZE-PRIMARY permit 300:200
ip community-list standard CL-BRONZE-SECONDARY permit 300:100
!
! DATACENTER
ip community-list standard CL-DC-PRIMARY permit 800:200
ip community-list standard CL-DC-SECONDARY permit 800:100
!
! BLOQUEIO DE PROPAGACAO - GUEST (VLAN 30 / 10.11.30.0/24)
ip prefix-list PL-BLOCK-GOLD-GUEST seq 5 permit 10.11.30.0/24
!
route-map RM-NO-GUEST-OUT deny 5
 match ip address prefix-list PL-BLOCK-GOLD-GUEST
!
route-map RM-NO-GUEST-OUT permit 100
!
route-map RM-FROM-GOLD-02 permit 5
 match community CL-GUEST
 set local-preference 300
!
route-map RM-FROM-GOLD-02 permit 10
 match community CL-PRIMARY
 set local-preference 200
!
route-map RM-FROM-GOLD-02 permit 20
 match community CL-SECONDARY
 set local-preference 100
!
route-map RM-FROM-GOLD-02 permit 100
!
route-map RM-FROM-SILVER-ISP2 permit 10
 match community CL-SILVER-PRIMARY
 set local-preference 200
!
route-map RM-FROM-SILVER-ISP2 permit 20
 match community CL-SILVER-SECONDARY
 set local-preference 100
!
route-map RM-FROM-SILVER-ISP2 permit 100
!
route-map RM-FROM-BRONZE-ISP2 permit 10
 match community CL-BRONZE-PRIMARY
 set local-preference 200
!
route-map RM-FROM-BRONZE-ISP2 permit 20
 match community CL-BRONZE-SECONDARY
 set local-preference 100
!
route-map RM-FROM-BRONZE-ISP2 permit 100
!
route-map RM-FROM-DC-ISP2 permit 10
 match community CL-DC-PRIMARY
 set local-preference 100
!
route-map RM-FROM-DC-ISP2 permit 20
 match community CL-DC-SECONDARY
 set local-preference 100
!
route-map RM-FROM-DC-ISP2 permit 100
 set local-preference 100
!
end
wr mem

############################################################################################################################################################################

RT-EDGE-BRONZE-31-16 — FULL CONFIG

en
conf t
!
hostname RT-EDGE-BRONZE-31-16
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 exit
!
enable secret cisco
service password-encryption
!
interface e1/0
 description TRUNK-TO-ACCESS
 duplex full
 no shutdown
!
interface e1/0.10
 encapsulation dot1q 10
 description VLAN10-VENDAS
 ip address 10.31.10.1 255.255.255.0
!
interface e1/0.20
 encapsulation dot1q 20
 description VLAN20-FINANCEIRO
 ip address 10.31.20.1 255.255.255.0
!
interface e1/0.99
 encapsulation dot1q 99
 description VLAN99-GERENCIA
 ip address 10.31.99.16 255.255.255.0
!
interface e1/2
 description LINK-TO-ISP1-22
 duplex full
 ip address 200.31.162.16 255.255.255.0
 no shutdown
!
interface e1/3
 description LINK-TO-ISP2-23
 duplex full
 ip address 200.31.163.16 255.255.255.0
 no shutdown
!
ip dhcp pool VLAN10
 network 10.31.10.0 255.255.255.0
 default-router 10.31.10.1
!
ip dhcp pool VLAN20
 network 10.31.20.0 255.255.255.0
 default-router 10.31.20.1
!
router bgp 3000
 bgp log-neighbor-changes
 !
 neighbor 200.31.162.22 remote-as 65000
 neighbor 200.31.162.22 description ISP1-22
 !
 neighbor 200.31.163.23 remote-as 65000
 neighbor 200.31.163.23 description ISP2-23
 !
 address-family ipv4
  neighbor 200.31.162.22 activate
  neighbor 200.31.162.22 send-community
  neighbor 200.31.162.22 route-map RM-FROM-ISP1 in
  neighbor 200.31.162.22 route-map RM-TO-ISP1 out
  !
  neighbor 200.31.163.23 activate
  neighbor 200.31.163.23 send-community
  neighbor 200.31.163.23 route-map RM-FROM-ISP2 in
  neighbor 200.31.163.23 route-map RM-TO-ISP2 out
  !
  network 10.31.10.0 mask 255.255.255.0
  network 10.31.20.0 mask 255.255.255.0
  network 10.31.99.0 mask 255.255.255.0
 exit-address-family
!
route-map RM-FROM-ISP1 permit 10
 set local-preference 200
!
route-map RM-FROM-ISP2 permit 10
 set local-preference 100
!
route-map RM-TO-ISP1 permit 10
 set community 300:200 additive
!
route-map RM-TO-ISP2 permit 10
 set community 300:100 additive
!
end
wr mem

############################################################################################################################################################################

SW-ACCESS-BRONZE-31-17 — FULL CONFIG

en
conf t
!
hostname SW-ACCESS-BRONZE-31-17
!
no ip routing
!
vlan 10
 name VENDAS
!
vlan 20
 name FINANCEIRO
!
vlan 99
 name GERENCIA_INFRAESTRUTURA
!
interface vlan 99
 ip address 10.31.99.17 255.255.255.0
 no shutdown
!
ip default-gateway 10.31.99.16
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 exit
!
enable secret cisco
service password-encryption
!
interface e0/0
 description LINK-TO-RT-EDGE-BRONZE-31-16
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
interface e0/1
 description ACCESS-VLAN10
 switchport mode access
 switchport access vlan 10
 no shutdown
!
interface e0/3
 description ACCESS-VLAN20
 switchport mode access
 switchport access vlan 20
 no shutdown
!
end
wr mem

############################################################################################################################################################################

SW-ACCESS-SILVER-21-13 — FULL CONFIG

en
conf t
!
hostname SW-ACCESS-SILVER-21-13
!
no ip routing
!
vlan 10
 name VENDAS
!
vlan 20
 name FINANCEIRO
!
vlan 99
 name GERENCIA_INFRAESTRUTURA
!
interface vlan 99
 ip address 10.21.99.13 255.255.255.0
 no shutdown
!
ip default-gateway 10.21.99.12
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 exit
!
enable secret cisco
service password-encryption
!
interface range e0/0 - 1
 description LINK-TO-SW-MULTI-SILVER-21-12
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 channel-group 1 mode active
 no shutdown
!
interface port-channel1
 description PORTCHANNEL-TO-SW-MULTI-SILVER-21-12
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
interface e0/2
 description ACCESS-VLAN20
 switchport mode access
 switchport access vlan 20
 no shutdown
!
interface e0/3
 description ACCESS-VLAN10
 switchport mode access
 switchport access vlan 10
 no shutdown
!
end
wr mem

############################################################################################################################################################################

SW-MULTI-SILVER-21-12 — FULL CONFIG

en
conf t
!
hostname SW-MULTI-SILVER-21-12
!
vlan 10
 name VENDAS
!
vlan 20
 name FINANCEIRO
!
vlan 99
 name GERENCIA_INFRAESTRUTURA
!
ip routing
!
interface vlan 10
 ip address 10.21.10.1 255.255.255.0
 no shutdown
!
interface vlan 20
 ip address 10.21.20.1 255.255.255.0
 no shutdown
!
interface vlan 99
 ip address 10.21.99.12 255.255.255.0
 no shutdown
!
interface g0/0
 description LINK-TO-RT-EDGE-SILVER-21-10
 no switchport
 ip address 10.21.101.12 255.255.255.0
 no shutdown
!
interface g0/2
 description LINK-TO-RT-EDGE-SILVER-21-11
 no switchport
 ip address 10.21.111.12 255.255.255.0
 no shutdown
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 exit
!
enable secret cisco
service password-encryption
!
interface range g1/0 - 1
 description LINK-TO-SW-ACCESS-SILVER-21-13
 switchport trunk encapsulation dot1q
 switchport mode trunk
 channel-group 1 mode active
 no shutdown
!
interface port-channel1
 description PORTCHANNEL-TO-SW-ACCESS-SILVER-21-13
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
ip dhcp pool VLAN10
 network 10.21.10.0 255.255.255.0
 default-router 10.21.10.1
!
ip dhcp pool VLAN20
 network 10.21.20.0 255.255.255.0
 default-router 10.21.20.1
!
router ospf 1
 router-id 10.21.99.12
 passive-interface vlan 10
 passive-interface vlan 20
 passive-interface vlan 99
 network 10.21.10.1 0.0.0.0 area 0
 network 10.21.20.1 0.0.0.0 area 0
 network 10.21.99.12 0.0.0.0 area 0
 network 10.21.101.12 0.0.0.0 area 0
 network 10.21.111.12 0.0.0.0 area 0
!
end
wr mem

############################################################################################################################################################################

RT-EDGE-SILVER-21-10 — FULL CONFIG

en
conf t
!
hostname RT-EDGE-SILVER-21-10
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 transport input telnet
 exit
!
enable secret cisco
service password-encryption
!
interface e0/1
 description LINK-TO-SW-MULTI-SILVER-21-12
 duplex full
 ip address 10.21.101.10 255.255.255.0
 no shutdown
!
interface e1/2
 description LINK-TO-RT-EDGE-SILVER-21-11
 ip address 10.21.110.10 255.255.255.0
 no shutdown
!
interface loopback1
 description IBGP-SOURCE
 ip address 10.21.99.10 255.255.255.255
!
interface e0/0
 description LINK-TO-ISP1-22
 duplex full
 ip address 200.21.102.10 255.255.255.0
 no shutdown
!
router ospf 1
 router-id 10.21.99.10
 network 10.21.99.10 0.0.0.0 area 0
 network 10.21.101.10 0.0.0.0 area 0
 network 10.21.110.10 0.0.0.0 area 0
 !
 default-information originate metric 5 metric-type 1
 redistribute bgp 2000 subnets metric 5 metric-type 1
!
router bgp 2000
 bgp log-neighbor-changes
 !
 neighbor 200.21.102.22 remote-as 65000
 neighbor 200.21.102.22 description ISP1-22
 !
 neighbor 10.21.99.11 remote-as 2000
 neighbor 10.21.99.11 description iBGP-RT-EDGE-SILVER-21-11
 neighbor 10.21.99.11 update-source loopback1
 !
 address-family ipv4
  neighbor 200.21.102.22 activate
  neighbor 200.21.102.22 send-community
  neighbor 200.21.102.22 route-map RM-FROM-ISP1 in
  neighbor 200.21.102.22 route-map RM-TO-ISP1 out
  !
  neighbor 10.21.99.11 activate
  neighbor 10.21.99.11 next-hop-self
  !
  redistribute ospf 1 route-map RM-OSPF-TO-BGP
 exit-address-family
!
ip prefix-list PL-SILVER-ALL seq 5 permit 10.21.10.0/24
ip prefix-list PL-SILVER-ALL seq 10 permit 10.21.20.0/24
ip prefix-list PL-SILVER-ALL seq 15 permit 10.21.99.0/24
!
route-map RM-OSPF-TO-BGP permit 10
 match ip address prefix-list PL-SILVER-ALL
!
route-map RM-FROM-ISP1 permit 10
 set local-preference 200
!
route-map RM-TO-ISP1 permit 10
 set community 200:200 additive
!
end
wr mem

############################################################################################################################################################################

RT-EDGE-SILVER-21-11 — FULL CONFIG

en
conf t
!
hostname RT-EDGE-SILVER-21-11
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 transport input telnet
 exit
!
enable secret cisco
service password-encryption
!
interface e0/1
 description LINK-TO-SW-MULTI-SILVER-21-12
 duplex full
 ip address 10.21.111.11 255.255.255.0
 no shutdown
!
interface e1/2
 description LINK-TO-RT-EDGE-SILVER-21-10
 ip address 10.21.110.11 255.255.255.0
 no shutdown
!
interface loopback1
 description IBGP-SOURCE
 ip address 10.21.99.11 255.255.255.255
!
interface e0/0
 description LINK-TO-ISP2-23
 duplex full
 ip address 200.21.112.11 255.255.255.0
 no shutdown
!
router ospf 1
 router-id 10.21.99.11
 network 10.21.99.11 0.0.0.0 area 0
 network 10.21.111.11 0.0.0.0 area 0
 network 10.21.110.11 0.0.0.0 area 0
 !
 default-information originate metric 50 metric-type 1
 redistribute bgp 2000 subnets metric 50 metric-type 1
!
router bgp 2000
 bgp log-neighbor-changes
 !
 neighbor 200.21.112.23 remote-as 65000
 neighbor 200.21.112.23 description ISP2-23
 !
 neighbor 10.21.99.10 remote-as 2000
 neighbor 10.21.99.10 description iBGP-RT-EDGE-SILVER-21-10
 neighbor 10.21.99.10 update-source loopback1
 !
 address-family ipv4
  neighbor 200.21.112.23 activate
  neighbor 200.21.112.23 send-community
  neighbor 200.21.112.23 route-map RM-FROM-ISP2 in
  neighbor 200.21.112.23 route-map RM-TO-ISP2 out
  !
  neighbor 10.21.99.10 activate
  neighbor 10.21.99.10 next-hop-self
  !
  redistribute ospf 1 route-map RM-OSPF-TO-BGP
 exit-address-family
!
ip prefix-list PL-SILVER-ALL seq 5 permit 10.21.10.0/24
ip prefix-list PL-SILVER-ALL seq 10 permit 10.21.20.0/24
ip prefix-list PL-SILVER-ALL seq 15 permit 10.21.99.0/24
!
route-map RM-OSPF-TO-BGP permit 10
 match ip address prefix-list PL-SILVER-ALL
!
route-map RM-FROM-ISP2 permit 10
 set local-preference 100
!
route-map RM-TO-ISP2 permit 10
 set community 200:100 additive
!
end
wr mem

############################################################################################################################################################################

RT-EDGE-GOLD-11-01 — FULL CONFIG

en
conf t
!
hostname RT-EDGE-GOLD-11-01
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 exit
!
enable secret cisco
service password-encryption
!
interface e1/1
 description LINK-TO-RT-EDGE-GOLD-11-02
 ip address 10.11.12.1 255.255.255.0
 no shutdown
!
interface e1/2
 description LINK-TO-SW-MULTI-GOLD-11-03
 ip address 10.11.13.1 255.255.255.0
 no shutdown
!
interface e1/3
 description LINK-TO-SW-MULTI-GOLD-11-04
 ip address 10.11.14.1 255.255.255.0
 no shutdown
!
interface e1/4
 description LINK-TO-ISP1-22
 duplex full
 ip address 200.11.122.1 255.255.255.0
 no shutdown
!
interface loopback1
 ip address 10.11.99.1 255.255.255.255
!
router ospf 1
 router-id 10.11.99.1
 network 10.11.12.1 0.0.0.0 area 0
 network 10.11.13.1 0.0.0.0 area 0
 network 10.11.14.1 0.0.0.0 area 0
 network 10.11.99.1 0.0.0.0 area 0
 !
 default-information originate metric 5 metric-type 1
 redistribute bgp 1000 subnets metric 5 metric-type 1
!
router bgp 1000
 bgp log-neighbor-changes
 !
 neighbor 200.11.122.22 remote-as 65000
 neighbor 200.11.122.22 description ISP1-22
 !
 neighbor 10.11.12.2 remote-as 1000
 neighbor 10.11.12.2 description iBGP-RT-EDGE-GOLD-11-02
 !
 address-family ipv4
  neighbor 200.11.122.22 activate
  neighbor 200.11.122.22 send-community
  neighbor 200.11.122.22 route-map RM-FROM-ISP1 in
  neighbor 200.11.122.22 route-map RM-TO-ISP1 out
  !
  neighbor 10.11.12.2 activate
  neighbor 10.11.12.2 next-hop-self
  !
  redistribute ospf 1 route-map RM-OSPF-TO-BGP
 exit-address-family
!
ip prefix-list PL-GOLD-ALL seq 5 permit 10.11.10.0/24
ip prefix-list PL-GOLD-ALL seq 10 permit 10.11.20.0/24
ip prefix-list PL-GOLD-ALL seq 20 permit 10.11.99.0/24
!
ip prefix-list PL-GOLD-NO-GUEST seq 5 permit 10.11.10.0/24
ip prefix-list PL-GOLD-NO-GUEST seq 10 permit 10.11.20.0/24
ip prefix-list PL-GOLD-NO-GUEST seq 20 permit 10.11.99.0/24
!
ip prefix-list PL-GUEST seq 5 permit 10.11.30.0/24
!
route-map RM-OSPF-TO-BGP permit 10
 match ip address prefix-list PL-GOLD-ALL
!
route-map RM-FROM-ISP1 permit 10
 set local-preference 200
!
route-map RM-TO-ISP1 deny 5
 match ip address prefix-list PL-GUEST
!
route-map RM-TO-ISP1 permit 10
 match ip address prefix-list PL-GOLD-NO-GUEST
 set community 100:200 additive
!
end
wr mem

############################################################################################################################################################################

RT-EDGE-GOLD-11-02 — FULL CONFIG

en
conf t
!
hostname RT-EDGE-GOLD-11-02
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 exit
!
enable secret cisco
service password-encryption
!
interface e1/1
 description LINK-TO-RT-EDGE-GOLD-11-01
 ip address 10.11.12.2 255.255.255.0
 ip access-group ACL-BLOCK-GUEST-TO-EDGE01 out
 no shutdown
!
interface e1/0
 description LINK-TO-SW-MULTI-GOLD-11-03
 ip address 10.11.23.2 255.255.255.0
 ip policy route-map RM-GUEST-TO-ISP2
 no shutdown
!
interface e1/3
 description LINK-TO-SW-MULTI-GOLD-11-04
 ip address 10.11.24.2 255.255.255.0
 ip policy route-map RM-GUEST-TO-ISP2
 no shutdown
!
interface e1/4
 description LINK-TO-ISP2-23
 duplex full
 ip address 200.11.223.2 255.255.255.0
 no shutdown
!
interface loopback1
 ip address 10.11.99.2 255.255.255.255
!
ip access-list extended ACL-BLOCK-GUEST-TO-EDGE01
 deny ip 10.11.30.0 0.0.0.255 any
 permit ip any any
!
ip access-list extended ACL-GUEST-SOURCE
 permit ip 10.11.30.0 0.0.0.255 any
!
route-map RM-GUEST-TO-ISP2 permit 10
 match ip address ACL-GUEST-SOURCE
 set ip next-hop 200.11.223.23
!
router ospf 1
 router-id 10.11.99.2
 network 10.11.12.2 0.0.0.0 area 0
 network 10.11.23.2 0.0.0.0 area 0
 network 10.11.24.2 0.0.0.0 area 0
 network 10.11.99.2 0.0.0.0 area 0
 !
 default-information originate metric 50 metric-type 1
 redistribute bgp 1000 subnets metric 50 metric-type 1
!
router bgp 1000
 bgp log-neighbor-changes
 !
 neighbor 200.11.223.23 remote-as 65000
 neighbor 200.11.223.23 description ISP2-23
 !
 neighbor 10.11.12.1 remote-as 1000
 neighbor 10.11.12.1 description iBGP-RT-EDGE-GOLD-11-01
 !
 address-family ipv4
  neighbor 200.11.223.23 activate
  neighbor 200.11.223.23 send-community
  neighbor 200.11.223.23 route-map RM-FROM-ISP2 in
  neighbor 200.11.223.23 route-map RM-TO-ISP2 out
  !
  neighbor 10.11.12.1 activate
  neighbor 10.11.12.1 next-hop-self
  !
  redistribute ospf 1 route-map RM-OSPF-TO-BGP
 exit-address-family
!
ip prefix-list PL-GOLD-ALL seq 5 permit 10.11.10.0/24
ip prefix-list PL-GOLD-ALL seq 10 permit 10.11.20.0/24
ip prefix-list PL-GOLD-ALL seq 15 permit 10.11.30.0/24
ip prefix-list PL-GOLD-ALL seq 20 permit 10.11.99.0/24
!
ip prefix-list PL-GOLD-NORMAL seq 5 permit 10.11.10.0/24
ip prefix-list PL-GOLD-NORMAL seq 10 permit 10.11.20.0/24
ip prefix-list PL-GOLD-NORMAL seq 20 permit 10.11.99.0/24
!
ip prefix-list PL-GUEST seq 5 permit 10.11.30.0/24
!
route-map RM-OSPF-TO-BGP permit 10
 match ip address prefix-list PL-GOLD-ALL
!
route-map RM-FROM-ISP2 permit 10
 set local-preference 100
!
route-map RM-TO-ISP2 permit 5
 match ip address prefix-list PL-GUEST
 set community 100:300 additive
!
route-map RM-TO-ISP2 permit 10
 match ip address prefix-list PL-GOLD-NORMAL
 set community 100:100 additive
!
end
wr mem

############################################################################################################################################################################

SW-MULTI-GOLD-11-03 — FULL CONFIG

en
conf t
!
hostname SW-MULTI-GOLD-11-03
!
vlan 10
 name VENDAS
!
vlan 20
 name FINANCEIRO
!
vlan 30
 name CONVIDADOS
!
vlan 99
 name GERENCIA_INFRAESTRUTURA
!
ip routing
!
interface vlan 10
 ip address 10.11.10.3 255.255.255.0
 standby 10 ip 10.11.10.1
 standby 10 priority 110
 standby 10 preempt
 no shutdown
!
interface vlan 20
 ip address 10.11.20.3 255.255.255.0
 standby 20 ip 10.11.20.1
 standby 20 priority 110
 standby 20 preempt
 no shutdown
!
interface vlan 30
 ip address 10.11.30.3 255.255.255.0
 standby 30 ip 10.11.30.1
 standby 30 priority 110
 standby 30 preempt
 ip access-group ACL-GUEST-BLOCK-SITES in
 ip policy route-map RM-PBR-GUEST
 no shutdown
!
interface vlan 99
 ip address 10.11.99.3 255.255.255.0
 standby 99 ip 10.11.99.254
 standby 99 priority 110
 standby 99 preempt
 no shutdown
!
interface g0/0
 description LINK-TO-RT-EDGE-GOLD-11-01
 no switchport
 ip address 10.11.13.3 255.255.255.0
 no shutdown
!
interface g0/1
 description LINK-TO-RT-EDGE-GOLD-11-02
 no switchport
 ip address 10.11.23.3 255.255.255.0
 no shutdown
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 exit
!
spanning-tree mode rapid-pvst
spanning-tree vlan 10,20,30,99 root primary
!
enable secret cisco
service password-encryption
!
interface range g1/0 - 1
 channel-group 1 mode active
 no shutdown
!
interface port-channel1
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
interface range g1/2 - 3
 channel-group 2 mode active
 no shutdown
!
interface port-channel2
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
interface range g0/2 - 3
 channel-group 6 mode active
 no shutdown
!
interface port-channel6
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
ip dhcp excluded-address 10.11.10.1 10.11.10.10
ip dhcp excluded-address 10.11.20.1 10.11.20.10
ip dhcp excluded-address 10.11.30.1 10.11.30.10
!
ip dhcp pool VLAN10
 network 10.11.10.0 255.255.255.0
 default-router 10.11.10.1
!
ip dhcp pool VLAN20
 network 10.11.20.0 255.255.255.0
 default-router 10.11.20.1
!
ip dhcp pool VLAN30
 network 10.11.30.0 255.255.255.0
 default-router 10.11.30.1
!
ip access-list extended ACL-GUEST-BLOCK-SITES
 deny ip 10.11.30.0 0.0.0.255 10.89.0.0 0.0.255.255
 deny ip 10.11.30.0 0.0.0.255 10.21.0.0 0.0.255.255
 deny ip 10.11.30.0 0.0.0.255 10.31.0.0 0.0.255.255
 permit ip any any
!
ip access-list extended ACL-PBR-GUEST
 permit ip 10.11.30.0 0.0.0.255 any
!
route-map RM-PBR-GUEST permit 10
 match ip address ACL-PBR-GUEST
 set ip next-hop 10.11.23.2
!
router ospf 1
 router-id 10.11.99.3
 passive-interface vlan 10
 passive-interface vlan 20
 passive-interface vlan 30
 passive-interface vlan 99
 network 10.11.10.3 0.0.0.0 area 0
 network 10.11.20.3 0.0.0.0 area 0
 network 10.11.30.3 0.0.0.0 area 0
 network 10.11.99.3 0.0.0.0 area 0
 network 10.11.13.3 0.0.0.0 area 0
 network 10.11.23.3 0.0.0.0 area 0
!
end
wr mem

############################################################################################################################################################################

SW-MULTI-GOLD-11-04 — FULL CONFIG

en
conf t
!
hostname SW-MULTI-GOLD-11-04
!
vlan 10
 name VENDAS
!
vlan 20
 name FINANCEIRO
!
vlan 30
 name CONVIDADOS
!
vlan 99
 name GERENCIA_INFRAESTRUTURA
!
ip routing
!
interface vlan 10
 ip address 10.11.10.4 255.255.255.0
 standby 10 ip 10.11.10.1
 standby 10 priority 100
 standby 10 preempt
 no shutdown
!
interface vlan 20
 ip address 10.11.20.4 255.255.255.0
 standby 20 ip 10.11.20.1
 standby 20 priority 100
 standby 20 preempt
 no shutdown
!
interface vlan 30
 ip address 10.11.30.4 255.255.255.0
 standby 30 ip 10.11.30.1
 standby 30 priority 100
 standby 30 preempt
 ip access-group ACL-GUEST-BLOCK-SITES in
 ip policy route-map RM-PBR-GUEST
 no shutdown
!
interface vlan 99
 ip address 10.11.99.4 255.255.255.0
 standby 99 ip 10.11.99.254
 standby 99 priority 100
 standby 99 preempt
 no shutdown
!
interface g0/0
 description LINK-TO-RT-EDGE-GOLD-11-01
 no switchport
 ip address 10.11.14.4 255.255.255.0
 no shutdown
!
interface g0/1
 description LINK-TO-RT-EDGE-GOLD-11-02
 no switchport
 ip address 10.11.24.4 255.255.255.0
 no shutdown
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 exit
!
spanning-tree mode rapid-pvst
spanning-tree vlan 10,20,30,99 root secondary
!
enable secret cisco
service password-encryption
!
interface range g1/0 - 1
 channel-group 5 mode active
 no shutdown
!
interface port-channel5
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
interface range g1/2 - 3
 channel-group 3 mode active
 no shutdown
!
interface port-channel3
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
interface range g0/2 - 3
 channel-group 6 mode active
 no shutdown
!
interface port-channel6
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
ip dhcp excluded-address 10.11.10.1 10.11.10.10
ip dhcp excluded-address 10.11.20.1 10.11.20.10
ip dhcp excluded-address 10.11.30.1 10.11.30.10
!
ip dhcp pool VLAN10
 network 10.11.10.0 255.255.255.0
 default-router 10.11.10.1
!
ip dhcp pool VLAN20
 network 10.11.20.0 255.255.255.0
 default-router 10.11.20.1
!
ip dhcp pool VLAN30
 network 10.11.30.0 255.255.255.0
 default-router 10.11.30.1
!
ip access-list extended ACL-GUEST-BLOCK-SITES
 deny ip 10.11.30.0 0.0.0.255 10.89.0.0 0.0.255.255
 deny ip 10.11.30.0 0.0.0.255 10.21.0.0 0.0.255.255
 deny ip 10.11.30.0 0.0.0.255 10.31.0.0 0.0.255.255
 permit ip any any
!
ip access-list extended ACL-PBR-GUEST
 permit ip 10.11.30.0 0.0.0.255 any
!
route-map RM-PBR-GUEST permit 10
 match ip address ACL-PBR-GUEST
 set ip next-hop 10.11.24.2
!
router ospf 1
 router-id 10.11.99.4
 passive-interface vlan 10
 passive-interface vlan 20
 passive-interface vlan 30
 passive-interface vlan 99
 network 10.11.10.4 0.0.0.0 area 0
 network 10.11.20.4 0.0.0.0 area 0
 network 10.11.30.4 0.0.0.0 area 0
 network 10.11.99.4 0.0.0.0 area 0
 network 10.11.14.4 0.0.0.0 area 0
 network 10.11.24.4 0.0.0.0 area 0
!
end
wr mem

############################################################################################################################################################################

SW-ACCESS-GOLD-11-05 — FULL CONFIG

en
conf t
!
hostname SW-ACCESS-GOLD-11-05
!
no ip routing
!
vlan 10
 name VENDAS
!
vlan 20
 name FINANCEIRO
!
vlan 30
 name CONVIDADOS
!
vlan 99
 name GERENCIA_INFRAESTRUTURA
!
interface vlan 99
 ip address 10.11.99.5 255.255.255.0
 no shutdown
!
ip default-gateway 10.11.99.254
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 exit
!
enable secret cisco
service password-encryption
!
interface range e0/0 - 1
 description LINK-TO-SW-MULTI-GOLD-11-03
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 channel-group 1 mode active
 no shutdown
!
interface port-channel1
 description PORTCHANNEL-TO-SW-MULTI-GOLD-11-03
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
interface range e1/0 - 1
 description LINK-TO-SW-MULTI-GOLD-11-04
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 channel-group 3 mode active
 no shutdown
!
interface port-channel3
 description PORTCHANNEL-TO-SW-MULTI-GOLD-11-04
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
interface range e0/2 - 3
 description LINK-TO-SW-ACCESS-GOLD-11-06
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 channel-group 4 mode active
 no shutdown
!
interface port-channel4
 description PORTCHANNEL-TO-SW-ACCESS-GOLD-11-06
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
interface e1/2
 description ACCESS-VLAN10
 switchport mode access
 switchport access vlan 10
 no shutdown
!
interface e1/3
 description ACCESS-VLAN20
 switchport mode access
 switchport access vlan 20
 no shutdown
!
end
wr mem

############################################################################################################################################################################

SW-ACCESS-GOLD-11-06 — FULL CONFIG

en
conf t
!
hostname SW-ACCESS-GOLD-11-06
!
no ip routing
!
vlan 10
 name VENDAS
!
vlan 20
 name FINANCEIRO
!
vlan 30
 name CONVIDADOS
!
vlan 99
 name GERENCIA_INFRAESTRUTURA
!
interface vlan 99
 ip address 10.11.99.6 255.255.255.0
 no shutdown
!
ip default-gateway 10.11.99.254
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
line vty 0 4
 password cisco
 login
 exit
!
enable secret cisco
service password-encryption
!
interface range e0/0 - 1
 description LINK-TO-SW-MULTI-GOLD-11-04
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 channel-group 5 mode active
 no shutdown
!
interface port-channel5
 description PORTCHANNEL-TO-SW-MULTI-GOLD-11-04
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
interface range e1/0 - 1
 description LINK-TO-SW-MULTI-GOLD-11-03
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 channel-group 2 mode active
 no shutdown
!
interface port-channel2
 description PORTCHANNEL-TO-SW-MULTI-GOLD-11-03
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
interface range e0/2 - 3
 description LINK-TO-SW-ACCESS-GOLD-11-05
 duplex full
 switchport trunk encapsulation dot1q
 switchport mode trunk
 channel-group 4 mode active
 no shutdown
!
interface port-channel4
 description PORTCHANNEL-TO-SW-ACCESS-GOLD-11-05
 switchport trunk encapsulation dot1q
 switchport mode trunk
 no shutdown
!
interface e1/2
 description ACCESS-VLAN30
 switchport mode access
 switchport access vlan 30
 no shutdown
!
interface e1/3
 description ACCESS-VLAN99
 switchport mode access
 switchport access vlan 99
 no shutdown
!
end
wr mem

############################################################################################################################################################################

RT-EDGE-DC-89-20 — FULL CONFIG

en
conf t
!
hostname RT-EDGE-DC-89-20
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
enable secret cisco
service password-encryption
!
ip access-list standard ACL-MGMT-JUMPSERVER
 permit 10.11.99.10
 deny any
!
line vty 0 4
 password cisco
 login
 transport input telnet
 access-class ACL-MGMT-JUMPSERVER in
 logging synchronous
 exit
!
interface e1/0
 description LINK-TO-ISP1-22
 duplex full
 ip address 200.89.202.20 255.255.255.0
 no shutdown
!
interface e1/1
 description LINK-TO-RT-EDGE-DC-89-21
 ip address 10.89.255.20 255.255.255.0
 no shutdown
!
interface e1/2
 description DC-LAN
 ip address 10.89.200.1 255.255.255.0
 no shutdown
!
interface loopback1
 ip address 10.89.1.1 255.255.255.255
!
interface loopback2
 ip address 10.89.2.2 255.255.255.255
!
interface loopback3
 ip address 10.89.3.3 255.255.255.255
!
interface loopback4
 ip address 10.89.4.4 255.255.255.255
!
interface loopback5
 ip address 10.89.5.5 255.255.255.255
!
interface loopback99
 ip address 10.89.99.20 255.255.255.255
!
router bgp 80000
 bgp log-neighbor-changes
 !
 neighbor 200.89.202.22 remote-as 65000
 neighbor 200.89.202.22 description ISP1-22
 neighbor 200.89.202.22 ttl-security hops 1
 !
 neighbor 10.89.255.21 remote-as 80000
 neighbor 10.89.255.21 description iBGP-RT-EDGE-DC-89-21
 neighbor 10.89.255.21 ttl-security hops 1
 !
 address-family ipv4
  neighbor 200.89.202.22 activate
  neighbor 200.89.202.22 send-community
  neighbor 200.89.202.22 route-map RM-FROM-ISP1 in
  neighbor 200.89.202.22 route-map RM-TO-ISP1 out
  !
  neighbor 10.89.255.21 activate
  neighbor 10.89.255.21 next-hop-self
  !
  network 10.89.1.1 mask 255.255.255.255
  network 10.89.2.2 mask 255.255.255.255
  network 10.89.3.3 mask 255.255.255.255
  network 10.89.4.4 mask 255.255.255.255
  network 10.89.5.5 mask 255.255.255.255
  network 10.89.99.20 mask 255.255.255.255
  network 10.89.200.0 mask 255.255.255.0
 exit-address-family
!
ip prefix-list PL-DEFAULT seq 5 permit 0.0.0.0/0
!
route-map RM-FROM-ISP1 permit 10
 match ip address prefix-list PL-DEFAULT
 set local-preference 200
!
route-map RM-FROM-ISP1 permit 20
!
route-map RM-TO-ISP1 permit 10
 set community 800:200 additive
!
end
wr mem

############################################################################################################################################################################

RT-EDGE-DC-89-21 — FULL CONFIG

en
conf t
!
hostname RT-EDGE-DC-89-21
!
line console 0
 password cisco
 login
 logging synchronous
 exit
!
enable secret cisco
service password-encryption
!
ip access-list standard ACL-MGMT-JUMPSERVER
 permit 10.11.99.10
 deny any
!
line vty 0 4
 password cisco
 login
 transport input telnet
 access-class ACL-MGMT-JUMPSERVER in
 logging synchronous
 exit
!
interface e1/0
 description LINK-TO-ISP2-23
 duplex full
 ip address 200.89.212.21 255.255.255.0
 no shutdown
!
interface e1/1
 description LINK-TO-RT-EDGE-DC-89-20
 ip address 10.89.255.21 255.255.255.0
 no shutdown
!
interface loopback6
 ip address 10.89.6.6 255.255.255.255
!
interface loopback7
 ip address 10.89.7.7 255.255.255.255
!
interface loopback8
 ip address 10.89.8.8 255.255.255.255
!
interface loopback9
 ip address 10.89.9.9 255.255.255.255
!
interface loopback10
 ip address 10.89.10.10 255.255.255.255
!
interface loopback99
 ip address 10.89.99.21 255.255.255.255
!
router bgp 80000
 bgp log-neighbor-changes
 !
 neighbor 200.89.212.23 remote-as 65000
 neighbor 200.89.212.23 description ISP2-23
 neighbor 200.89.212.23 ttl-security hops 1
 !
 neighbor 10.89.255.20 remote-as 80000
 neighbor 10.89.255.20 description iBGP-RT-EDGE-DC-89-20
 neighbor 10.89.255.20 ttl-security hops 1
 !
 address-family ipv4
  neighbor 200.89.212.23 activate
  neighbor 200.89.212.23 send-community
  neighbor 200.89.212.23 route-map RM-FROM-ISP2 in
  neighbor 200.89.212.23 route-map RM-TO-ISP2 out
  !
  neighbor 10.89.255.20 activate
  neighbor 10.89.255.20 next-hop-self
  !
  network 10.89.6.6 mask 255.255.255.255
  network 10.89.7.7 mask 255.255.255.255
  network 10.89.8.8 mask 255.255.255.255
  network 10.89.9.9 mask 255.255.255.255
  network 10.89.10.10 mask 255.255.255.255
  network 10.89.99.21 mask 255.255.255.255
 exit-address-family
!
ip prefix-list PL-DEFAULT seq 5 permit 0.0.0.0/0
!
route-map RM-FROM-ISP2 permit 10
 match ip address prefix-list PL-DEFAULT
 set local-preference 100
!
route-map RM-FROM-ISP2 permit 20
!
route-map RM-TO-ISP2 permit 10
 set community 800:100 additive
!
end
wr mem

############################################################################################################################################################################

ADMINISTRADOR-REMOTO — FULL CONFIG

enable
!
configure terminal
!
hostname ADMINISTRADOR-REMOTO
!
int e0
ip address 200.1.232.24 255.255.255.0
no shutdown
duplex full
exit
!
ip route 0.0.0.0 0.0.0.0 200.1.232.23
!
end
!
write memory

############################################################################################################################################################################

PC-VLAN99-GOLD-JUMPSERVER — FULL CONFIG

enable
!
configure terminal
!
hostname PC-VLAN99-GOLD-JUMPSERVER
!
crypto key generate rsa 1024
!
ip domain-name fiat.com
!
crypto key generate rsa
1024
!
int e0
!
ip address 10.11.99.10 255.255.255.0
no shutdown
duplex full
exit
!
ip route 0.0.0.0 0.0.0.0 10.11.99.254
!
username admin password cisco
!
line vty 0 15
login local
transport input ssh
exit
!
enable secret cisco
!
end
!
write memory

############################################################################################################################################################################

ADMINISTRADOR-REMOTO#ssh -l admin 10.11.99.10
Password: cisco

############################################################################################################################################################################

PC-VLAN99-GOLD-JUMPSERVER#telnet 10.89.99.20
Password: cisco

PC-VLAN99-GOLD-JUMPSERVER#telnet 10.89.99.21
Password: cisco

############################################################################################################################################################################