09 Oct 14:43
[S5700]display current-configuration
[V300R024C00SPC100]
#
sysname S5700
#
drop illegal-mac alarm
#
ipv6
#
authentication-profile name default_authen_profile
authentication-profile name dot1x_authen_profile
authentication-profile name dot1xmac_authen_profile
authentication-profile name mac_authen_profile
authentication-profile name multi_authen_profile
authentication-profile name portal_authen_profile
#
dhcp enable
#
radius-server template default
#
pki realm default
certificate-check none
#
ssl policy default_policy type server
pki-realm default
version tls1.2
ciphersuite rsa_aes_128_sha256 rsa_aes_256_sha256 ecdhe_rsa_aes128_gcm_sha256 ecdhe_rsa_aes256_gcm_sha384
#
acl number 2000
rule 5 permit source 192.168.1.3 0
rule 1000 deny
#
acl number 3000
rule 5 permit tcp source 192.168.1.4 0 destination-port eq 22
rule 1000 deny tcp destination-port eq 22
#
ike proposal default
encryption-algorithm aes-256 aes-192 aes-128 aes-gcm-256 aes-gcm-192 aes-gcm-128
dh group14
authentication-algorithm sha2-512 sha2-384 sha2-256
authentication-method pre-share
integrity-algorithm hmac-sha2-256
prf hmac-sha2-256
#
free-rule-template name default_free_rule
#
portal-access-profile name portal_access_profile
#
aaa
authentication-scheme KONTA
authentication-mode local
authentication-scheme default
authentication-mode local
authentication-scheme radius
authentication-mode radius
authorization-scheme PRAWA
authorization-mode local
authorization-scheme default
authorization-mode local
accounting-scheme default
accounting-mode none
local-aaa-user password policy administrator
domain default
authentication-scheme default
accounting-scheme default
radius-server default
domain default_admin
authentication-scheme default
accounting-scheme default
domain put.poznan.pl
authentication-scheme KONTA
accounting-scheme default
authorization-scheme PRAWA
radius-server default
local-user admin password irreversible-cipher $1a$cRJbC&~[=!$Ic9##8w[m2tf1E1WApL#8:l|#WBSPPO8{2=(9hE8$
local-user admin privilege level 15
local-user admin service-type terminal ssh
local-user operator password irreversible-cipher $1a$b~J8RkB'[&$iQ_*3uyX"9q@WE,V8wnBQh}n~fN/k"#G_,8M"UrP$
local-user operator privilege level 15
local-user operator service-type terminal ssh
#
web
set fast-configuration state disable
#
firewall zone Local
#
mi-server
#
interface Vlanif1
ip address 192.168.1.1 255.255.255.0
dhcp select interface
#
interface GigabitEthernet0/0/0
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
description VirtualPort
ipv6 enable
ipv6 address auto link-local
ipv6 address auto global default
ip address dhcp-alloc
ipv6 address auto dhcp
#
interface NULL0
#
cellular profile default
modem auto-recovery dial action modem-reboot fail-times 128
modem auto-recovery icmp-unreachable action modem-reboot
modem auto-recovery services-unavailable action modem-reboot test-times 0 interval 3600
#
undo icmp name timestamp-request receive
#
snmp-agent local-engineid 800007DB03C4D438CDFBA8
#
ssh user admin authentication-type password
ssh user operator authentication-type password
stelnet server enable
ssh server permit interface all
#
http secure-server ssl-policy default_policy
http secure-server enable
http server permit interface GigabitEthernet0/0/8
#
fib regularly-refresh disable
#
user-interface con 0
authentication-mode password
set authentication password cipher %^%#2VQS'qzNQR^x8~T:D0Y<e-s3:KiG5=0Ra3.]E{k8VaJ+U8NK'I.j74Gz}bo*%^%#
history-command max-size 100
idle-timeout 0 0
user-interface vty 0
acl 3000 inbound
authentication-mode aaa
user privilege level 15
protocol inbound ssh
user-interface vty 1 4
acl 3000 inbound
authentication-mode aaa
protocol inbound ssh
#
wlan ac
traffic-profile name default
security-profile name default
security-profile name default-wds
security wpa2 psk pass-phrase %^%#G7eV<etUL7!O+"9`wr"QtPx_4yG'w@|H38E6$ST1%^%# aes
ssid-profile name default
vap-profile name default
wds-profile name default
regulatory-domain-profile name default
air-scan-profile name default
rrm-profile name default
radio-2g-profile name default
radio-5g-profile name default
wids-spoof-profile name default
wids-profile name default
ap-system-profile name default
port-link-profile name default
wired-port-profile name default
ap-group name default
#
dot1x-access-profile name dot1x_access_profile
#
mac-access-profile name mac_access_profile
#
voice
#
enterprise default
#
diagnose
#
ops
#
autostart
#
secelog
#
ms-channel
#
return
[S5700]