! Cisco IOS XE Software, Version 16.06.04 ! ! Image: Software: X86_64_LINUX_IOSD-UNIVERSALK9_NOLI-M, 16.6.4, RELEASE SOFTWARE (fc3) ! Image: Compiled: Sun 08-Jul-18 04:32 by mcpre ! Image: bootflash:/asr1002x-universalk9_noli.16.06.04.SPA.bin ! Chassis type: ASR1002-X ! Memory: main 6861555K/6147K ! Processor ID: FOX2316PPZ3 ! CPU: 2RU-X ! Memory: nvram 32768K ! ! VTP: show vtp status ! ! NAME: "Chassis", DESCR: "Cisco ASR1002-X Chassis" ! PID: ASR1002-X , VID: V07 , SN: FOX2316PPZ3 ! ! NAME: "Power Supply Module 0", DESCR: "Cisco ASR1002 AC Power Supply" ! PID: ASR1002-PWR-AC , VID: V04 , SN: DCB232440GB ! ! NAME: "Power Supply Module 1", DESCR: "Cisco ASR1002 AC Power Supply" ! PID: ASR1002-PWR-AC , VID: V04 , SN: DCB232440F4 ! ! NAME: "module 0", DESCR: "Cisco ASR1002-X SPA Interface Processor" ! PID: ASR1002-X , VID: , SN: ! ! NAME: "SPA subslot 0/0", DESCR: "6-port Built-in GE SPA" ! PID: 6XGE-BUILT-IN , VID: , SN: ! ! NAME: "subslot 0/0 transceiver 0", DESCR: "GE T" ! PID: ABCU-5710RZ-CS4 , VID: B2 , SN: AGM170629ZV ! ! NAME: "subslot 0/0 transceiver 1", DESCR: "GE T" ! PID: GLC-TE , VID: V01 , SN: AVC211024L9 ! ! NAME: "subslot 0/0 transceiver 2", DESCR: "GE T" ! PID: GLC-TE , VID: V01 , SN: AVC211024L7 ! ! NAME: "subslot 0/0 transceiver 3", DESCR: "GE T" ! PID: GLC-TE , VID: V01 , SN: AVC211024KX ! ! NAME: "module R0", DESCR: "Cisco ASR1002-X Route Processor" ! PID: ASR1002-X , VID: V07 , SN: JAE23390ST7 ! ! NAME: "module F0", DESCR: "Cisco ASR1002-X Embedded Services Processor" ! PID: ASR1002-X , VID: , SN: ! ! ! ! Last configuration change at 17:09:19 GMT Mon Sep 2 2024 by wellpower ! NVRAM config last updated at 05:38:47 GMT Tue Jul 30 2024 by wellpower ! version 16.6 service timestamps debug datetime msec service timestamps log datetime localtime service password-encryption platform qfp utilization monitor load 80 no platform punt-keepalive disable-kernel-core ! hostname E11_ASR1002-X ! boot-start-marker boot-end-marker ! ! vrf definition Mgmt-intf ! address-family ipv4 exit-address-family ! address-family ipv6 exit-address-family ! logging buffered 512000 enable password 7 06535C1549690D3B064E472B5B ! no aaa new-model clock timezone GMT 8 0 ! ! ! ! ! ! ! ip domain name cisco.com ! ! ! login block-for 60 attempts 5 within 30 login quiet-mode access-class 99 ! ! ! ! ! ! ! subscriber templating ! ! ! ! ! ! ! ! flow record FLOW-RECORD match interface input match ipv4 tos match ipv4 protocol match ipv4 source address match ipv4 destination address match transport source-port match transport destination-port collect counter bytes collect counter packets collect timestamp sys-uptime first collect timestamp sys-uptime last ! ! flow record FLOW-RECORD_out match ipv4 tos match ipv4 protocol match ipv4 source address match ipv4 destination address match transport source-port match transport destination-port match interface output collect counter bytes collect counter packets collect timestamp sys-uptime first collect timestamp sys-uptime last ! ! flow exporter netflow destination 10.7.49.252 source Port-channel1.749 transport udp 9554 ! ! flow monitor IPv4_netflow exporter netflow cache timeout inactive 10 cache timeout active 1 record FLOW-RECORD ! ! flow monitor IPv4_netflow_out exporter netflow cache timeout inactive 10 cache timeout active 1 record FLOW-RECORD_out ! multilink bundle-name authenticated ! ! ! ! ! ! ! ! crypto pki trustpoint TP-self-signed-1890996819 enrollment selfsigned subject-name cn=IOS-Self-Signed-Certificate-1890996819 revocation-check none rsakeypair TP-self-signed-1890996819 ! ! crypto pki certificate chain TP-self-signed-1890996819 certificate self-signed 01 30820330 30820218 A0030201 02020101 300D0609 2A864886 F70D0101 05050030 31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274 69666963 6174652D 31383930 39393638 3139301E 170D3139 31303234 30323232 33305A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649 4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 38393039 39363831 39308201 22300D06 092A8648 86F70D01 01010500 0382010F 00308201 0A028201 01009693 F287C592 6B9C4EF5 D8FC1BFD D5959C11 777E32E2 8058B529 39928BC8 155356A1 C1B6964E 22E9980D 7C389F95 C7B6416E 625B5882 BB2A7741 1422B443 FEA7B5C6 A0EE7E45 8216C7B1 C37E8764 77273E63 161AC4F2 6F691534 478290B3 515E465B 62B471DF 8BD3206E 37D9467D 8C64829F 04FF87B0 457F9C12 9AABF417 9DC7A820 C7872381 106758EB 65C79BDC 26390663 9EFF65AD 9B25C264 5E9AD1EF 54FB5277 EF85CD69 CD9FA011 3E200092 A5C25B17 0C809365 07E081F2 BC0B4735 16B4247B CC0AA13B 046712D0 34197F02 721A863B 024C88FD 47534412 3297709F 3AD61750 EB00877A 2B02E574 5A30AF31 4280562D 46E4C645 44526300 917B5DE1 68EB0203 010001A3 53305130 0F060355 1D130101 FF040530 030101FF 301F0603 551D2304 18301680 14425574 0BCAD26E C3652872 37805720 9B9A8502 4D301D06 03551D0E 04160414 4255740B CAD26EC3 65287237 8057209B 9A85024D 300D0609 2A864886 F70D0101 05050003 82010100 1B412739 65247DF3 7230AB4E 8610AF8C 189F1E1F 0B95E804 BFCA3C8F B690F7BD 72DDCAD6 E6119F91 E21BCAFE D1A2D830 894B0923 3EA9473E BC349532 46B0F97D 835C19E2 92655CDF B4EE17F8 EE1FAA11 E7A5BC22 9672FF23 165F6864 93989D67 82B7AAEC 982990D1 027960DF 898CC85E 7046830B 177E0E6E 06B93F4A 515E3816 55FB5B19 47BBF17B 4C70925B 7E18B45C ADEDB7F3 8A59F111 10C91A08 68917879 B1AA8FF3 585A222B D0634649 52F464E8 C8C02938 E0428690 83CEB16B EB0877B3 4E4CE6F9 A3286D1C 44114F42 E7565D8F 7A2B0226 8D2535BC 0E794A21 A06928D0 6B75D32D 9FCFCE0F 80A1F082 08BD8401 FBF5821F C45C4ABC 8277FB26 066FB14D quit ! ! license udi pid ASR1002-X sn JAE23390ST7 ! spanning-tree extend system-id diagnostic bootup level minimal ! ! username wellpower password 7 04681E161F1F7566274C111010 ! redundancy mode none ! ! ! ! ! ! track 100 ip sla 100 reachability delay down 10 up 10 ! track 101 ip sla 101 reachability delay down 10 up 10 ! ! class-map match-any Match_any_ip match access-group name Match_any class-map match-any 5m match access-group name any2any class-map match-any 10m_ext match access-group name Match_210.244.17.0/29 class-map match-any 1m match access-group name any2any class-map match-any 3m match access-group name any2any class-map match-any 40m match access-group name any2any class-map match-any 10m match access-group name any2any class-map match-any 20m match access-group name any2any ! policy-map 3m class 3m police 3000000 1000000 conform-action transmit exceed-action drop policy-map 5m class 5m police 5000000 1000000 conform-action transmit exceed-action drop policy-map 40m class 40m police 40000000 1000000 conform-action transmit exceed-action drop policy-map 10m_extend class 10m_ext police 1000000 100000 conform-action transmit exceed-action drop policy-map 10m class 10m police 10000000 1000000 conform-action transmit exceed-action drop policy-map 20m class 20m police 20000000 1000000 conform-action transmit exceed-action drop policy-map 1m class 1m police 1000000 1000000 conform-action transmit exceed-action drop policy-map Bandwidth_10M class Match_any_ip police cir 10000000 pir 11000000 conform-action transmit exceed-action drop policy-map 150m class Match_any_ip police 150000000 1000000 conform-action transmit exceed-action drop ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! interface Loopback1 no ip address ! interface Loopback2 no ip address ! interface Loopback6 ip address 10.100.40.18 255.255.255.255 ! interface Port-channel1 no ip address no negotiation auto ! interface Port-channel1.749 description MGT-2 encapsulation dot1Q 749 ip address 10.7.49.3 255.255.255.0 ! interface Port-channel1.2000 description CA212004_Wan encapsulation dot1Q 2000 ip address 139.175.158.6 255.255.255.252 ! interface Port-channel1.2001 description CA001028_Wan encapsulation dot1Q 2001 ip flow monitor IPv4_netflow input ip flow monitor IPv4_netflow_out output ip address 139.175.158.18 255.255.255.252 ! interface Port-channel1.2002 description CA510029_Wan encapsulation dot1Q 2002 ip address 139.175.158.22 255.255.255.252 ! interface Port-channel1.2749 description MGT encapsulation dot1Q 2749 ip address 10.27.49.3 255.255.255.0 ! interface Port-channel2 no ip address no negotiation auto ! interface Port-channel2.2 description CA212004_LAN encapsulation dot1Q 2 ip address 210.64.214.61 255.255.255.224 secondary ip address 210.64.214.62 255.255.255.224 ip policy route-map Output_Policy ! interface Port-channel2.17 description CA212004_LAN2 encapsulation dot1Q 17 ip address 210.244.17.1 255.255.255.240 service-policy input 10m service-policy output 10m ! interface Port-channel2.18 description Incapsula-LY-G11 encapsulation dot1Q 18 ip flow monitor IPv4_netflow input ip flow monitor IPv4_netflow_out output ip address 103.38.147.97 255.255.255.224 secondary ip address 103.252.244.81 255.255.255.224 ! interface Port-channel2.28 description CA510029_210.64.214.96/28 encapsulation dot1Q 28 ip address 210.64.214.97 255.255.255.240 ip policy route-map Output_Policy ! interface Port-channel2.29 description CA510029_oops_D_210.244.17.224/27 encapsulation dot1Q 29 ip address 210.244.17.254 255.255.255.224 ip policy route-map Output_Policy ! interface Port-channel2.30 description CA001028_LAN encapsulation dot1Q 30 ip address 210.244.19.249 255.255.255.0 secondary ip address 210.244.19.241 255.255.255.0 secondary ip address 210.244.19.254 255.255.255.0 secondary ip address 210.244.19.200 255.255.255.0 secondary ip address 210.244.19.251 255.255.255.0 ip policy route-map Output_Policy ! interface Port-channel2.31 description 210.64.215.112/28 encapsulation dot1Q 31 ip address 210.64.215.113 255.255.255.240 ! interface Port-channel2.61 description Incapsula-wellpower encapsulation dot1Q 61 ip address 103.38.147.129 255.255.255.240 secondary ip address 103.252.244.30 255.255.255.240 ! interface Port-channel2.62 description Incapsula-Ted encapsulation dot1Q 62 ip address 103.38.147.78 255.255.255.240 secondary ip address 103.252.244.14 255.255.255.240 shutdown ! interface Port-channel2.63 description Incapsula-Nat-TP encapsulation dot1Q 63 ip address 103.252.244.254 255.255.255.240 shutdown ! interface Port-channel2.64 description Incapsula-oops encapsulation dot1Q 64 ip address 103.252.244.190 255.255.255.192 ! interface Port-channel2.65 description Incapsula-Nat-Image encapsulation dot1Q 65 ip address 103.252.244.46 255.255.255.240 shutdown ! interface Port-channel2.100 description CHT_1G/600M#1 encapsulation dot1Q 100 ip address 211.72.32.117 255.255.255.0 ! interface Port-channel2.112 description CA212004_LAN3 encapsulation dot1Q 112 ip address 103.38.147.145 255.255.255.240 secondary ip address 210.64.216.1 255.255.255.240 service-policy input 10m service-policy output 10m ! interface Port-channel2.132 description CA212004_210.66.68.128/28 encapsulation dot1Q 132 ip address 210.66.68.129 255.255.255.248 ! interface Port-channel2.151 description CVT encapsulation dot1Q 151 ip address 103.49.247.1 255.255.255.240 ip policy route-map Output_Policy ! interface Port-channel2.152 description CVT_G09_10M encapsulation dot1Q 152 ip address 103.49.247.17 255.255.255.240 ip policy route-map Output_Policy shutdown service-policy input 10m service-policy output 10m ! interface Port-channel2.153 description CVT_G09_10M encapsulation dot1Q 153 ip address 103.49.246.1 255.255.255.240 ip policy route-map Output_Policy shutdown ! interface Port-channel2.154 description CA001028_LAN_G09 encapsulation dot1Q 154 ip address 210.64.205.145 255.255.255.240 ip policy route-map Output_Policy ! interface Port-channel2.155 description CA001028_LAN_G09_20220304 encapsulation dot1Q 155 ip address 210.64.215.33 255.255.255.240 ip policy route-map Output_Policy ! interface Port-channel2.156 description CVT_103.49.247.64/29_test encapsulation dot1Q 156 ip policy route-map Output_Policy shutdown ! interface Port-channel2.201 description CVT-oops-A encapsulation dot1Q 201 ip address 103.49.247.193 255.255.255.192 ip policy route-map Output_Policy ! interface Port-channel2.202 description CVT-wellpower encapsulation dot1Q 202 ip address 202.76.126.254 255.255.255.0 secondary ip address 103.208.0.254 255.255.255.0 secondary ip address 103.49.246.97 255.255.255.240 ip policy route-map Output_Policy service-policy input 20m service-policy output 20m ! interface Port-channel2.203 description CVT-oops-B encapsulation dot1Q 203 ip address 210.211.31.1 255.255.255.192 ip policy route-map Output_Policy ! interface Port-channel2.204 description CVT-wellpower-vm-Test encapsulation dot1Q 204 ip address 103.49.247.41 255.255.255.248 ip policy route-map Output_Policy service-policy input 20m service-policy output 20m ! interface Port-channel2.205 description Megai-tt vpn-backup encapsulation dot1Q 205 ip address 103.49.247.81 255.255.255.248 service-policy input 20m service-policy output 20m ! interface Port-channel2.401 encapsulation dot1Q 401 ip address 10.100.41.4 255.255.255.224 ! interface Tunnel1 description to PH ASR ip address 10.201.1.1 255.255.255.252 tunnel source 210.64.214.62 tunnel destination 103.48.30.254 ! interface Tunnel2 description to hk mega ip address 10.10.111.2 255.255.255.252 keepalive 3 3 tunnel source 10.100.41.4 tunnel destination 10.100.41.22 ! interface Tunnel3 description to hk mega backup ip address 103.49.246.242 255.255.255.252 tunnel source 210.244.19.251 tunnel destination 103.49.246.253 ! interface Tunnel4 description to G11 VG C3850x ip address 10.40.2.1 255.255.255.252 keepalive 10 3 tunnel source 210.64.214.62 tunnel destination 139.175.158.2 ! interface Tunnel9 description E11 ASR-PH ASR for snmp ip address 10.111.0.1 255.255.255.252 keepalive 3 3 tunnel source 210.64.214.62 tunnel destination 103.202.224.254 ! interface Tunnel10 description Incapsula HK ip address 192.168.31.50 255.255.255.252 ip access-group 101 in ip tcp adjust-mss 1420 keepalive 3 3 tunnel source 210.244.19.251 tunnel destination 107.154.26.57 service-policy input 150m service-policy output 150m ! interface Tunnel11 description Incapsula TKO ip address 172.17.1.10 255.255.255.252 ip access-group 101 in ip tcp adjust-mss 1420 keepalive 3 3 tunnel source 211.72.32.117 tunnel destination 107.154.24.42 service-policy input 150m service-policy output 150m ! interface Tunnel100 description To_test_https ip address 100.2.2.1 255.255.255.252 tunnel source 210.64.214.62 tunnel destination 175.45.35.194 ! interface GigabitEthernet0/0/0 description to_Arbor_int0_ext0_C3850_G1/0/1 no ip address negotiation auto channel-group 1 mode active ! interface GigabitEthernet0/0/1 description to_Arbor_int1_ext1_C3850_G2/0/1 no ip address negotiation auto channel-group 1 mode active ! interface GigabitEthernet0/0/2 description to_Arbor_ext2_int2_C3850_G3/0/1 no ip address negotiation auto channel-group 2 mode active ! interface GigabitEthernet0/0/3 description to_Arbor_ext3_int3_C3850_G4/0/1 no ip address negotiation auto channel-group 2 mode active ! interface GigabitEthernet0/0/4 no ip address shutdown negotiation auto ! interface GigabitEthernet0/0/5 no ip address shutdown negotiation auto ! interface GigabitEthernet0 vrf forwarding Mgmt-intf no ip address shutdown negotiation auto ! router bgp 133158 bgp log-neighbor-changes neighbor incapsula-tko peer-group neighbor incapsula-tko remote-as 19551 neighbor incapsula-tko description incapsula-tko-19551 neighbor incapsula-tko version 4 neighbor incapsula-lax peer-group neighbor incapsula-lax remote-as 19551 neighbor incapsula-lax description incapsula-tko-19551 neighbor incapsula-lax version 4 neighbor incapsula-hk peer-group neighbor incapsula-hk remote-as 19551 neighbor incapsula-hk description incapsula-hk-19551 neighbor incapsula-hk version 4 neighbor 172.17.1.9 peer-group incapsula-tko neighbor 172.17.1.9 description tunnel11-to-incapsula-tko neighbor 172.20.1.81 peer-group incapsula-lax neighbor 172.20.1.81 description tunnel12-to-incapsula-lax neighbor 192.168.31.49 peer-group incapsula-hk neighbor 192.168.31.49 description tunnel17-to-incapsula-hk ! address-family ipv4 network 103.38.146.0 mask 255.255.255.0 network 103.38.147.0 mask 255.255.255.0 network 103.252.244.0 mask 255.255.255.0 neighbor incapsula-tko send-community neighbor incapsula-tko prefix-list deny-all in neighbor incapsula-tko route-map incapsula-tko out neighbor incapsula-lax send-community neighbor incapsula-lax prefix-list deny-all in neighbor incapsula-lax route-map incapsula-lax out neighbor incapsula-hk send-community neighbor incapsula-hk prefix-list deny-all in neighbor incapsula-hk route-map incapsula-hk out neighbor 172.17.1.9 activate neighbor 172.20.1.81 activate neighbor 192.168.31.49 activate exit-address-family ! ip forward-protocol nd ! ip bgp-community new-format no ip http server ip http authentication local no ip http secure-server ip tftp source-interface GigabitEthernet0 ip route 0.0.0.0 0.0.0.0 139.175.158.5 ip route 0.0.0.0 0.0.0.0 139.175.158.17 101 ip route 10.98.76.0 255.255.255.0 10.111.0.2 ip route 10.100.40.17 255.255.255.255 103.49.246.241 20 ip route 10.100.40.17 255.255.255.255 10.10.111.1 30 ip route 72.52.18.224 255.255.255.255 139.175.158.5 ip route 72.52.43.16 255.255.255.255 139.175.158.5 ip route 103.38.146.0 255.255.255.0 Null0 ip route 103.38.147.0 255.255.255.0 Null0 250 ip route 103.252.244.0 255.255.255.0 Null0 250 ip route 103.252.244.192 255.255.255.224 10.40.2.2 ip route 103.252.244.224 255.255.255.240 210.64.214.56 ip route 103.252.244.224 255.255.255.240 10.201.1.2 10 ip route 107.154.24.42 255.255.255.255 211.72.32.254 ip route 107.154.50.216 255.255.255.255 210.64.214.53 ip ssh port 3001 rotary 1 ip ssh version 2 ! ip access-list extended Match_210.244.17.0/29 permit ip 210.244.17.0 0.0.0.7 any permit ip any any ip access-list extended Match_any permit ip any any ip access-list extended TW_to_CVT permit ip 103.49.247.192 0.0.0.63 any permit ip 103.208.0.0 0.0.0.255 any permit ip 210.211.31.0 0.0.0.63 any permit ip 103.49.246.96 0.0.0.15 any permit ip 103.49.247.0 0.0.0.255 any permit ip 103.49.246.0 0.0.0.15 any permit ip 103.49.246.0 0.0.0.255 any permit ip 103.208.1.0 0.0.0.255 any permit ip 202.76.126.0 0.0.0.255 any ip access-list extended TW_to_CVT_SP permit ip 202.76.126.0 0.0.0.255 any ip access-list extended TW_to_CVT_SP2 permit ip 103.208.0.0 0.0.0.255 any ip access-list extended any2any permit ip any any ip access-list extended ssh-permit permit tcp 210.64.214.32 0.0.0.31 any eq telnet permit tcp host 210.244.19.250 any eq telnet permit tcp host 61.216.103.162 any eq 22 permit tcp 211.72.32.0 0.0.0.255 any eq 22 permit tcp host 211.20.122.55 any eq 22 permit tcp 211.72.32.0 0.0.0.255 any eq telnet permit tcp host 211.20.122.60 any eq 22 permit ip 10.27.49.0 0.0.0.255 any permit ip 10.100.99.0 0.0.0.255 any permit tcp host 210.244.19.250 any eq 22 permit ip 10.7.49.0 0.0.0.255 any permit tcp host 210.244.19.175 any eq 22 ! ! ip prefix-list 103.252.224.0-out seq 5 permit 103.252.224.0/24 ! ip prefix-list CUST-subnet seq 10 permit 103.252.224.0/24 ! ip prefix-list deny-all seq 5 deny 0.0.0.0/0 le 32 ! ip prefix-list incapsula-out seq 3 permit 103.252.244.0/24 ip prefix-list incapsula-out seq 4 permit 103.252.224.0/24 ip prefix-list incapsula-out seq 5 permit 103.38.147.0/24 ip prefix-list incapsula-out seq 7 permit 103.38.146.0/24 ! ip prefix-list prolexic-out seq 5 permit 103.252.244.0/24 ! ip prefix-list prolexic-suppress seq 5 deny 103.252.224.0/24 ip sla 100 icmp-echo 10.10.111.1 source-ip 10.10.111.2 frequency 5 ip sla schedule 100 life forever start-time now ip sla 101 icmp-echo 103.49.246.241 source-ip 103.49.246.242 frequency 5 ip sla schedule 101 life forever start-time now logging trap warnings logging host 210.244.19.250 access-list 99 permit 61.216.103.162 access-list 99 permit 211.20.122.55 access-list 99 permit 210.64.214.250 access-list 99 permit 210.244.19.250 access-list 99 permit 61.59.16.0 0.0.0.255 access-list 99 permit 210.64.214.32 0.0.0.31 access-list 99 permit 211.72.32.0 0.0.0.255 access-list 99 permit 10.27.49.0 0.0.0.255 access-list 101 deny icmp any host 103.252.244.14 access-list 101 deny icmp any host 103.38.147.78 access-list 101 permit ip any any access-list 120 deny ip 210.244.19.0 0.0.0.255 210.244.19.0 0.0.0.255 access-list 120 permit ip 210.244.19.0 0.0.0.255 any access-list 120 permit ip 210.64.205.144 0.0.0.15 any access-list 120 permit ip 210.64.215.32 0.0.0.15 any access-list 121 permit ip 210.244.19.0 0.0.0.255 202.77.138.0 0.0.0.15 access-list 122 permit ip 210.244.17.224 0.0.0.31 any access-list 122 permit ip 210.64.214.96 0.0.0.15 any ! ! route-map incapsula-tko permit 10 match ip address prefix-list incapsula-out set community 19551:511 ! route-map incapsula-lax permit 10 match ip address prefix-list incapsula-out set community no-export ! route-map Output_Policy permit 7 match ip address TW_to_CVT set ip precedence priority set ip next-hop verify-availability 10.10.111.1 5 track 100 set ip next-hop verify-availability 103.49.246.241 6 track 101 ! route-map Output_Policy permit 9 match ip address 121 set ip precedence priority set ip next-hop 10.201.0.10 ! route-map Output_Policy permit 10 match ip address 120 set ip precedence priority set ip next-hop 139.175.158.17 ! route-map Output_Policy permit 11 match ip address 122 set ip precedence priority set ip next-hop 139.175.158.21 ! route-map incapsula-hk permit 10 match ip address prefix-list incapsula-out ! route-map prolexic-out permit 10 match ip address prefix-list prolexic-out ! route-map 103.252.224.0-tko permit 10 match ip address prefix-list 103.252.224.0-out set community 19551:513 ! route-map 103.252.224.0-lax permit 10 match ip address prefix-list 103.252.224.0-out ! snmp-server community ikeeper RW snmp-server enable traps snmp linkdown linkup snmp-server enable traps syslog snmp-server host 210.244.19.250 ikeeper ! ! control-plane ! ! ! ! ! ! line con 0 stopbits 1 line aux 0 stopbits 1 line vty 0 4 access-class ssh-permit in login local rotary 1 transport input telnet ssh ! ntp server 118.163.81.62 ! wsma agent exec ! wsma agent config ! wsma agent filesys ! wsma agent notify ! ! end