Appendix
The following files are used in this chapter:
- configuration of AGG-1
- configuration of BNG-1 with per-Vport load balancing with classes and weights
- configuration of BNG-1 with per-Vport load balancing without classes and weights
- configuration of BNG-1 with per-subscriber load balancing
- RADIUS users
agg-1
# TiMOS-B-22.10.R1 both/x86_64 Nokia 7750 SR Copyright (c) 2000-2022 Nokia.
# All rights reserved. All use subject to applicable license agreements.
# Built on Sun Oct 30 14:49:55 PDT 2022 by builder in /builds/c/2210B/R1/panos/main/sros
# Configuration format version 22.10 revision 0
# Generated 2022-11-18T08:49:28.3Z by admin from 135.231.208.32
# Commit ID 1
# Committed 2022-11-17T11:34:34.8Z by system (MD-CLI) from Console
# Log "System booted version B-22.10.R1."
configure {
card 1 {
card-type iom-1
mda 1 {
mda-type me6-100gb-qsfp28
}
mda 2 {
mda-type me6-100gb-qsfp28
xconnect {
mac 1 {
loopback 1 {
}
}
}
}
fp 1 {
}
}
log {
filter "1001" {
named-entry "10" {
description "Collect only events of major severity or higher"
action forward
match {
severity {
gte major
}
}
}
}
log-id "100" {
description "Default Serious Errors Log"
filter "1001"
source {
main true
}
destination {
memory {
max-entries 500
}
}
}
log-id "99" {
description "Default System Log"
source {
main true
}
destination {
memory {
max-entries 500
}
}
}
}
port 1/1/c1 {
admin-state enable
connector {
breakout c10-10g
}
}
port 1/1/c1/1 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/2 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/3 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/4 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/5 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/6 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/7 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/8 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/9 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/10 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c2 {
admin-state enable
connector {
breakout c10-10g
}
}
port 1/1/c2/1 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c2/2 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c2/3 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c2/4 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c2/5 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c2/6 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c2/7 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c2/8 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c2/9 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c2/10 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c3 {
admin-state enable
connector {
breakout c10-10g
}
}
port 1/1/c3/1 {
admin-state enable
ethernet {
mode hybrid
encap-type qinq
}
}
port 1/1/c3/2 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c3/3 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c3/4 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c3/5 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c3/6 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c3/7 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c3/8 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c3/9 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c3/10 {
admin-state enable
ethernet {
mode hybrid
encap-type dot1q
}
}
port 1/1/c4 {
admin-state enable
connector {
breakout c4-10g
}
}
port 1/1/c4/1 {
admin-state enable
ethernet {
mode hybrid
dot1x {
tunneling true
}
}
}
port 1/1/c5 {
}
port 1/1/c6 {
}
port 1/2/c1 {
}
port 1/2/c2 {
}
port 1/2/c3 {
}
port 1/2/c4 {
}
port 1/2/c5 {
}
port 1/2/c6 {
}
port 1/2/m1/1 {
}
router "Base" {
autonomous-system 64500
router-id 192.0.2.5
interface "int-1-pe-1-p-1" {
port 1/1/c1/1:1
ipv6 {
address 2001:db8::101 {
prefix-length 120
}
}
}
interface "system" {
ipv4 {
primary {
address 192.0.2.5
prefix-length 32
}
}
ipv6 {
address 2001:db8::5 {
prefix-length 128
}
}
}
interface "to-ixia" {
port 1/1/c3/1:1.1
ipv4 {
primary {
address 172.16.100.1
prefix-length 24
}
}
ipv6 {
address 2001:db8::6401 {
prefix-length 120
}
}
}
interface "to-radius" {
port 1/1/c3/10:114
ipv4 {
primary {
address 192.168.114.5
prefix-length 24
}
}
}
bgp {
admin-state enable
vpn-apply-export true
vpn-apply-import true
rapid-withdrawal true
rapid-update {
evpn true
}
advertise-ipv6-next-hops {
evpn true
}
group "evpn" {
peer-as 64500
local-address 2001:db8::5
family {
evpn true
}
}
neighbor "2001:db8::14" {
group "evpn"
}
}
isis 0 {
admin-state enable
advertise-passive-only false
advertise-router-capability area
ipv6-routing native
level-capability 2
traffic-engineering true
area-address [49.0001]
interface "int-1-pe-1-p-1" {
}
interface "system" {
}
interface "to-ixia" {
}
}
ldp {
interface-parameters {
interface "int-1-pe-1-p-1" {
ipv6 {
admin-state enable
}
}
}
}
}
service {
system {
extended-default-qinq-sap-lookup true
}
epipe "access" {
admin-state enable
service-id 1
customer "1"
bgp 1 {
}
sap 1/1/c3/1:*.* {
}
bgp-evpn {
evi 10
local-attachment-circuit "access" {
eth-tag 1
}
remote-attachment-circuit "bng" {
eth-tag 2
}
mpls 1 {
admin-state enable
send-tunnel-encap {
mpls-over-udp true
}
auto-bind-tunnel {
resolution any
}
route-next-hop {
system-ipv6
}
}
}
}
}
system {
name "AGG-1"
management-interface {
configuration-mode model-driven
cli {
cli-engine [md-cli classic-cli]
}
yang-modules {
nokia-submodules true
nokia-combined-modules false
}
snmp {
admin-state disable
}
}
ip {
allow-qinq-network-interface true
}
bluetooth {
advertising-timeout 30
}
login-control {
idle-timeout none
}
security {
aaa {
local-profiles {
profile "administrative" {
default-action permit-all
entry 10 {
match "configure system security"
action permit
}
entry 20 {
match "show system security"
action permit
}
entry 30 {
match "tools perform security"
action permit
}
entry 40 {
match "tools dump security"
action permit
}
entry 50 {
match "admin system security"
action permit
}
entry 100 {
match "configure li"
action deny
}
entry 110 {
match "show li"
action deny
}
entry 111 {
match "clear li"
action deny
}
entry 112 {
match "tools dump li"
action deny
}
netconf {
base-op-authorization {
action true
cancel-commit true
close-session true
commit true
copy-config true
create-subscription true
delete-config true
discard-changes true
edit-config true
get true
get-config true
get-data true
get-schema true
kill-session true
lock true
validate true
}
}
}
profile "default" {
entry 10 {
match "exec"
action permit
}
entry 20 {
match "exit"
action permit
}
entry 30 {
match "help"
action permit
}
entry 40 {
match "logout"
action permit
}
entry 50 {
match "password"
action permit
}
entry 60 {
match "show config"
action deny
}
entry 65 {
match "show li"
action deny
}
entry 66 {
match "clear li"
action deny
}
entry 67 {
match "tools dump li"
action deny
}
entry 68 {
match "state li"
action deny
}
entry 70 {
match "show"
action permit
}
entry 75 {
match "state"
action permit
}
entry 80 {
match "enable-admin"
action permit
}
entry 90 {
match "enable"
action permit
}
entry 100 {
match "configure li"
action deny
}
netconf {
base-op-authorization {
action true
cancel-commit true
close-session true
commit true
copy-config true
create-subscription true
delete-config true
discard-changes true
edit-config true
get true
get-config true
get-data true
get-schema true
validate true
}
}
}
}
}
ssh {
server-cipher-list-v2 {
cipher 190 {
name aes256-ctr
}
cipher 192 {
name aes192-ctr
}
cipher 194 {
name aes128-ctr
}
cipher 200 {
name aes128-cbc
}
cipher 205 {
name 3des-cbc
}
cipher 225 {
name aes192-cbc
}
cipher 230 {
name aes256-cbc
}
}
client-cipher-list-v2 {
cipher 190 {
name aes256-ctr
}
cipher 192 {
name aes192-ctr
}
cipher 194 {
name aes128-ctr
}
cipher 200 {
name aes128-cbc
}
cipher 205 {
name 3des-cbc
}
cipher 225 {
name aes192-cbc
}
cipher 230 {
name aes256-cbc
}
}
server-mac-list-v2 {
mac 200 {
name hmac-sha2-512
}
mac 210 {
name hmac-sha2-256
}
mac 215 {
name hmac-sha1
}
mac 220 {
name hmac-sha1-96
}
mac 225 {
name hmac-md5
}
mac 240 {
name hmac-md5-96
}
}
client-mac-list-v2 {
mac 200 {
name hmac-sha2-512
}
mac 210 {
name hmac-sha2-256
}
mac 215 {
name hmac-sha1
}
mac 220 {
name hmac-sha1-96
}
mac 225 {
name hmac-md5
}
mac 240 {
name hmac-md5-96
}
}
}
user-params {
local-user {
user "admin" {
password "$2y$10$TQrZlpBDra86.qoexZUzQeBXDY1FcdDhGWdD9lLxMuFyPVSm0OGy6"
access {
console true
}
console {
member ["administrative"]
}
}
}
}
}
}
}
# Finished 2022-11-18T08:49:28.3Z
bng-per-vport-balancing-with-classes-weights
# TiMOS-C-22.10.R1 cpm/x86_64 Nokia 7750 SR Copyright (c) 2000-2022 Nokia.
# All rights reserved. All use subject to applicable license agreements.
# Built on Sun Oct 30 14:49:55 PDT 2022 by builder in /builds/c/2210B/R1/panos/main/sros
# Configuration format version 22.10 revision 0
# Generated 2022-12-14T13:31:35.4-06:00 by admin from 135.231.208.32
# Commit ID 2
# Committed 2022-12-14T12:45:28.3-06:00 by admin (MD-CLI) from 135.231.208.32
# Commit ID 1
# Committed 2022-12-14T12:38:03.7-06:00 by system (MD-CLI) from Console
# Log "System booted version C-22.10.R1."
configure {
aaa {
radius {
server-policy "radius-server-1" {
servers {
router-instance "Base"
server 1 {
server-name "free-radius-1"
}
}
}
}
}
card 1 {
card-type iom5-e
mda 1 {
mda-type me6-100gb-qsfp28
}
mda 2 {
mda-type me6-100gb-qsfp28
}
}
fwd-path-ext {
sdp-id-range {
start 17500
end 17600
}
fpe 1 {
description "pw-port on a lag"
path {
xc-lag-a "lag-2"
xc-lag-b "lag-3"
}
application {
pw-port-extension {
}
}
}
}
lag "lag-1" {
admin-state enable
description "lag to p-1"
mode hybrid
max-ports 64
port 1/1/c1/1 {
}
port 1/1/c1/2 {
}
}
lag "lag-2" {
admin-state enable
description "fpe pw-port pxc lag - transit side"
mode hybrid
max-ports 64
port pxc-1.a {
}
port pxc-2.a {
}
}
lag "lag-3" {
admin-state enable
description "fpe pw-port pxc lag - termination side"
mode hybrid
max-ports 64
access {
per-fp-ing-queuing true
per-fp-egr-queuing true
per-fp-sap-instance true
adapt-qos {
mode link
}
}
per-link-hash {
weighted {
subscriber-hash-mode vport
}
}
port pxc-1.b {
}
port pxc-2.b {
}
}
log {
filter "1001" {
named-entry "10" {
description "Collect only events of major severity or higher"
action forward
match {
severity {
gte major
}
}
}
}
log-id "100" {
description "Default Serious Errors Log"
filter "1001"
source {
main true
}
destination {
memory {
max-entries 500
}
}
}
log-id "99" {
description "Default System Log"
source {
main true
}
destination {
memory {
max-entries 500
}
}
}
}
port 1/1/c1 {
admin-state enable
connector {
breakout c10-10g
}
}
port 1/1/c1/1 {
admin-state enable
description "lag-1 to p-1 access"
ethernet {
mode hybrid
}
}
port 1/1/c1/2 {
admin-state enable
description "lag-1 to p-1 access"
ethernet {
mode hybrid
}
}
port 1/1/c1/3 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/4 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/5 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/6 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/7 {
admin-state enable
description "to pe-2 network"
ethernet {
mode hybrid
}
}
port 1/1/c1/8 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/9 {
admin-state enable
ethernet {
mode hybrid
dot1x {
tunneling true
}
}
}
port 1/1/c1/10 {
admin-state enable
description "RADIUS and mirroring"
ethernet {
mode hybrid
}
}
port 1/1/c2 {
admin-state enable
connector {
breakout c1-100g
}
}
port 1/1/c2/1 {
admin-state enable
ethernet {
mode hybrid
encap-type dot1q
dot1x {
tunneling true
}
}
}
port 1/1/c4 {
admin-state enable
connector {
breakout c4-10g
}
}
port 1/1/c4/1 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c4/2 {
admin-state enable
description "PXC 1; pw-port lag 2,3"
ethernet {
mode hybrid
dot1x {
tunneling true
}
}
}
port 1/1/c4/3 {
admin-state enable
description "PXC 2; pw-port lag 2,3"
ethernet {
mode hybrid
dot1x {
tunneling true
}
}
}
port 1/1/c4/4 {
admin-state enable
ethernet {
mode hybrid
}
}
port pxc-1.a {
admin-state enable
}
port pxc-1.b {
admin-state enable
description "PXC lag-3, pw-port termination"
ethernet {
access {
egress {
virtual-port "vport-1" {
aggregate-rate {
rate 9000000
}
host-match {
int-dest-id "vport-1" { }
}
lag-per-link-hash {
class 1
weight 15
}
}
virtual-port "vport-10" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-10" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-11" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-11" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-12" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-12" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-13" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-13" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-14" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-14" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-15" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-15" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-16" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-16" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-2" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-2" { }
}
lag-per-link-hash {
class 1
weight 5
}
}
virtual-port "vport-3" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-3" { }
}
lag-per-link-hash {
class 1
weight 5
}
}
virtual-port "vport-4" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-4" { }
}
lag-per-link-hash {
class 1
weight 5
}
}
virtual-port "vport-5" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-5" { }
}
lag-per-link-hash {
class 2
weight 15
}
}
virtual-port "vport-6" {
aggregate-rate {
rate 1000000
}
host-match {
int-dest-id "vport-6" { }
}
lag-per-link-hash {
class 2
weight 5
}
}
virtual-port "vport-7" {
aggregate-rate {
rate 1000000
}
host-match {
int-dest-id "vport-7" { }
}
lag-per-link-hash {
class 2
weight 5
}
}
virtual-port "vport-8" {
aggregate-rate {
rate 1000000
}
host-match {
int-dest-id "vport-8" { }
}
lag-per-link-hash {
class 2
weight 5
}
}
virtual-port "vport-9" {
aggregate-rate {
rate 1400000
}
host-match {
int-dest-id "vport-9" { }
}
lag-per-link-hash {
class 3
weight 7
}
}
}
}
egress {
port-scheduler-policy {
policy-name "lag-3-pxc"
}
}
}
}
port pxc-2.a {
admin-state enable
}
port pxc-2.b {
admin-state enable
description "PXC lag-3, pw-port termination"
ethernet {
access {
egress {
virtual-port "vport-1" {
aggregate-rate {
rate 9000000
}
host-match {
int-dest-id "vport-1" { }
}
lag-per-link-hash {
class 1
weight 15
}
}
virtual-port "vport-10" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-10" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-11" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-11" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-12" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-12" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-13" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-13" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-14" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-14" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-15" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-15" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-16" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-16" { }
}
lag-per-link-hash {
class 3
weight 1
}
}
virtual-port "vport-2" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-2" { }
}
lag-per-link-hash {
class 1
weight 5
}
}
virtual-port "vport-3" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-3" { }
}
lag-per-link-hash {
class 1
weight 5
}
}
virtual-port "vport-4" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-4" { }
}
lag-per-link-hash {
class 1
weight 5
}
}
virtual-port "vport-5" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-5" { }
}
lag-per-link-hash {
class 2
weight 15
}
}
virtual-port "vport-6" {
aggregate-rate {
rate 1000000
}
host-match {
int-dest-id "vport-6" { }
}
lag-per-link-hash {
class 2
weight 5
}
}
virtual-port "vport-7" {
aggregate-rate {
rate 1000000
}
host-match {
int-dest-id "vport-7" { }
}
lag-per-link-hash {
class 2
weight 5
}
}
virtual-port "vport-8" {
aggregate-rate {
rate 1000000
}
host-match {
int-dest-id "vport-8" { }
}
lag-per-link-hash {
class 2
weight 5
}
}
virtual-port "vport-9" {
aggregate-rate {
rate 1400000
}
host-match {
int-dest-id "vport-9" { }
}
lag-per-link-hash {
class 3
weight 7
}
}
}
}
egress {
port-scheduler-policy {
policy-name "lag-3-pxc"
}
}
}
}
port-xc {
pxc 1 {
admin-state enable
description "pw-port lag 2,3"
port-id 1/1/c4/2
}
pxc 2 {
admin-state enable
description "pw-port lag 2,3"
port-id 1/1/c4/3
}
}
pw-port 1 {
encap-type qinq
epipe "access" {
admin-state enable
fpe-id 1
}
}
python {
python-script "monitor" {
admin-state enable
urls ["ftp://135.231.216.68/pub/configs/alu/SIMS/ACGs/hashing-per-vport-on-pxc/monitor_lag_sr.py"]
version python3
}
python-script "monitor-sched" {
admin-state enable
urls ["ftp://135.231.216.68/pub/configs/alu/SIMS/ACGs/hashing-per-vport-on-pxc/monitor_lag_port_scheduler_sr.py"]
version python3
}
python-script "monitor-sched-clear" {
admin-state enable
urls ["ftp://135.231.216.68/pub/configs/alu/SIMS/ACGs/hashing-per-vport-on-pxc/monitor_lag_port_scheduler_clear_sr.py"]
version python3
}
}
qos {
sap-egress "sap-egess-1" {
policy-id 2
queue 1 {
port-parent {
}
}
}
port-scheduler-policy "lag-3-pxc" {
}
}
router "Base" {
autonomous-system 64500
router-id 192.0.2.20
interface "int-1-bng-1-p-1" {
port lag-1:1
ipv6 {
address 2001:db8::501 {
prefix-length 120
}
}
}
interface "system" {
ipv4 {
primary {
address 192.0.2.20
prefix-length 32
}
}
ipv6 {
address 2001:db8::14 {
prefix-length 128
}
}
}
interface "to-radius" {
port 1/1/c1/10:114
ipv4 {
primary {
address 192.168.114.20
prefix-length 24
}
}
}
bgp {
admin-state enable
vpn-apply-export true
vpn-apply-import true
rapid-withdrawal true
rapid-update {
evpn true
}
group "evpn" {
peer-as 64500
local-address 2001:db8::14
family {
evpn true
}
}
neighbor "2001:db8::5" {
group "evpn"
}
}
isis 0 {
admin-state enable
advertise-passive-only false
advertise-router-capability area
ipv6-routing native
level-capability 2
traffic-engineering true
area-address [49.0001]
interface "int-1-bng-1-p-1" {
}
interface "system" {
}
}
ldp {
interface-parameters {
interface "int-1-bng-1-p-1" {
ipv6 {
admin-state enable
}
}
}
}
radius {
server "free-radius-1" {
address 192.168.114.2
secret "HDqTwZYSvEu934VNhUQy/pubZxTKpSDzvHg=" hash2
accept-coa true
}
}
}
service {
epipe "access" {
admin-state enable
service-id 1
customer "1"
bgp 1 {
}
bgp-evpn {
evi 10
local-attachment-circuit "bng" {
eth-tag 2
}
remote-attachment-circuit "access" {
eth-tag 1
}
mpls 1 {
admin-state enable
send-tunnel-encap {
mpls-over-udp false
}
auto-bind-tunnel {
resolution any
}
route-next-hop {
system-ipv6
}
}
}
}
vpls "capture-sap" {
admin-state enable
service-id 5
customer "1"
load-balancing {
per-service-hashing true
}
capture-sap pw-1:*.* {
radius-auth-policy "radius-1"
trigger-packet {
dhcp true
}
ipoe-session {
admin-state enable
ipoe-session-policy "ipoe-session-policy-1"
}
}
}
vprn "vport-hashing" {
admin-state enable
service-id 10
customer "1"
interface "loopback-1" {
admin-state enable
loopback true
ipv4 {
local-dhcp-server "dhcpv4"
primary {
address 192.168.0.1
prefix-length 32
}
neighbor-discovery {
local-proxy-arp false
remote-proxy-arp false
}
dhcp {
admin-state enable
}
}
}
interface "to-ixia" {
ipv4 {
primary {
address 172.16.102.1
prefix-length 24
}
}
sap 1/1/c1/7:2 {
}
ipv6 {
address 2001:db8::6601 {
prefix-length 120
}
}
}
ipv6 {
router-advertisement {
interface "to-ixia" {
admin-state enable
max-advertisement-interval 15
min-advertisement-interval 10
}
}
}
dhcp-server {
dhcpv4 "dhcpv4" {
admin-state enable
pool-selection {
use-gi-address {
scope pool
}
use-pool-from-client {
}
}
pool "dhcpv4-1" {
max-lease-time 1200
subnet 10.10.0.0/24 {
address-range 10.10.0.10 end 10.10.0.100 {
failover-control-type access-driven
}
}
}
}
}
subscriber-interface "sub-int-1" {
admin-state enable
ipv4 {
address 10.10.0.254 {
prefix-length 24
}
}
group-interface "group-int-1" {
admin-state enable
radius-auth-policy "radius-1"
oper-up-while-empty true
ipv4 {
neighbor-discovery {
remote-proxy-arp true
populate false
}
dhcp {
admin-state enable
server [192.168.0.1]
trusted true
gi-address 10.10.0.254
match-circuit-id true
option-82 {
action keep
vendor-specific-option {
pool-name true
}
}
lease-populate {
max-leases 100
}
client-applications {
dhcp true
}
}
}
ipoe-session {
admin-state enable
ipoe-session-policy "ipoe-session-policy-1"
sap-session-limit 100
force-auth {
cid-change false
rid-change false
}
}
}
}
}
}
sfm 1 {
sfm-type m-sfm6-7/12
}
subscriber-mgmt {
ipoe-session-policy "ipoe-session-policy-1" {
}
sub-profile "sub-profile-1" {
egress {
qos {
agg-rate {
rate 1000
}
}
}
}
sla-profile "sla-profile-1" {
egress {
qos {
sap-egress {
policy-name "sap-egess-1"
port-parent-location vport
overrides {
queue 1 {
stat-mode v4-v6
}
}
}
}
}
}
sub-ident-policy "sub-ident-policy-1" {
sla-profile-map {
use-direct-map-as-default true
}
sub-profile-map {
use-direct-map-as-default true
}
}
radius-authentication-policy "radius-1" {
password "ncd8qyrNUMhYfa2SfrUqHMDZ9IXn3sVSmYBzbw==" hash2
pppoe-access-method pap-chap
radius-server-policy "radius-server-1"
user-name {
format circuit-id
}
include-radius-attribute {
circuit-id true
nas-identifier true
}
}
msap-policy "msap-policy-1" {
sub-sla-mgmt {
subscriber-limit 1
sub-ident-policy "sub-ident-policy-1"
defaults {
subscriber-id {
sap-id
}
}
single-sub-parameters {
profiled-traffic-only true
}
}
ies-vprn-only-sap-parameters {
anti-spoof next-hop-ip-and-mac-addr
ingress {
qos {
queuing-type service
}
}
}
}
}
system {
name "bng-1"
management-interface {
configuration-mode model-driven
cli {
cli-engine [md-cli classic-cli]
md-cli {
environment {
more false
command-alias {
alias "monitor-lag" {
admin-state enable
python-script "monitor"
mount-point global { }
}
alias "monitor-schd-clear" {
admin-state enable
python-script "monitor-sched-clear"
mount-point global { }
}
alias "monitor-scheduler" {
admin-state enable
python-script "monitor-sched"
mount-point global { }
}
}
}
}
}
netconf {
admin-state enable
}
yang-modules {
nokia-submodules false
nokia-combined-modules true
}
snmp {
admin-state disable
}
}
login-control {
idle-timeout none
}
security {
aaa {
local-profiles {
profile "administrative" {
default-action permit-all
entry 10 {
match "configure system security"
action permit
}
entry 20 {
match "show system security"
action permit
}
entry 30 {
match "tools perform security"
action permit
}
entry 40 {
match "tools dump security"
action permit
}
entry 50 {
match "admin system security"
action permit
}
entry 100 {
match "configure li"
action deny
}
entry 110 {
match "show li"
action deny
}
entry 111 {
match "clear li"
action deny
}
entry 112 {
match "tools dump li"
action deny
}
netconf {
base-op-authorization {
action true
cancel-commit true
close-session true
commit true
copy-config true
create-subscription true
delete-config true
discard-changes true
edit-config true
get true
get-config true
get-data true
get-schema true
kill-session true
lock true
validate true
}
}
}
profile "default" {
entry 10 {
match "exec"
action permit
}
entry 20 {
match "exit"
action permit
}
entry 30 {
match "help"
action permit
}
entry 40 {
match "logout"
action permit
}
entry 50 {
match "password"
action permit
}
entry 60 {
match "show config"
action deny
}
entry 65 {
match "show li"
action deny
}
entry 66 {
match "clear li"
action deny
}
entry 67 {
match "tools dump li"
action deny
}
entry 68 {
match "state li"
action deny
}
entry 70 {
match "show"
action permit
}
entry 75 {
match "state"
action permit
}
entry 80 {
match "enable-admin"
action permit
}
entry 90 {
match "enable"
action permit
}
entry 100 {
match "configure li"
action deny
}
}
}
}
ssh {
server-admin-state enable
server-cipher-list-v2 {
cipher 190 {
name aes256-ctr
}
cipher 192 {
name aes192-ctr
}
cipher 194 {
name aes128-ctr
}
cipher 200 {
name aes128-cbc
}
cipher 205 {
name 3des-cbc
}
cipher 225 {
name aes192-cbc
}
cipher 230 {
name aes256-cbc
}
}
client-cipher-list-v2 {
cipher 190 {
name aes256-ctr
}
cipher 192 {
name aes192-ctr
}
cipher 194 {
name aes128-ctr
}
cipher 200 {
name aes128-cbc
}
cipher 205 {
name 3des-cbc
}
cipher 225 {
name aes192-cbc
}
cipher 230 {
name aes256-cbc
}
}
server-mac-list-v2 {
mac 200 {
name hmac-sha2-512
}
mac 210 {
name hmac-sha2-256
}
mac 215 {
name hmac-sha1
}
mac 220 {
name hmac-sha1-96
}
mac 225 {
name hmac-md5
}
mac 240 {
name hmac-md5-96
}
}
client-mac-list-v2 {
mac 200 {
name hmac-sha2-512
}
mac 210 {
name hmac-sha2-256
}
mac 215 {
name hmac-sha1
}
mac 220 {
name hmac-sha1-96
}
mac 225 {
name hmac-md5
}
mac 240 {
name hmac-md5-96
}
}
}
user-params {
local-user {
user "admin" {
password "$2y$10$TQrZlpBDra86.qoexZUzQeBXDY1FcdDhGWdD9lLxMuFyPVSm0OGy6"
access {
console true
netconf true
}
console {
member ["administrative"]
}
}
}
}
}
time {
prefer-local-time true
zone {
standard {
name cst
}
}
dst-zone "CDT" {
end {
day sunday
month november
hours-minutes "02:00"
}
start {
day sunday
month march
hours-minutes "02:00"
}
}
sntp {
admin-state enable
server 135.227.160.253 {
}
}
}
}
}
# Finished 2022-12-14T13:31:35.4-06:00
bng-per-vport-balancing-wo-classes-weights
# TiMOS-C-22.10.R1 cpm/x86_64 Nokia 7750 SR Copyright (c) 2000-2022 Nokia.
# All rights reserved. All use subject to applicable license agreements.
# Built on Sun Oct 30 14:49:55 PDT 2022 by builder in /builds/c/2210B/R1/panos/main/sros
# Configuration format version 22.10 revision 0
# Generated 2022-12-14T13:38:31.1-06:00 by admin from 135.231.208.32
# Commit ID 3
# Committed 2022-12-14T13:33:11.3-06:00 by admin (MD-CLI) from 135.231.208.32
configure {
aaa {
radius {
server-policy "radius-server-1" {
servers {
router-instance "Base"
server 1 {
server-name "free-radius-1"
}
}
}
}
}
card 1 {
card-type iom5-e
mda 1 {
mda-type me6-100gb-qsfp28
}
mda 2 {
mda-type me6-100gb-qsfp28
}
}
fwd-path-ext {
sdp-id-range {
start 17500
end 17600
}
fpe 1 {
description "pw-port on a lag"
path {
xc-lag-a "lag-2"
xc-lag-b "lag-3"
}
application {
pw-port-extension {
}
}
}
}
lag "lag-1" {
admin-state enable
description "lag to p-1"
mode hybrid
max-ports 64
port 1/1/c1/1 {
}
port 1/1/c1/2 {
}
}
lag "lag-2" {
admin-state enable
description "fpe pw-port pxc lag - transit side"
mode hybrid
max-ports 64
port pxc-1.a {
}
port pxc-2.a {
}
}
lag "lag-3" {
admin-state enable
description "fpe pw-port pxc lag - termination side"
mode hybrid
max-ports 64
access {
per-fp-ing-queuing true
per-fp-egr-queuing true
per-fp-sap-instance true
adapt-qos {
mode link
}
}
per-link-hash {
weighted {
subscriber-hash-mode vport
}
}
port pxc-1.b {
}
port pxc-2.b {
}
}
log {
filter "1001" {
named-entry "10" {
description "Collect only events of major severity or higher"
action forward
match {
severity {
gte major
}
}
}
}
log-id "100" {
description "Default Serious Errors Log"
filter "1001"
source {
main true
}
destination {
memory {
max-entries 500
}
}
}
log-id "99" {
description "Default System Log"
source {
main true
}
destination {
memory {
max-entries 500
}
}
}
}
port 1/1/c1 {
admin-state enable
connector {
breakout c10-10g
}
}
port 1/1/c1/1 {
admin-state enable
description "lag-1 to p-1 access"
ethernet {
mode hybrid
}
}
port 1/1/c1/2 {
admin-state enable
description "lag-1 to p-1 access"
ethernet {
mode hybrid
}
}
port 1/1/c1/3 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/4 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/5 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/6 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/7 {
admin-state enable
description "to pe-2 network"
ethernet {
mode hybrid
}
}
port 1/1/c1/8 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/9 {
admin-state enable
ethernet {
mode hybrid
dot1x {
tunneling true
}
}
}
port 1/1/c1/10 {
admin-state enable
description "RADIUS and mirroring"
ethernet {
mode hybrid
}
}
port 1/1/c2 {
admin-state enable
connector {
breakout c1-100g
}
}
port 1/1/c2/1 {
admin-state enable
ethernet {
mode hybrid
encap-type dot1q
dot1x {
tunneling true
}
}
}
port 1/1/c4 {
admin-state enable
connector {
breakout c4-10g
}
}
port 1/1/c4/1 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c4/2 {
admin-state enable
description "PXC 1; pw-port lag 2,3"
ethernet {
mode hybrid
dot1x {
tunneling true
}
}
}
port 1/1/c4/3 {
admin-state enable
description "PXC 2; pw-port lag 2,3"
ethernet {
mode hybrid
dot1x {
tunneling true
}
}
}
port 1/1/c4/4 {
admin-state enable
ethernet {
mode hybrid
}
}
port pxc-1.a {
admin-state enable
}
port pxc-1.b {
admin-state enable
description "PXC lag-3, pw-port termination"
ethernet {
access {
egress {
virtual-port "vport-1" {
aggregate-rate {
rate 9000000
}
host-match {
int-dest-id "vport-1" { }
}
}
virtual-port "vport-10" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-10" { }
}
}
virtual-port "vport-11" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-11" { }
}
}
virtual-port "vport-12" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-12" { }
}
}
virtual-port "vport-13" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-13" { }
}
}
virtual-port "vport-14" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-14" { }
}
}
virtual-port "vport-15" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-15" { }
}
}
virtual-port "vport-16" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-16" { }
}
}
virtual-port "vport-2" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-2" { }
}
}
virtual-port "vport-3" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-3" { }
}
}
virtual-port "vport-4" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-4" { }
}
}
virtual-port "vport-5" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-5" { }
}
}
virtual-port "vport-6" {
aggregate-rate {
rate 1000000
}
host-match {
int-dest-id "vport-6" { }
}
}
virtual-port "vport-7" {
aggregate-rate {
rate 1000000
}
host-match {
int-dest-id "vport-7" { }
}
}
virtual-port "vport-8" {
aggregate-rate {
rate 1000000
}
host-match {
int-dest-id "vport-8" { }
}
}
virtual-port "vport-9" {
aggregate-rate {
rate 1400000
}
host-match {
int-dest-id "vport-9" { }
}
}
}
}
egress {
port-scheduler-policy {
policy-name "lag-3-pxc"
}
}
}
}
port pxc-2.a {
admin-state enable
}
port pxc-2.b {
admin-state enable
description "PXC lag-3, pw-port termination"
ethernet {
access {
egress {
virtual-port "vport-1" {
aggregate-rate {
rate 9000000
}
host-match {
int-dest-id "vport-1" { }
}
}
virtual-port "vport-10" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-10" { }
}
}
virtual-port "vport-11" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-11" { }
}
}
virtual-port "vport-12" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-12" { }
}
}
virtual-port "vport-13" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-13" { }
}
}
virtual-port "vport-14" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-14" { }
}
}
virtual-port "vport-15" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-15" { }
}
}
virtual-port "vport-16" {
aggregate-rate {
rate 200000
}
host-match {
int-dest-id "vport-16" { }
}
}
virtual-port "vport-2" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-2" { }
}
}
virtual-port "vport-3" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-3" { }
}
}
virtual-port "vport-4" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-4" { }
}
}
virtual-port "vport-5" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-5" { }
}
}
virtual-port "vport-6" {
aggregate-rate {
rate 1000000
}
host-match {
int-dest-id "vport-6" { }
}
}
virtual-port "vport-7" {
aggregate-rate {
rate 1000000
}
host-match {
int-dest-id "vport-7" { }
}
}
virtual-port "vport-8" {
aggregate-rate {
rate 1000000
}
host-match {
int-dest-id "vport-8" { }
}
}
virtual-port "vport-9" {
aggregate-rate {
rate 1400000
}
host-match {
int-dest-id "vport-9" { }
}
}
}
}
egress {
port-scheduler-policy {
policy-name "lag-3-pxc"
}
}
}
}
port-xc {
pxc 1 {
admin-state enable
description "pw-port lag 2,3"
port-id 1/1/c4/2
}
pxc 2 {
admin-state enable
description "pw-port lag 2,3"
port-id 1/1/c4/3
}
}
pw-port 1 {
encap-type qinq
epipe "access" {
admin-state enable
fpe-id 1
}
}
python {
python-script "monitor" {
admin-state enable
urls ["ftp://135.231.216.68/pub/configs/alu/SIMS/ACGs/hashing-per-vport-on-pxc/monitor_lag_sr.py"]
version python3
}
python-script "monitor-sched" {
admin-state enable
urls ["ftp://135.231.216.68/pub/configs/alu/SIMS/ACGs/hashing-per-vport-on-pxc/monitor_lag_port_scheduler_sr.py"]
version python3
}
python-script "monitor-sched-clear" {
admin-state enable
urls ["ftp://135.231.216.68/pub/configs/alu/SIMS/ACGs/hashing-per-vport-on-pxc/monitor_lag_port_scheduler_clear_sr.py"]
version python3
}
}
qos {
sap-egress "sap-egess-1" {
policy-id 2
queue 1 {
port-parent {
}
}
}
port-scheduler-policy "lag-3-pxc" {
}
}
router "Base" {
autonomous-system 64500
router-id 192.0.2.20
interface "int-1-bng-1-p-1" {
port lag-1:1
ipv6 {
address 2001:db8::501 {
prefix-length 120
}
}
}
interface "system" {
ipv4 {
primary {
address 192.0.2.20
prefix-length 32
}
}
ipv6 {
address 2001:db8::14 {
prefix-length 128
}
}
}
interface "to-radius" {
port 1/1/c1/10:114
ipv4 {
primary {
address 192.168.114.20
prefix-length 24
}
}
}
bgp {
admin-state enable
vpn-apply-export true
vpn-apply-import true
rapid-withdrawal true
rapid-update {
evpn true
}
group "evpn" {
peer-as 64500
local-address 2001:db8::14
family {
evpn true
}
}
neighbor "2001:db8::5" {
group "evpn"
}
}
isis 0 {
admin-state enable
advertise-passive-only false
advertise-router-capability area
ipv6-routing native
level-capability 2
traffic-engineering true
area-address [49.0001]
interface "int-1-bng-1-p-1" {
}
interface "system" {
}
}
ldp {
interface-parameters {
interface "int-1-bng-1-p-1" {
ipv6 {
admin-state enable
}
}
}
}
radius {
server "free-radius-1" {
address 192.168.114.2
secret "HDqTwZYSvEu934VNhUQy/pubZxTKpSDzvHg=" hash2
accept-coa true
}
}
}
service {
epipe "access" {
admin-state enable
service-id 1
customer "1"
bgp 1 {
}
bgp-evpn {
evi 10
local-attachment-circuit "bng" {
eth-tag 2
}
remote-attachment-circuit "access" {
eth-tag 1
}
mpls 1 {
admin-state enable
send-tunnel-encap {
mpls-over-udp false
}
auto-bind-tunnel {
resolution any
}
route-next-hop {
system-ipv6
}
}
}
}
vpls "capture-sap" {
admin-state enable
service-id 5
customer "1"
load-balancing {
per-service-hashing true
}
capture-sap pw-1:*.* {
radius-auth-policy "radius-1"
trigger-packet {
dhcp true
}
ipoe-session {
admin-state enable
ipoe-session-policy "ipoe-session-policy-1"
}
}
}
vprn "vport-hashing" {
admin-state enable
service-id 10
customer "1"
interface "loopback-1" {
admin-state enable
loopback true
ipv4 {
local-dhcp-server "dhcpv4"
primary {
address 192.168.0.1
prefix-length 32
}
neighbor-discovery {
local-proxy-arp false
remote-proxy-arp false
}
dhcp {
admin-state enable
}
}
}
interface "to-ixia" {
ipv4 {
primary {
address 172.16.102.1
prefix-length 24
}
}
sap 1/1/c1/7:2 {
}
ipv6 {
address 2001:db8::6601 {
prefix-length 120
}
}
}
ipv6 {
router-advertisement {
interface "to-ixia" {
admin-state enable
max-advertisement-interval 15
min-advertisement-interval 10
}
}
}
dhcp-server {
dhcpv4 "dhcpv4" {
admin-state enable
pool-selection {
use-gi-address {
scope pool
}
use-pool-from-client {
}
}
pool "dhcpv4-1" {
max-lease-time 1200
subnet 10.10.0.0/24 {
address-range 10.10.0.10 end 10.10.0.100 {
failover-control-type access-driven
}
}
}
}
}
subscriber-interface "sub-int-1" {
admin-state enable
ipv4 {
address 10.10.0.254 {
prefix-length 24
}
}
group-interface "group-int-1" {
admin-state enable
radius-auth-policy "radius-1"
oper-up-while-empty true
ipv4 {
neighbor-discovery {
remote-proxy-arp true
populate false
}
dhcp {
admin-state enable
server [192.168.0.1]
trusted true
gi-address 10.10.0.254
match-circuit-id true
option-82 {
action keep
vendor-specific-option {
pool-name true
}
}
lease-populate {
max-leases 100
}
client-applications {
dhcp true
}
}
}
ipoe-session {
admin-state enable
ipoe-session-policy "ipoe-session-policy-1"
sap-session-limit 100
force-auth {
cid-change false
rid-change false
}
}
}
}
}
}
sfm 1 {
sfm-type m-sfm6-7/12
}
subscriber-mgmt {
ipoe-session-policy "ipoe-session-policy-1" {
}
sub-profile "sub-profile-1" {
egress {
qos {
agg-rate {
rate 1000
}
}
}
}
sla-profile "sla-profile-1" {
egress {
qos {
sap-egress {
policy-name "sap-egess-1"
port-parent-location vport
overrides {
queue 1 {
stat-mode v4-v6
}
}
}
}
}
}
sub-ident-policy "sub-ident-policy-1" {
sla-profile-map {
use-direct-map-as-default true
}
sub-profile-map {
use-direct-map-as-default true
}
}
radius-authentication-policy "radius-1" {
password "ncd8qyrNUMhYfa2SfrUqHMDZ9IXn3sVSmYBzbw==" hash2
pppoe-access-method pap-chap
radius-server-policy "radius-server-1"
user-name {
format circuit-id
}
include-radius-attribute {
circuit-id true
nas-identifier true
}
}
msap-policy "msap-policy-1" {
sub-sla-mgmt {
subscriber-limit 1
sub-ident-policy "sub-ident-policy-1"
defaults {
subscriber-id {
sap-id
}
}
single-sub-parameters {
profiled-traffic-only true
}
}
ies-vprn-only-sap-parameters {
anti-spoof next-hop-ip-and-mac-addr
ingress {
qos {
queuing-type service
}
}
}
}
}
system {
name "bng-1"
management-interface {
configuration-mode model-driven
cli {
cli-engine [md-cli classic-cli]
md-cli {
environment {
more false
command-alias {
alias "monitor-lag" {
admin-state enable
python-script "monitor"
mount-point global { }
}
alias "monitor-schd-clear" {
admin-state enable
python-script "monitor-sched-clear"
mount-point global { }
}
alias "monitor-scheduler" {
admin-state enable
python-script "monitor-sched"
mount-point global { }
}
}
}
}
}
netconf {
admin-state enable
}
yang-modules {
nokia-submodules false
nokia-combined-modules true
}
snmp {
admin-state disable
}
}
login-control {
idle-timeout none
}
security {
aaa {
local-profiles {
profile "administrative" {
default-action permit-all
entry 10 {
match "configure system security"
action permit
}
entry 20 {
match "show system security"
action permit
}
entry 30 {
match "tools perform security"
action permit
}
entry 40 {
match "tools dump security"
action permit
}
entry 50 {
match "admin system security"
action permit
}
entry 100 {
match "configure li"
action deny
}
entry 110 {
match "show li"
action deny
}
entry 111 {
match "clear li"
action deny
}
entry 112 {
match "tools dump li"
action deny
}
netconf {
base-op-authorization {
action true
cancel-commit true
close-session true
commit true
copy-config true
create-subscription true
delete-config true
discard-changes true
edit-config true
get true
get-config true
get-data true
get-schema true
kill-session true
lock true
validate true
}
}
}
profile "default" {
entry 10 {
match "exec"
action permit
}
entry 20 {
match "exit"
action permit
}
entry 30 {
match "help"
action permit
}
entry 40 {
match "logout"
action permit
}
entry 50 {
match "password"
action permit
}
entry 60 {
match "show config"
action deny
}
entry 65 {
match "show li"
action deny
}
entry 66 {
match "clear li"
action deny
}
entry 67 {
match "tools dump li"
action deny
}
entry 68 {
match "state li"
action deny
}
entry 70 {
match "show"
action permit
}
entry 75 {
match "state"
action permit
}
entry 80 {
match "enable-admin"
action permit
}
entry 90 {
match "enable"
action permit
}
entry 100 {
match "configure li"
action deny
}
}
}
}
ssh {
server-admin-state enable
server-cipher-list-v2 {
cipher 190 {
name aes256-ctr
}
cipher 192 {
name aes192-ctr
}
cipher 194 {
name aes128-ctr
}
cipher 200 {
name aes128-cbc
}
cipher 205 {
name 3des-cbc
}
cipher 225 {
name aes192-cbc
}
cipher 230 {
name aes256-cbc
}
}
client-cipher-list-v2 {
cipher 190 {
name aes256-ctr
}
cipher 192 {
name aes192-ctr
}
cipher 194 {
name aes128-ctr
}
cipher 200 {
name aes128-cbc
}
cipher 205 {
name 3des-cbc
}
cipher 225 {
name aes192-cbc
}
cipher 230 {
name aes256-cbc
}
}
server-mac-list-v2 {
mac 200 {
name hmac-sha2-512
}
mac 210 {
name hmac-sha2-256
}
mac 215 {
name hmac-sha1
}
mac 220 {
name hmac-sha1-96
}
mac 225 {
name hmac-md5
}
mac 240 {
name hmac-md5-96
}
}
client-mac-list-v2 {
mac 200 {
name hmac-sha2-512
}
mac 210 {
name hmac-sha2-256
}
mac 215 {
name hmac-sha1
}
mac 220 {
name hmac-sha1-96
}
mac 225 {
name hmac-md5
}
mac 240 {
name hmac-md5-96
}
}
}
user-params {
local-user {
user "admin" {
password "$2y$10$TQrZlpBDra86.qoexZUzQeBXDY1FcdDhGWdD9lLxMuFyPVSm0OGy6"
access {
console true
netconf true
}
console {
member ["administrative"]
}
}
}
}
}
time {
prefer-local-time true
zone {
standard {
name cst
}
}
dst-zone "CDT" {
end {
day sunday
month november
hours-minutes "02:00"
}
start {
day sunday
month march
hours-minutes "02:00"
}
}
sntp {
admin-state enable
server 135.227.160.253 {
}
}
}
}
}
# Finished 2022-12-14T13:38:31.1-06:00
bng-vport-per-subscriber-balancing
# TiMOS-C-22.10.R1 cpm/x86_64 Nokia 7750 SR Copyright (c) 2000-2022 Nokia.
# All rights reserved. All use subject to applicable license agreements.
# Built on Sun Oct 30 14:49:55 PDT 2022 by builder in /builds/c/2210B/R1/panos/main/sros
# Configuration format version 22.10 revision 0
# Generated 2022-12-14T13:42:02.4-06:00 by admin from 135.231.208.32
# Commit ID 5
# Committed 2022-12-14T13:41:47.9-06:00 by admin (MD-CLI) from 135.231.208.32
# Commit ID 4
# Committed 2022-12-14T13:41:11.6-06:00 by admin (MD-CLI) from 135.231.208.32
# Commit ID 3
# Committed 2022-12-14T13:33:11.3-06:00 by admin (MD-CLI) from 135.231.208.32
configure {
aaa {
radius {
server-policy "radius-server-1" {
servers {
router-instance "Base"
server 1 {
server-name "free-radius-1"
}
}
}
}
}
card 1 {
card-type iom5-e
mda 1 {
mda-type me6-100gb-qsfp28
}
mda 2 {
mda-type me6-100gb-qsfp28
}
}
fwd-path-ext {
sdp-id-range {
start 17500
end 17600
}
fpe 1 {
description "pw-port on a lag"
path {
xc-lag-a "lag-2"
xc-lag-b "lag-3"
}
application {
pw-port-extension {
}
}
}
}
lag "lag-1" {
admin-state enable
description "lag to p-1"
mode hybrid
max-ports 64
port 1/1/c1/1 {
}
port 1/1/c1/2 {
}
}
lag "lag-2" {
admin-state enable
description "fpe pw-port pxc lag - transit side"
mode hybrid
max-ports 64
port pxc-1.a {
}
port pxc-2.a {
}
}
lag "lag-3" {
admin-state enable
description "fpe pw-port pxc lag - termination side"
mode hybrid
max-ports 64
access {
per-fp-ing-queuing false
per-fp-egr-queuing false
per-fp-sap-instance false
adapt-qos {
mode port-fair
}
}
port pxc-1.b {
}
port pxc-2.b {
}
}
log {
filter "1001" {
named-entry "10" {
description "Collect only events of major severity or higher"
action forward
match {
severity {
gte major
}
}
}
}
log-id "100" {
description "Default Serious Errors Log"
filter "1001"
source {
main true
}
destination {
memory {
max-entries 500
}
}
}
log-id "99" {
description "Default System Log"
source {
main true
}
destination {
memory {
max-entries 500
}
}
}
}
port 1/1/c1 {
admin-state enable
connector {
breakout c10-10g
}
}
port 1/1/c1/1 {
admin-state enable
description "lag-1 to p-1 access"
ethernet {
mode hybrid
}
}
port 1/1/c1/2 {
admin-state enable
description "lag-1 to p-1 access"
ethernet {
mode hybrid
}
}
port 1/1/c1/3 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/4 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/5 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/6 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/7 {
admin-state enable
description "to pe-2 network"
ethernet {
mode hybrid
}
}
port 1/1/c1/8 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c1/9 {
admin-state enable
ethernet {
mode hybrid
dot1x {
tunneling true
}
}
}
port 1/1/c1/10 {
admin-state enable
description "RADIUS and mirroring"
ethernet {
mode hybrid
}
}
port 1/1/c2 {
admin-state enable
connector {
breakout c1-100g
}
}
port 1/1/c2/1 {
admin-state enable
ethernet {
mode hybrid
encap-type dot1q
dot1x {
tunneling true
}
}
}
port 1/1/c4 {
admin-state enable
connector {
breakout c4-10g
}
}
port 1/1/c4/1 {
admin-state enable
ethernet {
mode hybrid
}
}
port 1/1/c4/2 {
admin-state enable
description "PXC 1; pw-port lag 2,3"
ethernet {
mode hybrid
dot1x {
tunneling true
}
}
}
port 1/1/c4/3 {
admin-state enable
description "PXC 2; pw-port lag 2,3"
ethernet {
mode hybrid
dot1x {
tunneling true
}
}
}
port 1/1/c4/4 {
admin-state enable
ethernet {
mode hybrid
}
}
port pxc-1.a {
admin-state enable
}
port pxc-1.b {
admin-state enable
description "PXC lag-3, pw-port termination"
ethernet {
access {
egress {
virtual-port "vport-1" {
aggregate-rate {
rate 1500000
}
host-match {
int-dest-id "vport-1" { }
}
}
virtual-port "vport-10" {
aggregate-rate {
rate 9000000
}
host-match {
int-dest-id "vport-10" { }
}
}
virtual-port "vport-11" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-11" { }
}
}
virtual-port "vport-12" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-12" { }
}
}
virtual-port "vport-13" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-13" { }
}
}
virtual-port "vport-14" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-14" { }
}
}
virtual-port "vport-15" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-15" { }
}
}
virtual-port "vport-16" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-16" { }
}
}
virtual-port "vport-2" {
aggregate-rate {
rate 500000
}
host-match {
int-dest-id "vport-2" { }
}
}
virtual-port "vport-3" {
aggregate-rate {
rate 500000
}
host-match {
int-dest-id "vport-3" { }
}
}
virtual-port "vport-4" {
aggregate-rate {
rate 500000
}
host-match {
int-dest-id "vport-4" { }
}
}
virtual-port "vport-5" {
aggregate-rate {
rate 4500000
}
host-match {
int-dest-id "vport-5" { }
}
}
virtual-port "vport-6" {
aggregate-rate {
rate 1500000
}
host-match {
int-dest-id "vport-6" { }
}
}
virtual-port "vport-7" {
aggregate-rate {
rate 1500000
}
host-match {
int-dest-id "vport-7" { }
}
}
virtual-port "vport-8" {
aggregate-rate {
rate 1500000
}
host-match {
int-dest-id "vport-8" { }
}
}
virtual-port "vport-9" {
aggregate-rate {
rate 9000000
}
host-match {
int-dest-id "vport-9" { }
}
}
}
}
egress {
port-scheduler-policy {
policy-name "lag-3-pxc"
}
}
}
}
port pxc-2.a {
admin-state enable
}
port pxc-2.b {
admin-state enable
description "PXC lag-3, pw-port termination"
ethernet {
access {
egress {
virtual-port "vport-1" {
aggregate-rate {
rate 1500000
}
host-match {
int-dest-id "vport-1" { }
}
}
virtual-port "vport-10" {
aggregate-rate {
rate 9000000
}
host-match {
int-dest-id "vport-10" { }
}
}
virtual-port "vport-11" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-11" { }
}
}
virtual-port "vport-12" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-12" { }
}
}
virtual-port "vport-13" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-13" { }
}
}
virtual-port "vport-14" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-14" { }
}
}
virtual-port "vport-15" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-15" { }
}
}
virtual-port "vport-16" {
aggregate-rate {
rate 3000000
}
host-match {
int-dest-id "vport-16" { }
}
}
virtual-port "vport-2" {
aggregate-rate {
rate 500000
}
host-match {
int-dest-id "vport-2" { }
}
}
virtual-port "vport-3" {
aggregate-rate {
rate 500000
}
host-match {
int-dest-id "vport-3" { }
}
}
virtual-port "vport-4" {
aggregate-rate {
rate 500000
}
host-match {
int-dest-id "vport-4" { }
}
}
virtual-port "vport-5" {
aggregate-rate {
rate 4500000
}
host-match {
int-dest-id "vport-5" { }
}
}
virtual-port "vport-6" {
aggregate-rate {
rate 1500000
}
host-match {
int-dest-id "vport-6" { }
}
}
virtual-port "vport-7" {
aggregate-rate {
rate 1500000
}
host-match {
int-dest-id "vport-7" { }
}
}
virtual-port "vport-8" {
aggregate-rate {
rate 1500000
}
host-match {
int-dest-id "vport-8" { }
}
}
virtual-port "vport-9" {
aggregate-rate {
rate 9000000
}
host-match {
int-dest-id "vport-9" { }
}
}
}
}
egress {
port-scheduler-policy {
policy-name "lag-3-pxc"
}
}
}
}
port-xc {
pxc 1 {
admin-state enable
description "pw-port lag 2,3"
port-id 1/1/c4/2
}
pxc 2 {
admin-state enable
description "pw-port lag 2,3"
port-id 1/1/c4/3
}
}
pw-port 1 {
encap-type qinq
epipe "access" {
admin-state enable
fpe-id 1
}
}
python {
python-script "monitor" {
admin-state enable
urls ["ftp://135.231.216.68/pub/configs/alu/SIMS/ACGs/hashing-per-vport-on-pxc/monitor_lag_sr.py"]
version python3
}
python-script "monitor-sched" {
admin-state enable
urls ["ftp://135.231.216.68/pub/configs/alu/SIMS/ACGs/hashing-per-vport-on-pxc/monitor_lag_port_scheduler_sr.py"]
version python3
}
python-script "monitor-sched-clear" {
admin-state enable
urls ["ftp://135.231.216.68/pub/configs/alu/SIMS/ACGs/hashing-per-vport-on-pxc/monitor_lag_port_scheduler_clear_sr.py"]
version python3
}
}
qos {
sap-egress "sap-egess-1" {
policy-id 2
queue 1 {
port-parent {
}
}
}
port-scheduler-policy "lag-3-pxc" {
}
}
router "Base" {
autonomous-system 64500
router-id 192.0.2.20
interface "int-1-bng-1-p-1" {
port lag-1:1
ipv6 {
address 2001:db8::501 {
prefix-length 120
}
}
}
interface "system" {
ipv4 {
primary {
address 192.0.2.20
prefix-length 32
}
}
ipv6 {
address 2001:db8::14 {
prefix-length 128
}
}
}
interface "to-radius" {
port 1/1/c1/10:114
ipv4 {
primary {
address 192.168.114.20
prefix-length 24
}
}
}
bgp {
admin-state enable
vpn-apply-export true
vpn-apply-import true
rapid-withdrawal true
rapid-update {
evpn true
}
group "evpn" {
peer-as 64500
local-address 2001:db8::14
family {
evpn true
}
}
neighbor "2001:db8::5" {
group "evpn"
}
}
isis 0 {
admin-state enable
advertise-passive-only false
advertise-router-capability area
ipv6-routing native
level-capability 2
traffic-engineering true
area-address [49.0001]
interface "int-1-bng-1-p-1" {
}
interface "system" {
}
}
ldp {
interface-parameters {
interface "int-1-bng-1-p-1" {
ipv6 {
admin-state enable
}
}
}
}
radius {
server "free-radius-1" {
address 192.168.114.2
secret "HDqTwZYSvEu934VNhUQy/pubZxTKpSDzvHg=" hash2
accept-coa true
}
}
}
service {
epipe "access" {
admin-state enable
service-id 1
customer "1"
bgp 1 {
}
bgp-evpn {
evi 10
local-attachment-circuit "bng" {
eth-tag 2
}
remote-attachment-circuit "access" {
eth-tag 1
}
mpls 1 {
admin-state enable
send-tunnel-encap {
mpls-over-udp false
}
auto-bind-tunnel {
resolution any
}
route-next-hop {
system-ipv6
}
}
}
}
vpls "capture-sap" {
admin-state enable
service-id 5
customer "1"
load-balancing {
per-service-hashing true
}
capture-sap pw-1:*.* {
radius-auth-policy "radius-1"
trigger-packet {
dhcp true
}
ipoe-session {
admin-state enable
ipoe-session-policy "ipoe-session-policy-1"
}
}
}
vprn "vport-hashing" {
admin-state enable
service-id 10
customer "1"
interface "loopback-1" {
admin-state enable
loopback true
ipv4 {
local-dhcp-server "dhcpv4"
primary {
address 192.168.0.1
prefix-length 32
}
neighbor-discovery {
local-proxy-arp false
remote-proxy-arp false
}
dhcp {
admin-state enable
}
}
}
interface "to-ixia" {
ipv4 {
primary {
address 172.16.102.1
prefix-length 24
}
}
sap 1/1/c1/7:2 {
}
ipv6 {
address 2001:db8::6601 {
prefix-length 120
}
}
}
ipv6 {
router-advertisement {
interface "to-ixia" {
admin-state enable
max-advertisement-interval 15
min-advertisement-interval 10
}
}
}
dhcp-server {
dhcpv4 "dhcpv4" {
admin-state enable
pool-selection {
use-gi-address {
scope pool
}
use-pool-from-client {
}
}
pool "dhcpv4-1" {
max-lease-time 1200
subnet 10.10.0.0/24 {
address-range 10.10.0.10 end 10.10.0.100 {
failover-control-type access-driven
}
}
}
}
}
subscriber-interface "sub-int-1" {
admin-state enable
ipv4 {
address 10.10.0.254 {
prefix-length 24
}
}
group-interface "group-int-1" {
admin-state enable
radius-auth-policy "radius-1"
oper-up-while-empty true
ipv4 {
neighbor-discovery {
remote-proxy-arp true
populate false
}
dhcp {
admin-state enable
server [192.168.0.1]
trusted true
gi-address 10.10.0.254
match-circuit-id true
option-82 {
action keep
vendor-specific-option {
pool-name true
}
}
lease-populate {
max-leases 100
}
client-applications {
dhcp true
}
}
}
ipoe-session {
admin-state enable
ipoe-session-policy "ipoe-session-policy-1"
sap-session-limit 100
force-auth {
cid-change false
rid-change false
}
}
}
}
}
}
sfm 1 {
sfm-type m-sfm6-7/12
}
subscriber-mgmt {
ipoe-session-policy "ipoe-session-policy-1" {
}
sub-profile "sub-profile-1" {
egress {
qos {
agg-rate {
rate 1000
}
}
}
}
sla-profile "sla-profile-1" {
egress {
qos {
sap-egress {
policy-name "sap-egess-1"
port-parent-location vport
overrides {
queue 1 {
stat-mode v4-v6
}
}
}
}
}
}
sub-ident-policy "sub-ident-policy-1" {
sla-profile-map {
use-direct-map-as-default true
}
sub-profile-map {
use-direct-map-as-default true
}
}
radius-authentication-policy "radius-1" {
password "ncd8qyrNUMhYfa2SfrUqHMDZ9IXn3sVSmYBzbw==" hash2
pppoe-access-method pap-chap
radius-server-policy "radius-server-1"
user-name {
format circuit-id
}
include-radius-attribute {
circuit-id true
nas-identifier true
}
}
msap-policy "msap-policy-1" {
sub-sla-mgmt {
subscriber-limit 1
sub-ident-policy "sub-ident-policy-1"
defaults {
subscriber-id {
sap-id
}
}
single-sub-parameters {
profiled-traffic-only true
}
}
ies-vprn-only-sap-parameters {
anti-spoof next-hop-ip-and-mac-addr
ingress {
qos {
queuing-type service
}
}
}
}
}
system {
name "bng-1"
management-interface {
configuration-mode model-driven
cli {
cli-engine [md-cli classic-cli]
md-cli {
environment {
more false
command-alias {
alias "monitor-lag" {
admin-state enable
python-script "monitor"
mount-point global { }
}
alias "monitor-schd-clear" {
admin-state enable
python-script "monitor-sched-clear"
mount-point global { }
}
alias "monitor-scheduler" {
admin-state enable
python-script "monitor-sched"
mount-point global { }
}
}
}
}
}
netconf {
admin-state enable
}
yang-modules {
nokia-submodules false
nokia-combined-modules true
}
snmp {
admin-state disable
}
}
login-control {
idle-timeout none
}
security {
aaa {
local-profiles {
profile "administrative" {
default-action permit-all
entry 10 {
match "configure system security"
action permit
}
entry 20 {
match "show system security"
action permit
}
entry 30 {
match "tools perform security"
action permit
}
entry 40 {
match "tools dump security"
action permit
}
entry 50 {
match "admin system security"
action permit
}
entry 100 {
match "configure li"
action deny
}
entry 110 {
match "show li"
action deny
}
entry 111 {
match "clear li"
action deny
}
entry 112 {
match "tools dump li"
action deny
}
netconf {
base-op-authorization {
action true
cancel-commit true
close-session true
commit true
copy-config true
create-subscription true
delete-config true
discard-changes true
edit-config true
get true
get-config true
get-data true
get-schema true
kill-session true
lock true
validate true
}
}
}
profile "default" {
entry 10 {
match "exec"
action permit
}
entry 20 {
match "exit"
action permit
}
entry 30 {
match "help"
action permit
}
entry 40 {
match "logout"
action permit
}
entry 50 {
match "password"
action permit
}
entry 60 {
match "show config"
action deny
}
entry 65 {
match "show li"
action deny
}
entry 66 {
match "clear li"
action deny
}
entry 67 {
match "tools dump li"
action deny
}
entry 68 {
match "state li"
action deny
}
entry 70 {
match "show"
action permit
}
entry 75 {
match "state"
action permit
}
entry 80 {
match "enable-admin"
action permit
}
entry 90 {
match "enable"
action permit
}
entry 100 {
match "configure li"
action deny
}
}
}
}
ssh {
server-admin-state enable
server-cipher-list-v2 {
cipher 190 {
name aes256-ctr
}
cipher 192 {
name aes192-ctr
}
cipher 194 {
name aes128-ctr
}
cipher 200 {
name aes128-cbc
}
cipher 205 {
name 3des-cbc
}
cipher 225 {
name aes192-cbc
}
cipher 230 {
name aes256-cbc
}
}
client-cipher-list-v2 {
cipher 190 {
name aes256-ctr
}
cipher 192 {
name aes192-ctr
}
cipher 194 {
name aes128-ctr
}
cipher 200 {
name aes128-cbc
}
cipher 205 {
name 3des-cbc
}
cipher 225 {
name aes192-cbc
}
cipher 230 {
name aes256-cbc
}
}
server-mac-list-v2 {
mac 200 {
name hmac-sha2-512
}
mac 210 {
name hmac-sha2-256
}
mac 215 {
name hmac-sha1
}
mac 220 {
name hmac-sha1-96
}
mac 225 {
name hmac-md5
}
mac 240 {
name hmac-md5-96
}
}
client-mac-list-v2 {
mac 200 {
name hmac-sha2-512
}
mac 210 {
name hmac-sha2-256
}
mac 215 {
name hmac-sha1
}
mac 220 {
name hmac-sha1-96
}
mac 225 {
name hmac-md5
}
mac 240 {
name hmac-md5-96
}
}
}
user-params {
local-user {
user "admin" {
password "$2y$10$TQrZlpBDra86.qoexZUzQeBXDY1FcdDhGWdD9lLxMuFyPVSm0OGy6"
access {
console true
netconf true
}
console {
member ["administrative"]
}
}
}
}
}
time {
prefer-local-time true
zone {
standard {
name cst
}
}
dst-zone "CDT" {
end {
day sunday
month november
hours-minutes "02:00"
}
start {
day sunday
month march
hours-minutes "02:00"
}
}
sntp {
admin-state enable
server 135.227.160.253 {
}
}
}
}
}
# Finished 2022-12-14T13:42:02.4-06:00
radius users
cid-1 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-1",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-1",
Fall-Through = No
cid-2 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-2",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-1",
Fall-Through = No
cid-3 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-3",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-2",
Fall-Through = No
cid-4 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-4",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-2",
Fall-Through = No
cid-5 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-5",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-3",
Fall-Through = No
cid-6 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-6",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-3",
Fall-Through = No
cid-7 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-7",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-4",
Fall-Through = No
cid-8 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-8",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-4",
Fall-Through = No
cid-9 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-9",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-5",
Fall-Through = No
cid-10 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-10",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-5",
Fall-Through = No
cid-11 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-11",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-6",
Fall-Through = No
cid-12 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-12",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-6",
Fall-Through = No
cid-13 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-13",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-7",
Fall-Through = No
cid-14 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-14",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-7",
Fall-Through = No
cid-15 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-15",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-8",
Fall-Through = No
cid-16 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-16",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-8",
Fall-Through = No
cid-17 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-17",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-9",
Fall-Through = No
cid-18 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-18",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-9",
Fall-Through = No
cid-19 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-19",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-10",
Fall-Through = No
cid-20 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-20",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-10",
Fall-Through = No
cid-21 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-21",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-11",
Fall-Through = No
cid-22 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-22",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-11",
Fall-Through = No
cid-23 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-23",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-12",
Fall-Through = No
cid-24 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-24",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-12",
Fall-Through = No
cid-25 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-25",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-13",
Fall-Through = No
cid-26 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-26",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-13",
Fall-Through = No
cid-27 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-27",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-14",
Fall-Through = No
cid-28 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-28",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-14",
Fall-Through = No
cid-29 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-29",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-15",
Fall-Through = No
cid-30 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-30",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-15",
Fall-Through = No
cid-31 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-31",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-16",
Fall-Through = No
cid-32 Cleartext-Password := "cse-password"
Alc-Subsc-ID-Str = "ipoe-ds-32",
Alc-Subsc-Prof-Str = "sub-profile-1",
Alc-SLA-Prof-Str = "sla-profile-1",
Alc-MSAP-Interface = "group-int-1",
Alc-MSAP-Policy = "msap-policy-1",
Alc-MSAP-Serv-Id = "10",
Framed-Pool = "dhcpv4-1",
Framed-IPv6-Pool = "dhcpv6-1",
Alc-Delegated-IPv6-Pool = "dhcpv6-1",
Alc-Int-Dest-Id-Str = "vport-16",
Fall-Through = No