# [?1h= Version: VyOS 1.2.9-S1 # Release Train: crux #  # Built by: autobuild@vyos.net # Built on: Thu 23 Feb 2023 13:47 UTC # Build UUID: 31f37177-d137-4df8-93c6-32c4b609b834 # Build Commit ID: 93090af8c36584-dirty #  # Architecture: x86_64 # Boot via: installed image # System type: KVM guest #  # Hardware vendor: QEMU # Hardware model: Standard PC (i440FX + PIIX, 1996) # Hardware S/N: Unknown # Hardware UUID: Unknown #  # Copyright: VyOS maintainers and contributors set firewall all-ping 'enable' set firewall broadcast-ping 'disable' set firewall config-trap 'disable' set firewall ipv6-receive-redirects 'disable' set firewall ipv6-src-route 'disable' set firewall ip-src-route 'disable' set firewall log-martians 'enable' set firewall options interface tun0 adjust-mss '1436' set firewall options interface tun1 adjust-mss '1436' set firewall receive-redirects 'disable' set firewall send-redirects 'enable' set firewall source-validation 'disable' set firewall syn-cookies 'enable' set firewall twa-hazards-protection 'disable' set interfaces ethernet eth0 address '177.234.150.118/30' set interfaces ethernet eth0 address '45.228.25.1/25' set interfaces ethernet eth0 address '10.10.10.1/30' set interfaces ethernet eth0 duplex 'auto' set interfaces ethernet eth0 ip set interfaces ethernet eth0 mac 'fc:1b:d1:d6:b7:91' set interfaces ethernet eth0 smp-affinity 'auto' set interfaces ethernet eth0 speed 'auto' set interfaces ethernet eth0 vif 963 address '198.18.52.186/30' set interfaces ethernet eth0 vif 963 description 'SAGE_VIA_WIX' set interfaces ethernet eth0 vif 963 ip arp-cache-timeout '10000' set interfaces ethernet eth0 vif 2437 address '198.18.52.158/30' set interfaces ethernet eth0 vif 2437 address '2804:574:6:100::ee/126' set interfaces ethernet eth0 vif 2437 description 'BI-LATERAL-SAGE' set interfaces ethernet eth0 vif 2437 ip arp-cache-timeout '14400' set interfaces ethernet eth0 vif 3350 address '187.16.215.110/20' set interfaces ethernet eth0 vif 3350 description 'IX.SP.V4' set interfaces ethernet eth0 vif 3350 ip arp-cache-timeout '14400' set interfaces ethernet eth0 vif 3351 address '2001:12f8::215:110/64' set interfaces ethernet eth0 vif 3351 description 'IX.SP.V6' set interfaces ethernet eth0 vif 3351 disable set interfaces ethernet eth1 address '45.228.25.29/30' comment interfaces ethernet eth1 address 'GATEWAY_FIREWALL_OPENSENSE' set interfaces ethernet eth1 description 'UPLINK_SWITCH_JUNIPER_P_3' set interfaces ethernet eth1 duplex 'auto' set interfaces ethernet eth1 smp-affinity 'auto' set interfaces ethernet eth1 speed 'auto' set interfaces loopback lo address '45.228.25.0/32' set interfaces loopback lo description 'LOOPBACK' set policy prefix-list AS52705_CHATMIX_24 rule 5 action 'permit' set policy prefix-list AS52705_CHATMIX_24 rule 5 prefix '45.228.25.0/24' set policy prefix-list DEFAULT_V4 rule 5 action 'permit' set policy prefix-list DEFAULT_V4 rule 5 prefix '0.0.0.0/0' set policy prefix-list FULL_ROUTING_V4 rule 5 action 'permit' set policy prefix-list FULL_ROUTING_V4 rule 5 ge '1' set policy prefix-list FULL_ROUTING_V4 rule 5 le '24' set policy prefix-list FULL_ROUTING_V4 rule 5 prefix '0.0.0.0/0' set policy prefix-list MONITORAMENTO_SAGE rule 10 action 'permit' set policy prefix-list MONITORAMENTO_SAGE rule 10 le '32' set policy prefix-list MONITORAMENTO_SAGE rule 10 prefix '198.18.55.131/32' set policy prefix-list6 CHATMIX-V6-OUT rule 5 action 'permit' set policy prefix-list6 CHATMIX-V6-OUT rule 5 prefix '2804:2408:C000::/48' set policy route-map DENY-ALL rule 10 action 'deny' set policy route-map IN-IPV4-HOSTDIME rule 5 action 'permit' set policy route-map IN-IPV4-HOSTDIME rule 5 match ip address prefix-list 'DEFAULT_V4' set policy route-map IN-IPV4-HOSTDIME rule 5 set local-preference '1200' set policy route-map IN-IPV4-HOSTDIME rule 10000 action 'deny' set policy route-map IN-IPV4-SAGE rule 5 action 'permit' set policy route-map IN-IPV4-SAGE rule 5 match ip address prefix-list 'DEFAULT_V4' set policy route-map IN-IPV4-SAGE rule 5 set local-preference '800' set policy route-map IN-IPV4-SAGE rule 10000 action 'deny' set policy route-map IN-IPV4-BILATERAIS-IX-SP rule 10 action 'permit' set policy route-map IN-IPV4-BILATERAIS-IX-SP rule 10 match ip address prefix-list 'FULL_ROUTING_V4' set policy route-map IN-IPV4-BILATERAIS-IX-SP rule 10 set local-preference '1000' set policy route-map IN-IPV4-BILATERAIS-IX-SP rule 10000 action 'deny' set policy route-map IN-IPV4-IX-SP rule 10 action 'permit' set policy route-map IN-IPV4-IX-SP rule 10 match ip address prefix-list 'FULL_ROUTING_V4' set policy route-map IN-IPV4-IX-SP rule 10 set local-preference '600' set policy route-map IN-IPV4-IX-SP rule 10000 action 'deny' set policy route-map IN-IPV4-TEAM-CYMRU rule 5 action 'permit' set policy route-map IN-IPV4-TEAM-CYMRU rule 5 set ip-next-hop '192.0.2.1' set policy route-map IN-IPV4-TEAM-CYMRU rule 5 set local-preference '2000' set policy route-map IN-IPV6-IX-SP rule 5 action 'deny' set policy route-map IN-IPV6-TEAM-CYMRU rule 5 action 'permit' set policy route-map IN-IPV6-TEAM-CYMRU rule 5 set ipv6-next-hop global '0100::' set policy route-map IN-IPV6-TEAM-CYMRU rule 5 set local-preference '2000' set policy route-map OUT-IPV4-HOSTDIME rule 10 action 'permit' set policy route-map OUT-IPV4-HOSTDIME rule 10 match ip address prefix-list 'AS52705_CHATMIX_24' set policy route-map OUT-IPV4-HOSTDIME rule 10 set as-path-prepend '52705' set policy route-map OUT-IPV4-HOSTDIME rule 10000 action 'deny' set policy route-map OUT-IPV4-LG rule 5 action 'permit' set policy route-map OUT-IPV4-LG rule 5 match ip address prefix-list 'FULL_ROUTING_V4' set policy route-map OUT-IPV4-SAGE rule 10 action 'permit' set policy route-map OUT-IPV4-SAGE rule 10 match ip address prefix-list 'AS52705_CHATMIX_24' set policy route-map OUT-IPV4-SAGE rule 20 action 'permit' set policy route-map OUT-IPV4-SAGE rule 20 match ip address prefix-list 'MONITORAMENTO_SAGE' set policy route-map OUT-IPV4-SAGE rule 10000 action 'deny' set policy route-map OUT-IPV4-BILATERAIS-IX-SP rule 10 action 'permit' set policy route-map OUT-IPV4-BILATERAIS-IX-SP rule 10 match ip address prefix-list 'AS52705_CHATMIX_24' set policy route-map OUT-IPV4-BILATERAIS-IX-SP rule 10000 action 'deny' set policy route-map OUT-IPV4-IX-SP rule 10 action 'permit' set policy route-map OUT-IPV4-IX-SP rule 10 match ip address prefix-list 'AS52705_CHATMIX_24' set policy route-map OUT-IPV4-IX-SP rule 10 set community 'none' set policy route-map OUT-IPV4-IX-SP rule 10000 action 'deny' set policy route-map OUT-IPV6-IX-SP rule 1 action 'permit' set policy route-map OUT-IPV6-IX-SP rule 1 match ipv6 address prefix-list 'CHATMIX-V6-OUT' set policy route-map OUT-IPV6-IX-SP rule 5 action 'deny' set protocols bfd peer 177.234.156.1 multihop set protocols bfd peer 177.234.156.1 source address '177.234.150.118' set protocols bfd peer 177.234.156.2 multihop set protocols bfd peer 177.234.156.2 source address '177.234.150.118' set protocols bgp 52705 address-family ipv4-unicast network 45.228.25.0/24 set protocols bgp 52705 address-family ipv4-unicast network 198.18.55.131/32 set protocols bgp 52705 address-family ipv6-unicast network 2804:2408:C000::/48 set protocols bgp 52705 neighbor 177.234.156.1 bfd check-control-plane-failure set protocols bgp 52705 neighbor 177.234.156.1 peer-group 'HOSTDIME' set protocols bgp 52705 neighbor 177.234.156.2 bfd check-control-plane-failure set protocols bgp 52705 neighbor 177.234.156.2 peer-group 'HOSTDIME' set protocols bgp 52705 neighbor 187.16.208.188 peer-group 'BILATERAIS_IPV4_IX_SP' set protocols bgp 52705 neighbor 187.16.208.188 remote-as '13335' set protocols bgp 52705 neighbor 187.16.216.252 address-family ipv4-unicast route-map export 'OUT-IPV4-LG' set protocols bgp 52705 neighbor 187.16.216.252 address-family ipv4-unicast route-map import 'DENY-ALL' set protocols bgp 52705 neighbor 187.16.216.252 description 'lgc.saopaulo.sp.ix.br' set protocols bgp 52705 neighbor 187.16.216.252 remote-as '20121' set protocols bgp 52705 neighbor 187.16.216.253 address-family ipv4-unicast allowas-in number '2' set protocols bgp 52705 neighbor 187.16.216.253 address-family ipv4-unicast nexthop-self force set protocols bgp 52705 neighbor 187.16.216.253 address-family ipv4-unicast route-map export 'OUT-IPV4-IX-SP' set protocols bgp 52705 neighbor 187.16.216.253 address-family ipv4-unicast route-map import 'IN-IPV4-IX-SP' set protocols bgp 52705 neighbor 187.16.216.253 address-family ipv4-unicast soft-reconfiguration inbound set protocols bgp 52705 neighbor 187.16.216.253 description 'ix1.v4.sp' set protocols bgp 52705 neighbor 187.16.216.253 remote-as '26162' set protocols bgp 52705 neighbor 187.16.216.254 address-family ipv4-unicast nexthop-self force set protocols bgp 52705 neighbor 187.16.216.254 address-family ipv4-unicast route-map export 'OUT-IPV4-IX-SP' set protocols bgp 52705 neighbor 187.16.216.254 address-family ipv4-unicast route-map import 'IN-IPV4-IX-SP' set protocols bgp 52705 neighbor 187.16.216.254 address-family ipv4-unicast soft-reconfiguration inbound set protocols bgp 52705 neighbor 187.16.216.254 description 'ix.v4.sp' set protocols bgp 52705 neighbor 187.16.216.254 remote-as '26162' set protocols bgp 52705 neighbor 187.16.219.111 peer-group 'BILATERAIS_IPV4_IX_SP' set protocols bgp 52705 neighbor 187.16.219.111 remote-as '13335' set protocols bgp 52705 neighbor 198.18.52.157 address-family ipv4-unicast route-map export 'OUT-IPV4-SAGE' set protocols bgp 52705 neighbor 198.18.52.157 address-family ipv4-unicast route-map import 'IN-IPV4-SAGE' set protocols bgp 52705 neighbor 198.18.52.157 address-family ipv4-unicast soft-reconfiguration inbound set protocols bgp 52705 neighbor 198.18.52.157 description 'SAGE-BI-LATERAL' set protocols bgp 52705 neighbor 198.18.52.157 remote-as '65463' set protocols bgp 52705 neighbor 198.18.54.189 address-family ipv4-unicast route-map export 'OUT-IPV4-SAGE' set protocols bgp 52705 neighbor 198.18.54.189 address-family ipv4-unicast route-map import 'IN-IPV4-SAGE' set protocols bgp 52705 neighbor 198.18.54.189 address-family ipv4-unicast soft-reconfiguration inbound set protocols bgp 52705 neighbor 198.18.54.189 ebgp-multihop '2' set protocols bgp 52705 neighbor 198.18.54.189 remote-as '65463' set protocols bgp 52705 neighbor 198.18.54.189 shutdown set protocols bgp 52705 neighbor 198.18.54.189 update-source '177.234.150.118' set protocols bgp 52705 neighbor 216.31.3.81 peer-group 'IPV4_TEAM_CYMRU' set protocols bgp 52705 neighbor 216.31.7.81 peer-group 'IPV4_TEAM_CYMRU' set protocols bgp 52705 neighbor 2001:12f8::252 address-family ipv6-unicast route-map export 'OUT-IPV6-IX-SP' set protocols bgp 52705 neighbor 2001:12f8::252 address-family ipv6-unicast route-map import 'DENY-ALL' set protocols bgp 52705 neighbor 2001:12f8::252 description 'lgc.saopaulo.spv6.ix.br' set protocols bgp 52705 neighbor 2001:12f8::252 remote-as '20121' set protocols bgp 52705 neighbor 2001:12f8::252 shutdown set protocols bgp 52705 neighbor 2001:12f8::253 address-family ipv6-unicast route-map export 'OUT-IPV6-IX-SP' set protocols bgp 52705 neighbor 2001:12f8::253 address-family ipv6-unicast route-map import 'IN-IPV6-IX-SP' set protocols bgp 52705 neighbor 2001:12f8::253 description 'rs1.saopaulo.sp.ix.br' set protocols bgp 52705 neighbor 2001:12f8::253 remote-as '26162' set protocols bgp 52705 neighbor 2001:12f8::253 shutdown set protocols bgp 52705 neighbor 2001:12f8::254 address-family ipv6-unicast route-map export 'OUT-IPV6-IX-SP' set protocols bgp 52705 neighbor 2001:12f8::254 address-family ipv6-unicast route-map import 'IN-IPV6-IX-SP' set protocols bgp 52705 neighbor 2001:12f8::254 description 'rs2.saopaulo.sp.ix.br' set protocols bgp 52705 neighbor 2001:12f8::254 remote-as '26162' set protocols bgp 52705 neighbor 2001:12f8::254 shutdown set protocols bgp 52705 parameters router-id '177.234.150.118' set protocols bgp 52705 peer-group BILATERAIS_IPV4_IX_SP address-family ipv4-unicast route-map export 'OUT-IPV4-BILATERAIS-IX-SP' set protocols bgp 52705 peer-group BILATERAIS_IPV4_IX_SP address-family ipv4-unicast route-map import 'IN-IPV4-BILATERAIS-IX-SP' set protocols bgp 52705 peer-group BILATERAIS_IPV4_IX_SP address-family ipv4-unicast soft-reconfiguration inbound set protocols bgp 52705 peer-group HOSTDIME address-family ipv4-unicast route-map export 'OUT-IPV4-HOSTDIME' set protocols bgp 52705 peer-group HOSTDIME address-family ipv4-unicast route-map import 'IN-IPV4-HOSTDIME' set protocols bgp 52705 peer-group HOSTDIME address-family ipv4-unicast soft-reconfiguration inbound set protocols bgp 52705 peer-group HOSTDIME bfd set protocols bgp 52705 peer-group HOSTDIME ebgp-multihop '64' set protocols bgp 52705 peer-group HOSTDIME remote-as '33182' set protocols bgp 52705 peer-group HOSTDIME update-source '177.234.150.118' set protocols bgp 52705 peer-group IPV4_TEAM_CYMRU address-family ipv4-unicast route-map export 'DENY-ALL' set protocols bgp 52705 peer-group IPV4_TEAM_CYMRU address-family ipv4-unicast route-map import 'IN-IPV4-TEAM-CYMRU' set protocols bgp 52705 peer-group IPV4_TEAM_CYMRU ebgp-multihop '255' set protocols bgp 52705 peer-group IPV4_TEAM_CYMRU password 'M7migpgKYB' set protocols bgp 52705 peer-group IPV4_TEAM_CYMRU remote-as '65332' set protocols bgp 52705 peer-group IPV4_TEAM_CYMRU update-source '45.228.25.0' set protocols ospf area 0.0.0.0 network '45.228.25.0/24' set protocols ospf area 0.0.0.0 network '45.228.25.192/30' set protocols static route 45.228.25.0/24 blackhole distance '254' set protocols static route 45.228.25.2/32 next-hop 45.228.25.30 set protocols static route 45.228.25.128/25 next-hop 45.228.25.30 set protocols static route 177.234.156.0/24 next-hop 177.234.150.117 set protocols static route 192.0.2.1/32 blackhole comment protocols static route 192.0.2.1/32 'TEAM CYMRU' set protocols static route 198.18.55.114/32 blackhole distance '254' set protocols static route 198.18.55.131/32 blackhole distance '254' set protocols static route6 0100::/64 blackhole comment protocols static route6 0100::/64 'TEAM CYMRU' set protocols static route6 2804:2408:C000::/48 blackhole set service snmp community vyos authorization 'ro' set service snmp community vyos network '45.228.25.133/32' set service snmp community vyos network '177.10.56.141/32' set service snmp contact 'noc@chatmix.com.br' set service snmp listen-address 45.228.25.0 port '161' set service snmp location 'SP, CIRION' set service ssh port '9045' set system config-management commit-revisions '100' set system console device ttyS0 speed '9600' set system flow-accounting buffer-size '256' set system flow-accounting interface 'eth0' set system flow-accounting interface 'eth0.2437' set system flow-accounting interface 'eth0.2350' set system flow-accounting interface 'eth0.2351' set system flow-accounting interface 'eth1' set system flow-accounting interface 'eth0.3350' set system flow-accounting interface 'eth0.3351' set system flow-accounting netflow engine-id '9' set system flow-accounting netflow sampling-rate '100' set system flow-accounting netflow server 45.228.25.133 port '2055' set system flow-accounting netflow source-ip '45.228.25.0' set system flow-accounting netflow timeout expiry-interval '30' set system flow-accounting netflow timeout flow-generic '3600' set system flow-accounting netflow timeout icmp '300' set system flow-accounting netflow timeout max-active-life '604800' set system flow-accounting netflow timeout tcp-fin '300' set system flow-accounting netflow timeout tcp-generic '3600' set system flow-accounting netflow timeout tcp-rst '120' set system flow-accounting netflow timeout udp '300' set system flow-accounting netflow version '9' set system host-name 'vyos' set system ip arp table-size '8192' set system login user ispexpert authentication encrypted-password '$6$GNx7JzW8mvUr$2UpDlnQiuF1q0z.ArPCmkC89ot/JXgIFU1oISfnQZryJocz24RQX3G381BPJoMTNQ2vVuDCNGtrK2RP9P4BuV0' set system login user ispexpert authentication plaintext-password '' set system login user ispexpert level 'admin' set system login user oxidized authentication encrypted-password '$6$sNNnzL92LI4qO2$pM7.9z32xPZvVx9UnZyHRztPvg5ASV1kl1SvuKcQtCpg.8xtliNiGWryu9scNQ8Vr1YB/J0VL/kHOjobOMea3/' set system login user oxidized authentication plaintext-password '' set system login user oxidized level 'admin' set system login user rogerio authentication encrypted-password '$6$iUmfvhu3ZyTg$gl34HLnsmO5piOpeMciRwOctXGwqceyjNpnuzi5i1igimDYkoBb9hN8rd6lm0FRRL9RQ/J3FT/GBFgdgI1kgr.' set system login user rogerio authentication plaintext-password '' set system login user rogerio level 'admin' set system login user vyos authentication encrypted-password '$6$rP.14Ffz$6W4uHySge3A46z6lEnUl8seTrWA7HYB8kjxBwbqqxUj5XQh0TVjY2WpYkCdf7ysi4oliEQzE/tdJVMxOZ6vDF1' set system login user vyos authentication plaintext-password '' set system login user vyos level 'admin' set system ntp server 0.pool.ntp.org set system ntp server 1.pool.ntp.org set system ntp server 2.pool.ntp.org set system syslog global facility all level 'info' set system syslog global facility protocols level 'debug' set system time-zone 'America/Sao_Paulo'