2025-02-24 11:33:21
This commit is contained in:
parent
2b7b5d4dd3
commit
feee2e72d9
2 changed files with 0 additions and 3281 deletions
451
xml/config.xml
451
xml/config.xml
|
@ -1,451 +0,0 @@
|
|||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!-- config.xml - The main configuration file for the security device.
|
||||
Use the "inms_command" utility to edit. Manual editing is not recommended.
|
||||
-->
|
||||
<config>
|
||||
<config_version>3.1.1</config_version>
|
||||
<config_file_timestamp>1554450545070</config_file_timestamp>
|
||||
<device>
|
||||
<device_id>65</device_id>
|
||||
<device_name>BML10B3-43</device_name>
|
||||
<device_description>BML10B3-43</device_description>
|
||||
<device_serial_number>BML10B3-43</device_serial_number>
|
||||
<device_type_name>bml10</device_type_name>
|
||||
<device_type_id>81</device_type_id>
|
||||
<device_group_name>8</device_group_name>
|
||||
<device_group_id>8</device_group_id>
|
||||
<device_config_change>0</device_config_change>
|
||||
</device>
|
||||
<system>
|
||||
<hostname>BML10B3-43</hostname>
|
||||
<timezone>Asia/Ho_Chi_Minh</timezone>
|
||||
<ntp_server>ntp.vgisc.com</ntp_server>
|
||||
<login_time_interval>300</login_time_interval>
|
||||
<crypto_system_name>BCYCP</crypto_system_name>
|
||||
<screen_dim_interval>300</screen_dim_interval>
|
||||
<screen_brightness_level>9</screen_brightness_level>
|
||||
<sound_volume_level>100</sound_volume_level>
|
||||
<system_config_change>0</system_config_change>
|
||||
</system>
|
||||
<software>
|
||||
<software_version_number>331</software_version_number>
|
||||
<software_version_name>3.1.1</software_version_name>
|
||||
<software_version_build>2023.05.20</software_version_build>
|
||||
<software_installed_time>20/05/2023-12:58:30</software_installed_time>
|
||||
<software_config_change>0</software_config_change>
|
||||
</software>
|
||||
<service>
|
||||
<datetime_update_enable>yes</datetime_update_enable>
|
||||
<ipv4_enable>yes</ipv4_enable>
|
||||
<ipv6_enable>no</ipv6_enable>
|
||||
<ipv4_forward>yes</ipv4_forward>
|
||||
<ipv6_forward>no</ipv6_forward>
|
||||
<iptables_ipv4_enable>yes</iptables_ipv4_enable>
|
||||
<iptables_ipv6_enable>no</iptables_ipv6_enable>
|
||||
<dns_client_enable>yes</dns_client_enable>
|
||||
<dns_server_enable>no</dns_server_enable>
|
||||
<dhcp_client_enable>no</dhcp_client_enable>
|
||||
<sshd_enable>yes</sshd_enable>
|
||||
<ssh_enable>yes</ssh_enable>
|
||||
<scp_enable>yes</scp_enable>
|
||||
<megassh_sshd_enable>no</megassh_sshd_enable>
|
||||
<megassh_ssh_enable>no</megassh_ssh_enable>
|
||||
<megassh_scp_enable>no</megassh_scp_enable>
|
||||
<ipsec_enable>yes</ipsec_enable>
|
||||
<router_enable>yes</router_enable>
|
||||
<keepalived_enable>no</keepalived_enable>
|
||||
<inms_agent_enable>yes</inms_agent_enable>
|
||||
<bmvpn_enable>yes</bmvpn_enable>
|
||||
<megavpn_enable>no</megavpn_enable>
|
||||
<megawg_enable>no</megawg_enable>
|
||||
<gsm_agent_enable>no</gsm_agent_enable>
|
||||
<service_config_change>0</service_config_change>
|
||||
</service>
|
||||
<users>
|
||||
<linux_os_users>
|
||||
<item username="root" password="TooR" group="" home_dir="/root" shell="/bin/sh"/>
|
||||
<linux_os_users_config_change>0</linux_os_users_config_change>
|
||||
</linux_os_users>
|
||||
</users>
|
||||
<ipsec>
|
||||
<ipsec_plugins>charon megassl hkdf mgf1 random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pkcs12 pem pkcs8 kdf attr kernel-netlink resolve socket-default stroke vici updown counters</ipsec_plugins>
|
||||
<ipsec_secrets>
|
||||
<item secret_id_selector="" secret_type="PSK" secret_file="" secret_passphrase="0x6E9A3A46012EF27D9DB6F2FF682B1B80"/>
|
||||
<item secret_id_selector="" secret_type="RSA" secret_file="vpn12.vgisc.com.key" secret_passphrase=""/>
|
||||
</ipsec_secrets>
|
||||
<ipsec_config_setup>
|
||||
<item name="charondebug" value="all"/>
|
||||
<item name="uniqueids" value="no"/>
|
||||
<item name="strictcrlpolicy" value="no"/>
|
||||
</ipsec_config_setup>
|
||||
<ipsec_ca>
|
||||
<item name="root-ca">
|
||||
<item name="cacert" value="root-ca.vgisc.com.crt"/>
|
||||
<item name="auto" value="add"/>
|
||||
</item>
|
||||
<item name="sub-ca">
|
||||
<item name="cacert" value="sub-ca.vgisc.com.crt"/>
|
||||
<item name="auto" value="add"/>
|
||||
</item>
|
||||
</ipsec_ca>
|
||||
<ipsec_conn_default>
|
||||
<item name="ike" value="mkc4bctr-sha2_384-dh4096!"/>
|
||||
<item name="esp" value="mkc4bctr-sha2_384!"/>
|
||||
<item name="left" value="192.168.1.43"/>
|
||||
<item name="leftsubnet" value="172.16.43.0/24"/>
|
||||
<item name="leftcert" value="vpn43.vgisc.com.crt"/>
|
||||
<item name="leftid" value="vpn43.vgisc.com"/>
|
||||
<item name="keyexchange" value="ikev2"/>
|
||||
<item name="leftauth" value="ike:rsa/pss-sha256"/>
|
||||
<item name="rightauth" value="ike:rsa/pss-sha256"/>
|
||||
<item name="leftsendcert" value="ifasked"/>
|
||||
<item name="rightsendcert" value="ifasked"/>
|
||||
<item name="authby" value="pubkey"/>
|
||||
<item name="keyingtries" value="0"/>
|
||||
<item name="ikelifetime" value="24h"/>
|
||||
<item name="lifetime" value="12h"/>
|
||||
<item name="dpddelay" value="300s"/>
|
||||
<item name="dpdtimeout" value="1h"/>
|
||||
<item name="dpdaction" value="restart"/>
|
||||
<item name="compress" value="no"/>
|
||||
<item name="fragmentation" value="yes"/>
|
||||
<item name="leftfirewall" value="yes"/>
|
||||
<item name="auto" value="start"/>
|
||||
</ipsec_conn_default>
|
||||
<ipsec_conn>
|
||||
<item name="VPN41" left_host_id="" right_host_id="">
|
||||
<item name="right" value="192.168.1.42"/>
|
||||
<item name="rightsubnet" value="172.16.42.0/24"/>
|
||||
<item name="rightcert" value="vpn42.vgisc.com.crt"/>
|
||||
<item name="rightid" value="vpn42.vgisc.com"/>
|
||||
</item>
|
||||
</ipsec_conn>
|
||||
<ipsec_config_change>0</ipsec_config_change>
|
||||
</ipsec>
|
||||
<bmvpn>
|
||||
<bmvpn_conf>
|
||||
<item name="client.conf">
|
||||
<item name="client" value="NA"/>
|
||||
<item name="proto" value="tcp"/>
|
||||
<item name="dev" value="tun"/>
|
||||
<item name="remote" value="192.168.100.250 19001"/>
|
||||
<item name="resolv-retry" value="60"/>
|
||||
<item name="dh" value="dh_2048.pem"/>
|
||||
<item name="tls-auth" value="tls_auth_2304.pem 1"/>
|
||||
<item name="ca" value="ca.vgisc.com.crt"/>
|
||||
<item name="cert" value="vpn72.vgisc.com.crt"/>
|
||||
<item name="key" value="vpn72.vgisc.com.key"/>
|
||||
<item name="nobind" value="NA"/>
|
||||
<item name="persist-key" value="NA"/>
|
||||
<item name="persist-tun" value="NA"/>
|
||||
<item name="comp-lzo" value="NA"/>
|
||||
<item name="verb" value="3"/>
|
||||
<item name="log-deny" value="/var/log/bmvpn-client-deny.log"/>
|
||||
<item name="status" value="/var/log/bmvpn-client-status.log 60"/>
|
||||
<item name="log" value="/var/log/bmvpn-client.log"/>
|
||||
</item>
|
||||
<item name="server1.conf">
|
||||
<item name="port" value="19001"/>
|
||||
<item name="proto" value="tcp"/>
|
||||
<item name="dev" value="tun"/>
|
||||
<item name="mode" value="server"/>
|
||||
<item name="tun-mtu" value="1400"/>
|
||||
<item name="tun-mtu-extra" value="32"/>
|
||||
<item name="server" value="10.72.1.0 255.255.255.0"/>
|
||||
<item name="ifconfig" value="10.72.1.254 255.255.255.0"/>
|
||||
<item name="dh" value="dh_2048.pem"/>
|
||||
<item name="tls-auth" value="tls_auth_2304.pem 1"/>
|
||||
<item name="ca" value="ca.vgisc.com.crt"/>
|
||||
<item name="cert" value="server1.vgisc.com.crt"/>
|
||||
<item name="key" value="server1.vgisc.com.key"/>
|
||||
<item name="duplicate-cn" value="NA"/>
|
||||
<item name="topology" value="subnet"/>
|
||||
<item name="reneg-sec" value="36000"/>
|
||||
<item name="max-clients" value="1024"/>
|
||||
<item name="keepalive" value="30 120"/>
|
||||
<item name="persist-key" value="NA"/>
|
||||
<item name="persist-tun" value="NA"/>
|
||||
<item name="comp-lzo" value="NA"/>
|
||||
<item name="verb" value="3"/>
|
||||
<item name="log-deny" value="/var/log/bmvpn-server1-deny.log"/>
|
||||
<item name="status" value="/var/log/bmvpn-server1-status.log 60"/>
|
||||
<item name="log" value="/var/log/bmvpn-server1.log"/>
|
||||
<item name="management" value="0.0.0.0 19011"/>
|
||||
<item name="client-to-client" value="NA"/>
|
||||
<item name="client-config-dir" value="/opt/vgisc/etc/bmvpn/ccd"/>
|
||||
<item name="push" value="route 172.100.72.0 255.255.255.0"/>
|
||||
</item>
|
||||
</bmvpn_conf>
|
||||
<bmvpn_config_change>0</bmvpn_config_change>
|
||||
</bmvpn>
|
||||
<megavpn>
|
||||
<megavpn_conf>
|
||||
<item name="client.conf">
|
||||
<item name="client" value="NA"/>
|
||||
<item name="proto" value="tcp"/>
|
||||
<item name="dev" value="tun"/>
|
||||
<item name="remote" value="192.168.100.250 19001"/>
|
||||
<item name="resolv-retry" value="60"/>
|
||||
<item name="dh" value="dh_2048.pem"/>
|
||||
<item name="tls-auth" value="tls_auth_2304.pem 1"/>
|
||||
<item name="ca" value="ca.vgisc.com.crt"/>
|
||||
<item name="cert" value="vpn72.vgisc.com.crt"/>
|
||||
<item name="key" value="vpn72.vgisc.com.key"/>
|
||||
<item name="nobind" value="NA"/>
|
||||
<item name="persist-key" value="NA"/>
|
||||
<item name="persist-tun" value="NA"/>
|
||||
<item name="comp-lzo" value="NA"/>
|
||||
<item name="verb" value="3"/>
|
||||
<item name="log-deny" value="/var/log/bmvpn-client-deny.log"/>
|
||||
<item name="status" value="/var/log/bmvpn-client-status.log 60"/>
|
||||
<item name="log" value="/var/log/bmvpn-client.log"/>
|
||||
</item>
|
||||
<item name="server1.conf">
|
||||
<item name="port" value="19001"/>
|
||||
<item name="proto" value="tcp"/>
|
||||
<item name="dev" value="tun"/>
|
||||
<item name="mode" value="server"/>
|
||||
<item name="tun-mtu" value="1400"/>
|
||||
<item name="tun-mtu-extra" value="32"/>
|
||||
<item name="server" value="10.72.1.0 255.255.255.0"/>
|
||||
<item name="ifconfig" value="10.72.1.254 255.255.255.0"/>
|
||||
<item name="dh" value="dh_2048.pem"/>
|
||||
<item name="tls-auth" value="tls_auth_2304.pem 1"/>
|
||||
<item name="ca" value="ca.vgisc.com.crt"/>
|
||||
<item name="cert" value="server1.vgisc.com.crt"/>
|
||||
<item name="key" value="server1.vgisc.com.key"/>
|
||||
<item name="duplicate-cn" value="NA"/>
|
||||
<item name="topology" value="subnet"/>
|
||||
<item name="reneg-sec" value="36000"/>
|
||||
<item name="max-clients" value="1024"/>
|
||||
<item name="keepalive" value="30 120"/>
|
||||
<item name="persist-key" value="NA"/>
|
||||
<item name="persist-tun" value="NA"/>
|
||||
<item name="comp-lzo" value="NA"/>
|
||||
<item name="verb" value="3"/>
|
||||
<item name="log-deny" value="/var/log/bmvpn-server1-deny.log"/>
|
||||
<item name="status" value="/var/log/bmvpn-server1-status.log 60"/>
|
||||
<item name="log" value="/var/log/bmvpn-server1.log"/>
|
||||
<item name="management" value="0.0.0.0 19011"/>
|
||||
<item name="client-to-client" value="NA"/>
|
||||
<item name="client-config-dir" value="/opt/vgisc/etc/bmvpn/ccd"/>
|
||||
<item name="push" value="route 172.100.72.0 255.255.255.0"/>
|
||||
</item>
|
||||
</megavpn_conf>
|
||||
<megavpn_config_change>0</megavpn_config_change>
|
||||
</megavpn>
|
||||
<iptables>
|
||||
<iptables_ipv4>
|
||||
<iptables_ipv4_config_change>0</iptables_ipv4_config_change>
|
||||
<chain_default_actions>
|
||||
<item name="INPUT" value="ACCEPT"/>
|
||||
<item name="OUTPUT" value="ACCEPT"/>
|
||||
<item name="FORWARD" value="ACCEPT"/>
|
||||
</chain_default_actions>
|
||||
<rules>
|
||||
<item id="40" chain="INPUT" l3_protocol="UDP" l4_protocol="IPERF" source="" dest="" dport="5201" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="39" chain="OUTPUT" l3_protocol="UDP" l4_protocol="IPERF" source="" dest="" dport="5201" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="38" chain="INPUT" l3_protocol="UDP" l4_protocol="IPERF" source="" dest="" dport="5001" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="37" chain="OUTPUT" l3_protocol="UDP" l4_protocol="IPERF" source="" dest="" dport="5001" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="36" chain="INPUT" l3_protocol="TCP" l4_protocol="IPERF" source="" dest="" dport="5201" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="35" chain="OUTPUT" l3_protocol="TCP" l4_protocol="IPERF" source="" dest="" dport="5201" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="34" chain="INPUT" l3_protocol="TCP" l4_protocol="IPERF" source="" dest="" dport="5001" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="33" chain="OUTPUT" l3_protocol="TCP" l4_protocol="IPERF" source="" dest="" dport="5001" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="32" chain="INPUT" l3_protocol="UDP" l4_protocol="DNS" source="" dest="" dport="53" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="31" chain="OUTPUT" l3_protocol="UDP" l4_protocol="DNS" source="" dest="" dport="53" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="30" chain="INPUT" l3_protocol="TCP" l4_protocol="INMS" source="" dest="" dport="9001" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="29" chain="OUTPUT" l3_protocol="TCP" l4_protocol="INMS" source="" dest="" dport="9001" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="28" chain="INPUT" l3_protocol="TCP" l4_protocol="BMVPN" source="" dest="" dport="19001" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="27" chain="OUTPUT" l3_protocol="TCP" l4_protocol="BMVPN" source="" dest="" dport="19001" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="26" chain="FORWARD" l3_protocol="UDP" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="25" chain="FORWARD" l3_protocol="TCP" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="24" chain="OUTPUT" l3_protocol="VRRP" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="23" chain="INPUT" l3_protocol="any" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="22" chain="OUTPUT" l3_protocol="OSPF" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="21" chain="INPUT" l3_protocol="OSPF" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="20" chain="OUTPUT" l3_protocol="ESP" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="19" chain="INPUT" l3_protocol="ESP" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="18" chain="OUTPUT" l3_protocol="ICMP" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="17" chain="INPUT" l3_protocol="ICMP" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="16" chain="OUTPUT" l3_protocol="UDP" l4_protocol="NTP" source="" dest="" dport="" sport="123" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="15" chain="INPUT" l3_protocol="UDP" l4_protocol="NTP" source="" dest="" dport="123" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="14" chain="OUTPUT" l3_protocol="UDP" l4_protocol="RIP" source="" dest="" dport="" sport="520" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="13" chain="INPUT" l3_protocol="UDP" l4_protocol="RIP" source="" dest="" dport="520" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="12" chain="OUTPUT" l3_protocol="UDP" l4_protocol="IPSEC-NAT-T" source="" dest="" dport="" sport="4500" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="11" chain="INPUT" l3_protocol="UDP" l4_protocol="IPSEC-NAT-T" source="" dest="" dport="4500" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="10" chain="OUTPUT" l3_protocol="UDP" l4_protocol="ISAKMP" source="" dest="" dport="" sport="500" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="9" chain="INPUT" l3_protocol="UDP" l4_protocol="ISAKMP" source="" dest="" dport="500" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="8" chain="OUTPUT" l3_protocol="TCP" l4_protocol="INMS" source="" dest="" dport="" sport="22222" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="7" chain="INPUT" l3_protocol="TCP" l4_protocol="INMS" source="" dest="" dport="22222" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="6" chain="OUTPUT" l3_protocol="TCP" l4_protocol="INMS" source="" dest="" dport="22222" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="5" chain="INPUT" l3_protocol="TCP" l4_protocol="INMS" source="" dest="" dport="" sport="22222" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="4" chain="OUTPUT" l3_protocol="TCP" l4_protocol="SSH" source="" dest="" dport="" sport="22" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="3" chain="INPUT" l3_protocol="TCP" l4_protocol="SSH" source="" dest="" dport="22" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="4" chain="OUTPUT" l3_protocol="TCP" l4_protocol="SSH" source="" dest="" dport="22" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="3" chain="INPUT" l3_protocol="TCP" l4_protocol="SSH" source="" dest="" dport="" sport="22" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="2" chain="OUTPUT" l3_protocol="any" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="any" out_interface="lo" action="ACCEPT"/>
|
||||
<item id="1" chain="INPUT" l3_protocol="any" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="lo" out_interface="any" action="ACCEPT"/>
|
||||
</rules>
|
||||
</iptables_ipv4>
|
||||
<iptables_ipv6>
|
||||
<iptables_ipv6_config_change>0</iptables_ipv6_config_change>
|
||||
<chain_default_actions>
|
||||
<item name="INPUT" value="DROP"/>
|
||||
<item name="OUTPUT" value="DROP"/>
|
||||
<item name="FORWARD" value="DROP"/>
|
||||
</chain_default_actions>
|
||||
<rules>
|
||||
<item id="2" chain="OUTPUT" l3_protocol="any" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
<item id="1" chain="INPUT" l3_protocol="any" l4_protocol="any" source="" dest="" dport="" sport="" in_interface="any" out_interface="any" action="ACCEPT"/>
|
||||
</rules>
|
||||
</iptables_ipv6>
|
||||
</iptables>
|
||||
<keepalived>
|
||||
<item name="vrrp_instance VI_1" value="">
|
||||
<item name="state" value="MASTER"/>
|
||||
<item name="interface" value="eno1"/>
|
||||
<item name="virtual_router_id" value="51"/>
|
||||
<item name="priority" value="102"/>
|
||||
<item name="advert_int" value="1"/>
|
||||
<item name="accept" value=""/>
|
||||
<item name="unicast_src_ip" value="192.168.100.72"/>
|
||||
<item name="unicast_peer" value="">
|
||||
<item name="192.168.100.72" value=""/>
|
||||
</item>
|
||||
<item name="authentication" value="">
|
||||
<item name="auth_type" value="PASS"/>
|
||||
<item name="auth_pass" value="P@ss20d"/>
|
||||
</item>
|
||||
<item name="virtual_ipaddress" value="">
|
||||
<item name="" value="192.168.100.72/24 dev eno1"/>
|
||||
<item name="" value="172.100.72.1/24 dev usb0"/>
|
||||
</item>
|
||||
<item name="track_interface" value="">
|
||||
<item name="eno1" value="weight -3"/>
|
||||
<item name="eno2" value="weight -3"/>
|
||||
</item>
|
||||
<item name="notify" value="/etc/keepalived/keepalived_notify.sh"/>
|
||||
</item>
|
||||
</keepalived>
|
||||
<ssh>
|
||||
<sshd_config>
|
||||
<item name="Port" value="22222"/>
|
||||
<sshd_config_change>0</sshd_config_change>
|
||||
</sshd_config>
|
||||
<ssh_config>
|
||||
<item name="Host" value="inms.vgisc.com">
|
||||
<item name="Port" value="22222"/>
|
||||
<item name="User" value="inms"/>
|
||||
</item>
|
||||
<ssh_config_change>0</ssh_config_change>
|
||||
</ssh_config>
|
||||
</ssh>
|
||||
<megassh>
|
||||
<megasshd_config>
|
||||
<item name="Port" value="22222"/>
|
||||
<sshd_config_change>0</sshd_config_change>
|
||||
</megasshd_config>
|
||||
<megassh_config>
|
||||
<item name="Host" value="inms.vgisc.com">
|
||||
<item name="Port" value="22222"/>
|
||||
<item name="User" value="inms"/>
|
||||
</item>
|
||||
<ssh_config_change>0</ssh_config_change>
|
||||
</megassh_config>
|
||||
</megassh>
|
||||
<inms_agent>
|
||||
<item name="server_ip" value="inms.vgisc.com"/>
|
||||
<item name="server_port" value="8000"/>
|
||||
<inms_agent_config_change>0</inms_agent_config_change>
|
||||
</inms_agent>
|
||||
<gsm_agent>
|
||||
<item name="Server" value="gsm-server.vgisc.com"/>
|
||||
<item name="ServerActive" value="gsm-server.vgisc.com"/>
|
||||
<item name="ListenPort" value="10050"/>
|
||||
<item name="TLSAccept" value="cert"/>
|
||||
<item name="TLSConnect" value="cert"/>
|
||||
<item name="TLSCAFile" value="gsm_bml10_ca.crt"/>
|
||||
<item name="TLSCertFile" value="gsm_bml10_host.crt"/>
|
||||
<item name="TLSCipherCert13" value="gsm_bml10_host.key"/>
|
||||
<item name="LogFile" value="/var/log/gsm_agentd.log"/>
|
||||
<gsm_agent_config_change>0</gsm_agent_config_change>
|
||||
</gsm_agent>
|
||||
<router>
|
||||
<zebra_enable>yes</zebra_enable>
|
||||
<vtysh_enable>yes</vtysh_enable>
|
||||
<ripd_enable>yes</ripd_enable>
|
||||
<ospfd_enable>no</ospfd_enable>
|
||||
<bgpd_enable>no</bgpd_enable>
|
||||
<isisd_enable>no</isisd_enable>
|
||||
<ripngd_enable>no</ripngd_enable>
|
||||
<ospf6d_enable>no</ospf6d_enable>
|
||||
<router_config_change>0</router_config_change>
|
||||
<zebra>
|
||||
<item name="hostname" value="router"/>
|
||||
<item name="password" value="TooR"/>
|
||||
<item name="enable password" value="TooR"/>
|
||||
<item name="log" value="file /var/log/frr/zebra.log"/>
|
||||
<item name="log" value="stdout"/>
|
||||
<item name="debug" value="zebra kernel"/>
|
||||
<item name="interface" value="eno1">
|
||||
<item name="description" value="WAN"/>
|
||||
</item>
|
||||
<item name="interface" value="eno2">
|
||||
<item name="description" value="LAN"/>
|
||||
</item>
|
||||
<item name="interface" value="lo">
|
||||
<item name="description" value="LO"/>
|
||||
</item>
|
||||
<item name="ip" value="forwarding"/>
|
||||
<item name="line" value="vty"/>
|
||||
<zebra_config_change>0</zebra_config_change>
|
||||
</zebra>
|
||||
<vtysh>
|
||||
<item name="service" value="integrated-vtysh-config"/>
|
||||
<item name="hostname" value="router"/>
|
||||
<item name="username" value="root TooR"/>
|
||||
<vtysh_config_change>0</vtysh_config_change>
|
||||
</vtysh>
|
||||
<ripd>
|
||||
<item name="hostname" value="ripd"/>
|
||||
<item name="password" value="TooR"/>
|
||||
<item name="log file" value="/var/log/frr/ripd.log"/>
|
||||
<item name="log" value="stdout"/>
|
||||
<item name="router" value="rip">
|
||||
<item name="version" value="2"/>
|
||||
<item name="redistribute" value="kernel"/>
|
||||
<item name="redistribute" value="connected"/>
|
||||
<item name="network" value="eno1"/>
|
||||
<item name="network" value="eno2"/>
|
||||
<item name="default-metric" value="10"/>
|
||||
</item>
|
||||
<item name="line" value="vty"/>
|
||||
<ripd_config_change>0</ripd_config_change>
|
||||
</ripd>
|
||||
<ospfd>
|
||||
<item name="hostname" value="ospfd"/>
|
||||
<item name="password" value="TooR"/>
|
||||
<item name="log file" value="/var/log/frr/ospfd.log"/>
|
||||
<item name="log" value="stdout"/>
|
||||
<item name="router" value="ospf">
|
||||
<item name="redistribute" value="kernel"/>
|
||||
<item name="redistribute" value="connected"/>
|
||||
<item name="default-metric" value="20"/>
|
||||
</item>
|
||||
<item name="line" value="vty"/>
|
||||
<ospfd_config_change>0</ospfd_config_change>
|
||||
</ospfd>
|
||||
<bgpd>
|
||||
<bgpd_config_change>0</bgpd_config_change>
|
||||
</bgpd>
|
||||
<isisd>
|
||||
<isisd_config_change>0</isisd_config_change>
|
||||
</isisd>
|
||||
<ripngd>
|
||||
<ripngd_config_change>0</ripngd_config_change>
|
||||
</ripngd>
|
||||
<ospf6d>
|
||||
<ospf6d_config_change>0</ospf6d_config_change>
|
||||
</ospf6d>
|
||||
</router>
|
||||
</config>
|
2830
xml/crypto_param.xml
2830
xml/crypto_param.xml
File diff suppressed because it is too large
Load diff
Loading…
Add table
Add a link
Reference in a new issue