!
ip access-list stateless logon-control-stateless any any svc-icmp permit any any svc-dns permit any any svc-dhcp permit any any svc-natt permit !
ip access-list session validuser
network 169.254.0.0 255.255.0.0 any any deny any any any permit
ipv6 alias any6 alias any6 any permit !
user-role authenticated
access-list stateless allowall-stateless !
user-role denyall !
user-role guest
access-list stateless http-acl-stateless access-list stateless https-acl-stateless access-list stateless dhcp-acl-stateless
access-list stateless icmp-acl-stateless access-list stateless dns-acl-stateless !
user-role logon
access-list stateless logon-control-stateless ! !
crypto ipsec transform-set default-boc-bm-transform esp-3des esp-sha-hmac crypto ipsec transform-set default-rap-transform esp-aes256 esp-sha-hmac crypto isakmp eap-passthrough eap-tls crypto isakmp eap-passthrough eap-peap
crypto isakmp eap-passthrough eap-mschapv2
mgmt-user admin root 9a05893a01941ea9fadbe8f7f92075bc5b5c8189ef96622520
no firewall attack-rate cp 1024
ipv6 firewall ext-hdr-parse-len 100 !
! firewall cp
packet-capture-defaults tcp disable udp disable sysmsg disable other disable !
ip domain lookup !
country CN
aaa authentication mac \!
aaa authentication dot1x \!
aaa server-group \ auth-server Internal
set role condition role value-of !
aaa profile \!
aaa authentication captive-portal \!
aaa authentication vpn \!
aaa authentication mgmt !
aaa authentication wired
! web-server !
aaa password-policy mgmt !
traceoptions !
qos-profile \!
policer-profile \!
ip-profile
default-gateway 172.31.11.1 !
lcd-menu !
interface-profile ospf-profile \ area 0.0.0.0 !
interface-profile pim-profile \!
interface-profile igmp-profile \!
stack-profile
! ipv6-profile !
interface-profile switching-profile \ access-vlan 712 !
interface-profile switching-profile \!
interface-profile switching-profile \ switchport-mode trunk !
interface-profile poe-profile \ enable !
interface-profile poe-profile \!
interface-profile poe-profile \ enable !
interface-profile enet-link-profile \!
interface-profile lldp-profile \!
interface-profile lldp-profile \
lldp transmit lldp receive med enable !
interface-profile mstp-profile \!
interface-profile pvst-port-profile \!
vlan-profile mld-snooping-profile \!
vlan-profile igmp-snooping-profile \!
vlan-profile igmp-snooping-profile \!
spanning-tree
mode mstp ! gvrp ! mstp ! lacp !
vlan \
igmp-snooping-profile \!
vlan \!
vlan \!
interface gigabitethernet \
switching-profile \!
interface vlan \
ip address 172.31.11.2 255.255.255.0 !
interface mgmt !
interface-group gigabitethernet \ apply-to 0/0/0-0/0/23 poe-profile \
switching-profile \!
interface-group gigabitethernet \ apply-to ALL
lldp-profile \ poe-profile \!
snmp-server view ALL oid-tree iso included
snmp-server group ALLPRIV v1 read ALL notify ALL snmp-server group ALLPRIV v2c read ALL notify ALL
snmp-server group ALLPRIV v3 noauth read ALL notify ALL snmp-server group AUTHPRIV v3 priv read ALL notify ALL snmp-server group AUTHNOPRIV v3 auth read ALL notify ALL
snmp-server enable trap
process monitor log
end
(aruba2500-xmu-2f) # (aruba2500-xmu-2f) # (aruba2500-xmu-2f) #
(aruba2500-xmu-2f) #write memory Saving Configuration...
Configuration Saved.
(aruba2500-xmu-2f) #show ip interface brief
Interface IP Address / IP Netmask Admin Protocol vlan 711 172.31.11.2 / 255.255.255.0 Up Up mgmt unassigned / unassigned Up Down
(aruba2500-xmu-2f) #ping 172.31.11.1 Press 'q' to abort.
Sending 5, 100-byte ICMP Echos to 172.31.11.1, timeout is 2 seconds: !!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1.525/1.922/2.534 ms
(aruba2500-xmu-2f) #write memory Saving Configuration...
Configuration Saved.
(aruba2500-xmu-2f) #configure terminal
Enter Configuration commands, one per line. End with CNTL/Z
(aruba2500-xmu-2f) (config) #end (aruba2500-xmu-2f) # (aruba2500-xmu-2f) # (aruba2500-xmu-2f) #
(aruba2500-xmu-2f) #copy ftp: 172.1.1.1.1 ?
(aruba2500-xmu-2f) #copy ftp: 172.1.1.1.1 endwin ?
(aruba2500-xmu-2f) #copy ftp: 172.1.1.1.1 endwin ArubaOS_MAS_7.2.2.1_38712 ? flash: Copy to the flash file system